Scout Trails Docs

Sessions

A session is one run of a coding agent, identified by the session ID the agent reports. The Sessions tab lists them, and each session has a detail page with its cost, risk flags, external domains and a timeline of every tool call.

How sessions are built

  • A session appears once at least one of its tool calls arrives. Tool calls carry the session ID, the actor and the agent.
  • A session’s cost comes from the model calls that carry the same session ID. Claude Code reports model calls with token counts and cost. Codex CLI doesn’t, so Codex sessions show — for cost.
  • A session’s duration is the wall-clock time from its first tool call to its last. It is elapsed time, not active time. An agent that resumes an earlier conversation reuses its session ID, so a session you return to over several days reports a duration of several days.

Sessions list

Open Sessions in the header. The subtitle reads “Per-session rollup — actor, agent, tools, errors, duration, cost.”

Filters

The filter bar has Window and Scope, which work as described in Dashboard basics. The list shows every session with at least one tool call in the window, from the selected scope.

Columns

ColumnMeaning
SessionA short label: the agent name and a shortened session ID (the first eight characters of a UUID), for example claude-code · 3f9c2a1b. Hover to see the full ID. Select it to open the session.
ActorThe display name of the actor that sent the session, with its role label underneath when it has one. If the actor isn’t known to the organization, its raw actor ID appears instead.
AgentThe name the agent reports for itself, such as claude-code, with its version underneath when reported.
ToolsNumber of tool calls in the window.
ErrorsNumber of those tool calls that ran and failed. Highlighted when above zero.
DurationTime between the first and last tool call in the window, shown as 45s, 12m, 3h 12m or 2d 4h.
CostThe session’s total model spend across the whole session, not only the window. — means no model calls arrived for the session, so its cost is unknown. $0.00 means its model calls arrived without a price.
StartedTime of the session’s first tool call in the window, in UTC.

Tools, Errors, Duration and Started count only the tool calls inside the window. For a session that began before the window, open the session to see its full figures.

Order and paging

Sessions are sorted by their most recent tool call, newest first. The list shows 25 sessions per page. Use Prev and Next below the table to move between pages; the label between them shows the page number and adds (last) on the final page. The page buttons are hidden when everything fits on one page.

Empty list

When no session matches, the table shows No sessions in this window. with Try 30 days and Back to Overview buttons. Widen the window or the scope, and check that an agent is configured to send data. See Agent setup.

Session detail

Select a session in any list to open its page. The heading shows the session label, and ← All sessions returns to the list.

The detail page always covers the whole session, regardless of the window you came from. A session ID that doesn’t exist in your organization returns a “404 page not found” page.

Overview card

FieldMeaning
Session IDThe full session ID, selectable for copying.
ActorThe actor’s display name and role label.
AgentThe agent’s name and version.
StartedTime of the session’s first tool call.
Last seenTime of the session’s most recent tool call.
DurationTime from Started to Last seen.
Tool callsTotal tool calls, followed by the number of errors. When there are errors, the error count is a link that filters the timeline below to them.
CostTotal model spend and the number of model calls, or — when no model calls arrived.

Cost

The Cost card covers the whole session:

FieldMeaning
Total costSum of the cost of every model call.
Model callsNumber of model calls.
Fresh input tokensInput tokens not served from the prompt cache.
Cache read tokensInput tokens served from the prompt cache, followed by the share of all input read from cache.
Cache creation tokensTokens written to the prompt cache.
Output tokensTokens the model generated.

When the session has no model calls, the card shows No model calls recorded. This is expected for agents that don’t report model calls, such as Codex CLI.

Spend by model

The Spend by model card lists each model the session used, most expensive first, with its Calls, Cost and a Share bar showing its portion of the session’s cost. A model call that didn’t name its model is listed as unattributed. When the session has no cost to divide, Share shows —. With no model calls the card shows Nothing to break down.

Risk flags

The Risk flags card lists what the Scout Trails detector found in the session’s tool calls, most severe first. Each row shows Severity, Flag and Evidence.

FlagSeverityRaised when
credential_detectedhighA tool call’s arguments or result contain something shaped like a secret: an AWS access key, a GitHub token, an OpenAI-style sk- key, a JWT, a private key block, a Stripe live key, a Slack token or a Bearer authorization header. The evidence shows the kind and only the first few characters.
destructive_operationhighA shell (Bash) command runs something destructive: a recursive or forced rm, git push --force, git reset --hard, git clean -f, DROP TABLE, TRUNCATE TABLE, dd writing to a device, mkfs, shutdown or reboot, or chmod 777.
sensitive_pathmediumArguments or results mention a sensitive file, such as .env files, .ssh/ paths, credentials.json, .pem and .key files, .aws/credentials, SSH private keys like id_rsa, .kube/config, or keystores (.p12, .pfx, .keystore, .jks).

Evidence is cut to 60 characters. When nothing was flagged the card shows No risk flags in this session.

External domains

The External domains card lists the internet hosts the session’s tool calls reached, with Hits counting the calls that touched each one, most-hit first. Scout Trails finds hosts in:

  • URLs in shell commands that use curl or wget.
  • The url argument of WebFetch calls.
  • url, endpoint, uri or base_url arguments of MCP tool calls.

Only http and https URLs count, and localhost, 127.0.0.1, 0.0.0.0 and ::1 are left out. With none, the card shows No external domains reached.

Tool-call timeline

The Tool-call timeline lists the session’s tool calls, newest first.

ColumnMeaning
ToolThe tool’s name. Select it to open the tool call.
TypeThe tool’s type, for example builtin or mcp.
DurationHow long the call took, such as 850ms, 1.2s, 3m05s or 1h02m. — for a denied call, which never ran.
Statusok, error or denied. See Status.
StartedWhen the call happened, in UTC.

When a call failed with an error message, its status is a toggle. Select it to show or hide an Error row with the message beneath the call.

The filter bar inside the card narrows the timeline only; the cards above always describe the whole session.

  • Tool — one tool name used in this session, or Any.
  • Tool type — one tool type, or Any.
  • Status — ok, error, denied or Any.

Select Apply to filter. Reset appears once a filter is set and clears it. The timeline pages with Prev and Next, 25 calls per page, and keeps your filters as you page.

The timeline’s empty states:

  • No tool calls match these filters. — the session has calls, but none match. Clear filters removes the filters.
  • No tool calls on this page. — the page is past the end of the timeline. Previous page goes back.