Skip to content

Software companies

Session replay data and computer-use agents: valuable but risky

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Session replay data shows how real users move through software, which is why builders of computer-use AI agents find it interesting, but it is among the riskiest records a software company holds. The safe default is to exclude it, making exceptions only for masked recordings of company-controlled or test accounts with clear notice and counsel sign-off.

Key takeaways

  • Session replay can capture anything a user saw or typed, including other people's data inside your customers' accounts.
  • Computer-use agent builders value goal-directed interaction sequences, which rarely require your customers' real screens.
  • Default to excluding customer session replays from any licensing scope.
  • Scripted recordings on demo tenants, QA sessions and end-to-end test suites are often safer substitutes.

Why do computer-use agent builders want interaction data?#

Computer-use agent builders want interaction data because their agents operate software the way people do: reading the screen, clicking, typing and moving between pages to finish a task. Learning that well takes many examples of real people completing real tasks in real interfaces, including the detours.

Session replay tools record exactly those sequences inside your product. In complex B2B software, a recording of someone building a dispatch schedule, reconciling a ledger or configuring user permissions shows the order of steps, the errors, the workarounds and the point where users gave up. That is why the question reaches the CTO's desk.

What makes session replay so risky?#

Session replay is risky because it captures whatever appeared on screen or in a form, not just what your product was designed to collect. Unless masking was configured carefully, recordings can include names, addresses, financial figures and free text typed by users, plus records belonging to your customers' own clients.

Notice and consent are the second problem. Many users never knew they were being recorded, and session recording has been the subject of US privacy lawsuits brought under state wiretapping and eavesdropping laws. In B2B software, your customer agreement and data processing addendum usually treat recordings as customer data you process on the customer's behalf.

The third problem is the replay vendor. Its terms govern export, retention and storage location, and some vendors reserve rights to aggregated data for their own purposes. All three layers have to line up before a single recording could be considered.

A risk-value matrix for interaction records#

A risk-value matrix sorts interaction records by how useful they are to agent builders and how much exposure they create. Most customer production recordings land in the corner of high value and high risk, which is why they are excluded by default.

A risk-value matrix for interaction records
Recording typeValue to agent buildersRiskDefault
Customer production sessions, unmaskedHighVery highExclude
Customer production sessions, masked at captureHighHighExclude unless contracts, notices and counsel all allow
Employee sessions in production toolsMediumMediumConsider with employee notice and masking
Scripted sessions on a demo tenant with synthetic recordsMediumLowCandidate
QA and end-to-end test runsMediumLowCandidate after secret checks
Usability studies with signed participant releasesMediumLow to mediumCandidate if releases cover the use
Product analytics events without screen contentLow to mediumMediumReview case by case

The default exclude rule and its exceptions#

The default rule is to exclude session replay from licensing scope. An exception is worth considering only when every condition below holds and counsel signs off in writing.

Masking after the fact is weaker than masking at capture. Replay formats can store text in many places, and custom components, embedded frames and canvas elements are easy to miss. Image redaction tools help with screenshots: the open-source Presidio project includes a module that redacts personal data in images, but its own documentation warns there is no guarantee it finds all sensitive information.

  • The recordings come from accounts your company controls, such as staff, QA or demo tenants, or from participants who signed releases covering this use.
  • Inputs and on-screen text were masked at capture, not cleaned afterward.
  • No customer tenant data appears on screen, or the tenant holds only synthetic records.
  • The replay vendor's terms allow export and reuse of the recordings.
  • The people recorded received notice that covers the intended use.

What should a CTO check in the current replay setup?#

A CTO should check the current replay configuration before any licensing conversation, because the setup decides what already exists in the archive. Most of the risk was locked in when recording started, not when someone proposed reusing it.

Pay particular attention to anything captured beyond the screen. Many replay tools can also record console logs and network requests, and those payloads can hold tokens, full customer records and API responses that never appeared visibly.

  • Masking defaults: whether all inputs and text are masked by default or only selected fields.
  • Page and tenant scope: which pages, environments and customer tenants have recording switched on.
  • Extra capture: whether console logs, network requests or full page contents are stored with the recording.
  • Retention: how long recordings are kept, and whether older archives were exported elsewhere.
  • Notice and opt-out: what end users and customer administrators were told, and whether customers can switch recording off.
  • Access: who inside the company, and at the vendor, can view recordings.

What can you offer instead of customer recordings?#

Safer substitutes for customer recordings often carry much of the same signal. What agent builders need is goal-directed sequences in your interface, and those can be produced without exposing anyone's account.

Scripted task recordings are the cleanest option: staff complete standard workflows on a demo tenant filled with synthetic records, with the goal and the success condition written down for each run. End-to-end test suites written in tools such as Playwright or Cypress encode the same workflows as executable steps. Support tickets with steps to reproduce describe where real users got stuck, without showing their screens.

Some builders also want an environment rather than recordings: a sandboxed copy of the product an agent can practice in. That is a separate product decision with its own security and contract questions.

Illustrative: a construction scheduling software vendor changes course#

Illustrative: a fictional construction scheduling software vendor has kept session replays of customer use for product research. The CTO asks whether they could be part of a licensing package for computer-use agents.

A review of a sample finds unmasked text fields showing subcontractor names, bid notes and site addresses, and the customer agreement treats all project content as customer data. The vendor excludes every customer recording and shortens replay retention. Instead, its solutions engineers record standard scheduling tasks on a demo tenant with synthetic projects, with masking enabled at capture and signed staff releases, paired with the company's end-to-end test suite.

The result is a candidate package the company can describe without exposing a single customer, and a replay configuration that collects less from now on.

How SourceX handles screen and interaction data#

SourceX records session replay as a record family during Supply, the first step of the SourceX five-step transaction, but flags it as high risk from the start. The first fit check asks only which tools are used, how masking is configured and whose accounts appear; no recordings are shared.

Where a company proceeds with substitutes such as scripted demo-tenant sessions, the Rights and Preparation steps document releases and masking, and the privacy record in the SourceX Evidence Packet states how the recordings were made. Often the right advice is simply to leave customer replays out.

Frequently asked questions

Is masking at capture enough to make session replays licensable?

No, not on its own. Masking reduces what is recorded, but notice, customer contracts and the replay vendor's terms still apply. Masking settings also miss things, such as custom components and embedded frames. Treat masking as necessary but not sufficient, and review the remaining questions with counsel.

Who owns session replay recordings, us or the replay vendor?

Usually the recordings are your data, or your customers' data, processed by the vendor on your behalf. Some vendor terms reserve rights to use aggregated or de-identified data for their own purposes. Check export rights, retention and any reserved rights in your agreement.

Should we delete old session replays?

Keep replays only as long as a documented purpose requires. Privacy laws generally expect data minimization, and old recordings carry risk with little ongoing value. Set retention in the replay tool, apply it to existing archives, and check for legal holds before deleting anything.

Do screen shares in support calls raise the same issues?

Yes. Recorded screen shares often show customer records and personal data, and the call itself may fall under recording consent rules. Treat them like customer session replays and exclude them by default.

What else do computer-use agent builders need besides recordings?

They usually need clear task goals, a definition of success and sometimes a safe environment where an agent can practice. Labeled scripted sessions and test suites can supply goals and success conditions without exposing customers.

Sources

  • Presidio is an open-source, MIT-licensed SDK for PII identification and anonymization in text and images, and includes a module that redacts PII in images. Source
  • Presidio's own documentation warns that "because it is using automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information." Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify