Skip to main content

Session Player

Introduction to Session Player

The Session Player is a powerful tool designed for comprehensive monitoring and forensic analysis. It allows you to view a user's screen and audio recordings in high detail. If the user's computer is currently online, the player enables real-time view of the user’s desktop and allows you to interact with it.

In addition to playing session recordings, the Session Player provides a suite of advanced features for real-time oversight, investigation, and auditing:

  • Take Remote Control: Remotely control a user's computer in real-time without requiring RDP or any third-party remote software, providing a seamless way to deliver hands-on technical assistance or intervene during high-risk activities.

  • Freeze Input: Freeze a user's inputs by locking their keyboard and mouse, allowing you to instantly halt suspicious or unauthorized actions as they happen to prevent potential data breaches or policy violations.

  • Send Ctrl+Alt+Del: Activate the Windows Security Options screen by sending the "Ctrl+Alt+Del" command, which enables you to manage system-level tasks, such as accessing the Task Manager, switching users, or changing passwords, even during a remote session.

  • Track Events Easily: Track user Activities and behavior rule violation Alerts directly on the player timeline as color-coded pins, simplifying auditing by highlighting exactly when specific events occurred.

  • Add Tags: Add Tags with notes to recordings to create a searchable record of critical moments, facilitating efficient case management and easier auditing or investigation.

  • Export Evidence: Export still images and videos for evidence gathering, providing tangible, time-stamped documentation for legal proceedings, HR reviews, or compliance audits.

  • Review Multiple Screens: The player supports tracking and displaying activities across multiple monitor setups.

  • Review Multiple Sessions: The player supports tracking and displaying activities across multiple computer sessions.

  • Virtual Desktop Compatibility: Support virtual desktops, including those from Terminal Servers. When the Agent is installed on a Terminal Server, each RDP user's session is recorded separately.

Session Player Timeline

The player timeline respects the configured Timezone setting in Configurations > Settings > Locale, displaying the full day while correctly clipping sessions that cross the midnight threshold.

Session Recording Prerequisites

To record and view a user's desktop with the Session Player, you must enable Screen Recording in the Monitoring Profiles (this setting is on by default). To capture and play back user audio, you must enable Audio in the Monitoring Profiles, which is disabled by default.

Accessing the Session Player

Here are a few ways to launch the Session Player:

  • From dashboard grid widgets: Click the Movie Camera icon, available in the grid widget(s) of most dashboards.

  • From a grid row: Click the Three Dots icon or right-click on a row, then select View record from the Context Menu.

  • From thumbnails: On screens like Live View or Overview dashboards, you can click on any thumbnail under the Live Montage widget.

  • From Employee's or Computer's Details: On the Employee's details or Computer's details details screen, click the Live View button.

Session Player Modes

The Session Player offers two distinct viewing modes: Live View and History View.

Live View

With the Live View mode, the Session Player turns into a fully functional remote desktop client. You can view a real-time stream of the user’s desktop and take remote control of it.

Here are the player controls available in the Live View mode:

1. View Employee’s Details: Click the Employee's Name (top-left corner) at any time to open the Employee's Details page in a new browser tab.

2. Select Date (Deactivates Live View): Selecting a date from the Calendar drop-down list to deactivate the Live View and switch to the History View mode. Moving the Play Head or setting a new Date/Time (bottom-right corner) also deactivates the Live View mode.

3. Zoom In/Out: Click the Fit screen drop-down menu to change the zoom level of the video.

4. Activate Live View: Click the Live button near the top-right corner to enable the Live View mode. When the player is in Live View mode, the Live button will turn orange, an orange border will appear around the video, and the pay head will also turn orange.

The Live button is shown only when the user's computer is online.

5. Take a Snapshot: Click the Camera icon to download a still image of the video you're currently viewing. This will save the snapshot as a PNG file.

6. View Log of Events: Click the Alert icon to open the Log of Events panel.

7. Export Video: Click the Download icon to export the video.

8. Play/Pause Video: Click the Play / Pause button to play or pause the video.

9. Control Sound: Click the Speaker icons to mute/unmute the audio. Click and drag the Knob to increase/decrease the volume.

Note that the Audio option must be enabled from the monitoring profile for audio to be recorded.

10. Standard / Reconstructed Video: Click the Standard Video / Reconstructed Video icon to switch between Standard and Reconstructed Video Modes.

11. Send Ctrl+Alt+Del: Click the Exclamation icon to send the CTRL+ALT+DEL command to the user’s computer. This will bring up the Security Options screen, where you can access options to change the account password, switch a user, open the Task Manager, etc.

12. Freeze Input: Click the Lock icon to freeze/unfreeze the user’s input. When input is frozen, the user won’t be able to use their keyboard or mouse.

You can send a message to the user when this command is activated by configuring it from the Message to display section in Screen Recoding monitoring settings.

13. Take Remote Control: Click the Cursor icon to take remote control of the user's computer.

14. Navigate Timeline: Drag the Play Head to move navigation to timeline. You can also hover over the Timeline Rail to see a precise time tooltip that follows your cursor, allowing you to pinpoint the exact moment of an activity. Click to position the Play Head to that location. Note that moving the Play Head deactivates the Live View mode and enters the player in History View mode.

15. View Time/Date: The time and date for the Play Head position is shown at the bottom-right corner.

History View

In the History View mode, you will be able to see previous session recordings of a user.

To view a past recording, it must be within your retention period.

Here are the player controls available in the History View mode:

1. View Employee’s Details: Click the Employee's Name (top-left corner) at any time to open the Employee's Details page in a new browser tab.

2. Select Date: Selecting a date from the Calendar drop-down list to deactivate the Live View and switch to the History View mode. Moving the Play Head or setting a new Date/Time (bottom-right corner) also deactivates the Live View mode.

3. Select Computer: Click the Computer Name next to the Calendar to switch between the computers the employee used that day. The selector lists every computer with recordings for the viewed day, with a checkmark on the one currently playing. It is shown whenever the employee has at least one computer with recordings for the day (it is not shown in Live View).

4. Zoom In/Out: Click the Fit screen drop-down menu to change the zoom level of the video.

5. Activate Live View: Click the Live button near the top-right corner to enable the Live View mode.

The Live button is shown only when the user's computer is online.

6. Take a Snapshot: Click the Camera icon to download a still image of the video you're currently viewing. This will save the snapshot as a PNG file.

7. View Log of Events: Click the Alert icon to open the Log of Events panel.

8. Export Video: Click the Download icon to export the video.

9. Play/Pause Video: Click the Play / Pause button to play or pause the video.

10. Set Playback Speed: Use the Rewind and Fast Forward icons to slow down or speed up the playback. The current speed is shown on the speed indicator (e.g., 1x). Click the indicator to reset the speed to normal (1x).

11. Step Back / Step Forward: Pause the video, then click the Step Back or Step Forward icon to move through the recording one second at a time.

12. Control Sound: Click the Speaker icons to mute/unmute the audio. Click and drag the Knob to increase/decrease the volume.

Note that the Audio option must be enabled from the monitoring profile for audio to be recorded.

13. Standard / Reconstructed Video: Click the Standard Video / Reconstructed Video icon to switch between Standard and Reconstructed Video Modes.

14. Navigate Timeline: Drag the Play Head to move navigation to timeline. You can also hover over the Timeline Rail to see a precise time tooltip that follows your cursor, allowing you to pinpoint the exact moment of an activity. Click to position the Play Head to that location. Note that moving the Play Head deactivates the Live View mode.

Darker areas on the Timeline Rail indicate that no recording is available for that period. This can happen for several reasons, such as the Agent was disabled, the user logged out, Screen Recording was turned off, etc., or other issues. For troubleshooting, please refer to this Knowledge Base article on video recording issues.

15. Set Date/Time: You can set a new Date/Time from the bottom-right corner.

Switching Between Standard and Reconstructed Video Modes

Click the Standard Video / Reconstructed Video button to toggle between the two video modes:

  • Standard Video: Captures continuous images of the desktop. This mode requires the Screen Recording monitoring channel to be active and Screen Recording permission enabled on the Mac endpoint.

  • Reconstructed Video: Rebuilds the desktop from UI metadata, system events, and extracted text, without capturing actual screen pixels. Each window is redrawn with its title bar and content on a flat background.

On macOS, Standard Video requires the Screen Recording monitoring channel to be active and Screen Recording permission enabled on the Mac endpoint; Reconstructed Video relies only on Accessibility permission, completely bypassing the need for restrictive screen recording access on the Mac. For more information, check out this article in the Knowledge Base.

Here’s how a Reconstructed Video looks compared to the Standard Video side by side:

Changing the Zoom Level

Click the Fit screen drop-down menu to change the zoom level of the video. Select the Fit screen option from the menu to fit the video inside the window, or choose a fixed zoom level: 25%, 50%, 75%, etc. If the video doesn't fit in the window area, you will be able to move around the video by clicking-and-dragging anywhere on the video with your mouse. You can also use the mouse wheel and touch gestures.

Viewing Log of Events

Click the Alert icon to open the Log of Events panel to see all app and web Activities, review Alerts triggered by your rules, view or manage Tags, and browse the day's Sessions.

Activities

The Activities tab shows the user's interactions with apps and websites (like launching a program, opening a document, or visiting a website).

1. Click the Activities tab in the Log of Events panel.

2. Click the Follow icon to make the log automatically scroll to the entry matching the current playback position as the video plays. Click again to turn it off.

3. Click the Search icon to open the search field and look for specific activities. As you type, matching activities are highlighted in the list. Use the Up and Down arrows beside the field to jump between matches - the Play Head automatically moves to the corresponding timestamp. Click the X icon to clear the search.

4. Click on any activity in the list to jump to the exact moment it occurred on the Timeline Rail.

5. While the Activities tab is open, activities are also marked on the Timeline Rail as Green Pin icons:

a. A single activity appears as a small pin. Nearby activities (occurring within roughly half an hour of each other) collapse into a single numbered pin that displays the total count of contained activities (if there are more than 100 activities, it displays “99+”). Click a pin to move the Play Head to its first activity.

b. Hover over a numbered pin to fade the other pins and open a card listing every activity in the group with its timestamp. Click any row in the card to jump playback to that exact moment. The card stays open while you move the pointer onto it to scroll through long lists.

c. Activity pins cover only the activities loaded on the list. Click See more to load more and extend pin coverage.

Alerts

The Alerts tab shows the rule violation alerts triggered by the user.

1. Click the Alerts tab in the Log of Events panel.

2. Click the Follow icon to make the log automatically scroll to the entry matching the current playback position as the video plays. Click again to turn it off.

3. Click the Search icon to open the search field and look for specific alerts. As you type, matching alerts are highlighted in the list. Use the Up and Down arrows beside the field to jump between matches - the Play Head automatically moves to the corresponding timestamp. Click the X icon to clear the search.

4. Click on any alert in the list to jump to the exact moment it occurred on the Timeline Rail.

5. While the Alerts tab is open, alerts are also marked on the Timeline Rail as Orange Pin icons:

a. A single alert appears as a small pin. Nearby alerts (occurring within roughly half an hour of each other) collapse into a single numbered pin that displays the total count of contained alerts (if there are more than 100 alerts, it displays “99+”). Click a pin to move the Play Head to its first alert.

b. Hover over a numbered pin to fade the other pins and open a card listing every alert in the group with its timestamp. Click any row in the card to jump playback to that exact moment. The card stays open while you move the pointer onto it to scroll through long lists.

c. Alert pins cover the whole day's alerts. On days with more than 500 alerts, click See more to load the rest and extend pin coverage.

Tags

The Tags tab allows you to view and manage tags.

A tag is a specific moment in a video with a label and notes. This is a useful feature for auditing, tracking, and case management, as it lets you highlight important points in time.

1. Click the Tags tab in the Log of Events panel.

2. Click on any tag in the list to jump to the exact moment on the Timeline Rail.

3. While the Tags tab is open, alerts are also marked on the Timeline Rail as Blue Pin icons:

a. A single tag appears as a small pin. Nearby tag (occurring within roughly half an hour of each other) collapse into a single numbered pin that displays the total count of contained tags (if there are more than 100 tags, it displays “99+”). Click a pin to move the Play Head to its first tag.

b. Hover over a numbered pin to fade the other pins and open a card listing every tag in the group with its timestamp. Click any row in the card to jump playback to that exact moment. The card stays open while you move the pointer onto it to scroll through long lists.

4. Click the New tag button to add a new tag. A window will pop up:

a. Select an existing tag from the Entity drop-down list.

b. Alternatively, type a name in the Or create a new tag field to create a new tag.

c. Select the Date and Time.

d. Enter your Notes.

e. Click the Save button.

4. Click the Pencil icon to edit a tag (editing a tag is similar to adding a new tag). Click the Trash Can icon to remove/delete a tag.

Sessions

The Sessions tab lists the employee's related sessions for the day you are viewing: one row per computer the employee was logged into, with the number of login sessions recorded on that computer.

1. Click the Sessions tab in the Log of Events panel. The currently playing computer is highlighted in the list.

2. Click a computer in the list to switch the player to that computer's recording for the same day.

The Sessions list covers the whole day currently shown in the player (in the server timezone) and spans all of the employee's computers, not just the one currently playing. A "session" is one login session, from login to logout, on a computer. The same computer list is offered by the Computer Name selector next to the Calendar in History View.

Exporting Videos

Click the Download icon from the Session Player to open the Export video window:

1. Use the From and To selectors to define the exact period for the clip.

2. Select your desired Video speed and FPS (Frames per second).

3. In the Notify the email below after export finishes field, specify the email address where the secure video download link will be sent*.

*If you used the Specify a domain to allow Teramind data export option (Configurations > Settings > Security) to restrict exports to a specific domain, then you must use an email address within that approved domain.

4. You can also use the Disable sound option to remove the audio track from the recording (Note: Audio is only recorded if the Audio monitoring channel was enabled in the user's Monitoring Profile at the time of recording).

5. Click the Start export button to start the export process. When the export is ready, an email will be sent to the email address you specified above. The email looks like this:

Click the link in the email to download the video.

You can view a list of all the exported videos and download them from the System > Video Exports screen.

Retrieving Archived Video (Cloud)

Recordings older than 32 days are automatically moved to an archive. This process is in place to optimize storage usage and minimize processing overheads.

If you attempt to play an archived recording, the player displays a restore notification in the video area: "This video is in our archive, and we're working on restoring it for you. Restoring [date]. This may take a few hours.":

The player checks the restore status automatically while this message is shown. Once the retrieval is complete, you'll also receive an email at your account's address:

This email will contain a link that, when clicked, will open the Session Player and begin playing the video. At this point, you can export the video and then download it if you wish to keep a local copy.

Session Playback Under E2EE (On-Premises)

When End-to-End Encryption (E2EE) is enabled, the Session Player will mask the screen on both the Live View and History View modes, and you will see an "E2EE (end-to-end encryption) is enabled" message:

Enter your passphrase and press the Decrypt button to view the recording.

Did this answer your question?