Skip to main content
Color theme
Sign inRequest beta access

How ClickGuardIQ works

Move from an aggregate signal to the measured journey.

Website-scoped profiles and privacy-safe recordings help investigators understand acquisition, activity, identity, conversion, and risk context.

Sanitized beta interface — no customer data
Sanitized ClickGuardIQ Session Recordings interface with privacy-aware setup messaging.
Session RecordingsCurrent beta interface captured without recorded customer sessions or personal data.

A reproducible operating method

Visitor and Session Evidence begins with scope, provenance, and a permitted decision.

The method explains what enters the workflow, which transformation occurs, what leaves it, and which conclusion the evidence does not support.

The question this workflow owns

How can an operator move from an aggregate traffic signal to the measured visitor journey without overstating identity or collecting evidence without a defined purpose? This page is written for fraud investigators, paid-media and analytics teams, privacy owners, agencies, support teams, and buyers evaluating journey-level evidence. Its owner is website-scoped identity, measured journey, event provenance, privacy-safe recording, and investigation access, so adjacent product surfaces can reference the result without silently changing its meaning or authority.

The supported decision is whether the measured visitor or session evidence is sufficient for a defined investigation question, requires more context, remains unavailable or incomplete, or supports a policy-governed next step. That decision remains qualified by the selected property or client, eligible population, time window, filters, definitions, coverage, freshness, permissions, and evidence available when the workflow runs.

  • Workflow owner: website-scoped identity, measured journey, event provenance, privacy-safe recording, and investigation access
  • Audience: fraud investigators, paid-media and analytics teams, privacy owners, agencies, support teams, and buyers evaluating journey-level evidence
  • Supported decision: the measured visitor or session evidence is sufficient for a defined investigation question, requires more context, remains unavailable or incomplete, or supports a policy-governed next step

Inputs retain their original meaning

Inputs include permitted website-scoped anonymous identifiers, acquisition context, page and interaction events, sessions, recording references, conversion and lead occurrences, consent state, identity links, tracking health, risk assessments, customer or CRM feedback, and correction history. An observed event, calculated metric, inferred relationship, customer-provided field, provider-reported state, and human decision are different evidence types. The workflow records which type produced each value instead of flattening all of them into a generic fact.

The timeline distinguishes observed website events, calculated sessions and metrics, inferred or approved identity relationships, customer or CRM fields, provider facts, operator decisions, recording availability, masking, sampling, and later corrections. Source identity, event time, ingestion time, calculation time, definition or model version, eligible scope, confidence, coverage, freshness, and correction history travel with the result wherever the interface presents it.

Boundaries remain visible

A visitor identifier is not automatically a known person, device, household, account, lead, customer, or cross-site identity; a recording is measured event evidence rather than a complete reproduction of human intent. This distinction prevents collection from being treated as acceptance, a signal as confirmation, a recommendation as execution, an attempt as provider application, or an applied state as a verified business result.

When a required input, permission, provider capability, identity link, outcome, or correction path is missing, the method narrows the supported result or returns unavailable, incomplete, unclassified, needs-review, failed, expired, or unknown. It does not replace missing evidence with an authoritative-looking estimate.

Method capabilities

What the visitor and session evidence method must preserve.

These are testable behaviors of the operating model, not claims of guaranteed detection, provider coverage, blocking, savings, revenue, or customer performance.

Keep identity website-scoped

Use property-bounded anonymous identity by default and retain identifier type, source, confidence, consent, validity window, merge or split authority, and history.

Build a provenance-aware timeline

Order acquisition, pages, interactions, sessions, conversions, leads, risk, tracking, external facts, recording references, and corrections while preserving source and timestamps.

Explain session boundaries

Retain the session definition version, inactivity or navigation rules, start and end basis, late events, corrections, and relationship to visitor and acquisition scope.

Govern recording eligibility

Apply consent, masking, field exclusion, sampling, retention, access purpose, roles, audit, and deletion requirements before capture and playback.

Recommend evidence for a reason

Link recordings or journey segments to a defined incident, signal, conversion, lead, tracking question, anomaly, or reviewer request rather than encouraging indiscriminate viewing.

Retain unavailable and incomplete states

Explain consent exclusion, unsupported page, masking, sampling, collection failure, short retention, processing delay, missing identity, and permission denial without inventing a journey.

Questions operators encounter

Apply the method when evidence and system states disagree.

Each scenario illustrates how the workflow should retain uncertainty, chronology, ownership, and a responsible next step.

An aggregate source looks unusual

Open the eligible population, then move to specific visitors, sessions, events, reasons, coverage, recordings, conversions, and tracking context without treating samples as the whole population.

The same person may appear twice

Review identifier types, website scope, confidence, consent, time overlap, source, evidence for merge, legitimate separation, approval, and the correction impact before changing identity.

A recording appears incomplete

Check eligibility, consent, masking, sampling, page support, lifecycle, event delivery, processing, retention, browser limitations, and tracking health before interpreting absent behavior.

A suspicious visitor later becomes a lead

Link the occurrence while keeping visitor risk, identity, intent, quality, qualification, priority, CRM stage, value, and later feedback independently sourced and versioned.

The controlled sequence

Five stages of visitor and session evidence.

Stages are linked but not interchangeable. Every handoff carries the evidence snapshot, status, actor, time, limitation, and correction route needed by the next stage.

  1. 01

    Establish privacy and identity scope

    Resolve verified website, consent, identifier types, session rules, purpose, masking, exclusions, sampling, retention, access roles, and audit requirements.

    An anonymous visitor identifier does not prove a unique person or permit cross-client identity.
  2. 02

    Assemble the measured journey

    Link eligible acquisition, page, interaction, session, conversion, lead, tracking, and external events by permitted identifiers with source and time provenance.

  3. 03

    Attach risk and evidence context

    Show versioned metrics, signals, reasons, risk, confidence, coverage, freshness, incident links, and unavailable or opposing evidence without changing source events.

  4. 04

    Open purpose-bound recordings

    Recommend and authorize eligible recording segments for a named question; retain masking, sampling, access, playback, retention, and limitation context.

  5. 05

    Decide, correct, and retain history

    Record the investigation decision or need for more evidence, then append identity, session, attribution, event, feedback, or model corrections with downstream impact.

Evidence and implementation status

Separate the documented method from current product and external readiness.

Status labels distinguish implemented interface evidence, beta behavior, provider dependencies, planned coverage, and known limitations.

Visitor workspaceavailable

Sanitized product capture

The current interface demonstrates visitor navigation and readiness without customer identity, journeys, recordings, conversions, leads, risk, or outcomes.

Journey modelbeta

Website-scoped beta workflow

Identity scope, event provenance, sessions, recording links, risk context, access, and correction behavior are defined and require validation.

Browser and customer contextexternal

External evidence dependency

Consent, browser support, identifiers, CRM or customer fields, recording eligibility, and complete journey context depend on permitted connected sources.

Reconstruction qualitylimited

Inherently incomplete evidence

Sampling, masking, excluded fields, unsupported pages, lifecycle, blockers, collection gaps, processing, retention, and identity uncertainty can limit the measured journey.

Method quality review

Compare visitor and session evidence by reproducibility, not presentation alone.

The comparison describes two operating approaches. It does not assert that every alternative service uses the weaker approach.

Compare visitor and session evidence by reproducibility, not presentation alone.
ComparisonUnqualified visitor replayPurpose-bound journey evidence
IdentityTreats cookies, devices, networks, visitors, leads, and people as interchangeable global identities.Retains identifier type, verified website scope, source, confidence, consent, validity, approved merge or split, and history.
TimelineOrders current attributes and events without source, receipt time, correction state, or session definition.Preserves source provenance, event and receipt time, session and attribution versions, late arrival, processing, and corrections.
RecordingEncourages broad playback and presents missing detail as absent user behavior.Requires purpose, eligibility, consent, masking, sampling, access, retention, audit, and visible coverage limitations.
RiskTurns an aggregate or visitor score into a definitive explanation of intent.Shows signals, reasons, opposing evidence, risk, confidence, coverage, freshness, grain, and unclassified state separately.
OutcomeTreats a later conversion or lead as proof that earlier traffic was valid or fraudulent.Links occurrences while keeping attribution, quality, qualification, priority, risk, value, CRM or buyer feedback, and maturity independent.

Reproducibility and audit standard

Another authorized reviewer should be able to reach the same scoped record.

A useful methodology is inspectable before adoption, reproducible during operation, and correctable after new evidence arrives.

Measurement contract

Journey analysis names the website, identifier and session rules, acquisition and attribution versions, event and receipt windows, consent and recording eligibility, coverage, sampling, tracking health, and missing or delayed sources. Every summary, comparison, export, alert, and investigation link should preserve the population definition, numerator and denominator where relevant, inclusion and exclusion rules, selected period, timezone, freshness, coverage, and known collection gaps.

The contract also distinguishes event time from receipt, calculation, report, action, provider response, and verification time. This prevents late arrival, retry, deduplication, backfill, reprocessing, or timezone changes from silently altering the apparent sequence.

  • No metric without its population and definition
  • No status without its source and timestamp
  • No comparison without compatible scope and maturity

Version and correction contract

Approved identity merge or split, session-boundary change, attribution update, event correction, consent-policy change, CRM feedback, or model recalculation creates attributable history and identifies affected journey and investigation views. Raw source observations remain immutable; derived assessments, annotations, identity decisions, policy decisions, provider results, and outcome checks receive attributable versions or history entries.

A recalculation answers what the current definition would conclude from eligible retained evidence. It does not erase what the earlier version reported at the time. Corrections link the prior state, reason, actor or source, affected scope, new state, and any downstream records that require review.

Evaluation contract

Before beta activation, the organization should name the websites or clients, providers, event sources, consent mode, identity rules, permissions, review owners, policy thresholds, supported actions, expected provider states, verification checks, reversal route, and outcome window required by this workflow.

Evaluation should test data readiness, traceability, reason readability, reproducibility, permission enforcement, failure handling, and correction behavior before it evaluates operational or commercial outcomes. This page supplies no invented testimonial, customer logo, benchmark, detection rate, savings total, conversion lift, revenue result, or provider proof.

Visitor and Session Evidence questions

Clarify the method, its limitations, and the next responsible check.

Answers describe the intended and current beta boundary without presenting planned or external behavior as already verified.

Does one visitor ID represent one real person?

Not necessarily. It represents an identifier within a defined website and validity scope. Devices, browsers, consent changes, deletion, blockers, shared environments, resets, and identity corrections can create splits or collisions. Person-level claims require separate permitted evidence.

Can visitors be merged across customer websites?

Cross-client merges are prohibited. Any broader relationship would require verified common ownership, compatible consent and purpose, permitted identifiers, confidence rules, authorization, audit, correction, and privacy review. The default is website-scoped identity.

Are session recordings complete videos of everything a visitor did?

No. They are reconstructed from eligible captured events and can be limited by consent, masking, exclusion, sampling, browser or page support, lifecycle, network delivery, processing, retention, and permissions. Missing detail should remain labelled as unavailable.

Who should be able to view a recording?

Only authorized roles with a defined investigation or support purpose, permitted website or client scope, and appropriate privacy responsibility. Access, playback, exports where supported, and administrative changes should be auditable and retention-limited.

Can journey evidence confirm click fraud by itself?

No. It can provide behavioral, acquisition, identity, conversion, lead, tracking, and recording context. Classification still requires eligible evidence, a versioned assessment, confidence and coverage, policy or review, limitations, and a governed decision.

How are corrections handled in the journey?

A source event is not silently rewritten. Approved identity merge or split, session rule change, attribution update, field correction, feedback, or recalculation creates attributable history with prior state, reason, time, scope, and affected downstream records.

Review the workflow against your operating reality

Define identity, privacy, recording, and investigation boundaries before opening visitor evidence.

Share websites, consent and identity rules, session definition, recording purpose, masking, sampling, retention, roles, investigation questions, conversions or leads, external fields, and correction needs. The review will map current evidence support.