The job this surface owns
Live View is designed for operators who need immediate awareness of eligible measured activity without mistaking a recent stream for complete analysis. Its primary record is a freshness-labelled stream of website activity with acquisition, device, page, event, visitor, tracking, and eligible risk context. That focus matters because a useful operating surface should answer a specific question before it asks a team to act. Here, the question is whether a recent event deserves a deeper visitor, session, incident, or tracking-health investigation. The answer stays attached to the evidence and scope that produced it.
Live View is bounded by the selected website, current stream window, accepted event types, consent and sampling rules, ingestion state, and disclosed delay. That scope travels with summaries, filters, exports, and follow-up links so a number is not separated from the population it describes. When the required evidence is absent, the interface should say that the answer is unavailable or incomplete instead of replacing it with an estimate that looks authoritative.
- Primary record: a freshness-labelled stream of website activity with acquisition, device, page, event, visitor, tracking, and eligible risk context
- Decision supported: a recent event deserves a deeper visitor, session, incident, or tracking-health investigation
- Designed for: operators who need immediate awareness of eligible measured activity without mistaking a recent stream for complete analysis
A deliberate evidence boundary
A live stream shows what has arrived recently; it does not guarantee complete capture, completed sessionization, final scoring, historical comparability, or fraud confirmation. ClickGuardIQ preserves this distinction because a high-risk signal, an unusual pattern, a tracking defect, and confirmed invalid activity are not interchangeable findings. Each can change what an investigator checks next, but none should silently inherit the certainty of another.
Each eligible event can retain the visitor, session, source, validation, and signal references needed for a stable follow-up after the stream moves on. The operating record keeps source observations, calculated signals, human notes, decisions, provider responses, and verified outcomes attributable. Corrections create a history rather than rewriting the earlier state, which keeps later reporting and review understandable.
How it fits daily work
The interface distinguishes event time, receipt time, processing time, current stream delay, and the point where older activity belongs in historical views. This prevents a recent partial stream from being compared casually with a completed historical period. It also gives an operator a direct route to the underlying visitor, session, incident, conversion, lead, campaign, integration, or delivery record when more detail is justified.
Live activity can expose sensitive URLs, events, and acquisition context, so access, field display, masking, and client scope follow the selected website and role. Access is therefore part of the product model, not an afterthought. Sensitive evidence, exports, provider actions, and administrative changes should remain limited to the appropriate website, client, role, and purpose, with an audit trail that explains who did what and when.