Skip to main content
Every time a person or an AI agent connects to an account through PAM, a session is created. The Sessions page shows all sessions, active and completed, so you can monitor what’s connected and review what happened.

Viewing Sessions

Go to Privileged Access Management → Sessions to see the session list. Click on any session to see its details and recording. A machine identity has no email address, so its sessions show Machine Identity wherever a person’s email would appear.

Filtering

Use the filters to find specific sessions:
  • Status — Active, Ended
  • Account or Folder — Narrow to specific resources
  • User — Sessions by a specific person or machine identity
  • Date range — Sessions within a time period
The search bar finds sessions by account name, folder name, or the actor’s name or email.

Active Sessions

Active sessions show a Live indicator. While a session is active:
  • Logs update in real-time
  • You can monitor what’s happening
  • You can terminate the session if needed

Session Details

Click on a session to see:
  • Session info — who, what, when, duration, IP address
  • Session logs — commands (SSH) or queries (PostgreSQL) executed
  • Recording playback — review everything that happened

Terminating Sessions

If something shouldn’t be connected (a security incident, a policy violation, someone stuck, or an agent doing more than you expected), you can terminate the session.
  1. Find the active session
  2. Click on it to open details
  3. Click Terminate
  4. Confirm
Whoever is connected is disconnected immediately, person or machine. Use this for emergencies; normal sessions should end naturally.

Next Steps

To understand how session recordings work and where they’re stored:

Session Recording

How sessions are recorded.

External Storage

Store recordings in your own S3 bucket.