> ## Documentation Index
> Fetch the complete documentation index at: https://tbd-6fc993ce-archand-kernel-1870-telemetry-control-platform.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Telemetry Categories

> The categories a browser session can capture, what each contains, and their cost

A category groups related telemetry events and is the unit you enable or disable. Selection is opt-in: a session captures a category only when you turn it on.

For the full payload schema of any event type, see the [Stream telemetry events](https://kernel.sh/docs/api-reference/browser-telemetry/stream-telemetry-events-via-sse) endpoint in the API reference.

## Operational

These categories report on the session itself rather than page content.

| Category     | Captures                                                                                                                                                                   | Event types                                                                  |
| ------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------- |
| `control`    | Actions that drive the browser: computer-control calls, Playwright code execution, screenshots and clipboard access, plus browser-control commands sent over the CDP proxy | `api_call`, `cdp_command`                                                    |
| `platform`   | Calls that manage the VM rather than drive the browser: recording lifecycle, filesystem, process execution, telemetry and browser configuration                            | `platform_api_call`                                                          |
| `connection` | CDP and live view connect/disconnect activity                                                                                                                              | `cdp_connect`, `cdp_disconnect`, `live_view_connect`, `live_view_disconnect` |
| `system`     | VM-level failures                                                                                                                                                          | `system_oom_kill`, `service_crashed`                                         |
| `captcha`    | Results of automated captcha solves                                                                                                                                        | `captcha_solve_result`                                                       |

`control` answers "what did my agent do." `platform` is mostly Kernel acting on the VM on your behalf - saving a profile, capturing a replay, polling a recorder - so it is off by default even though the rest of this group is on. Enable it when you are debugging a profile save, a replay, or a session-setup step rather than the agent itself.

<Note>
  `control` reports the commands a client sends over the CDP proxy that drive the browser - input gestures, navigation, dialogs, file selection, screenshots. It does not report configuration commands or the DOM and Runtime traffic that Playwright and Puppeteer issue on your behalf, and it collapses the phases that duplicate a gesture (`mouseMoved`, `keyUp`, `char`), so one action reads as one event.
</Note>

## Browser activity

These categories report what's happening in the page. Capturing any of them attaches a Chrome DevTools Protocol (CDP) collector to the session and produces highly granular page-level events. Capturing them adds overhead, so enable only the ones you need.

| Category      | Captures                                                     | Event types                                                                                                                                                     |
| ------------- | ------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `console`     | Console output from the page                                 | `console_log`, `console_error`                                                                                                                                  |
| `network`     | Network requests, responses, and failures                    | `network_request`, `network_response`, `network_loading_failed`, `network_idle`                                                                                 |
| `page`        | Navigation and page lifecycle, including performance signals | `page_navigation`, `page_dom_content_loaded`, `page_load`, `page_tab_opened`, `page_layout_shift`, `page_lcp`, `page_layout_settled`, `page_navigation_settled` |
| `interaction` | Browser-native input in the page (clicks, keys, scroll)      | `interaction_click`, `interaction_key`, `interaction_scroll_settled`                                                                                            |
| `screenshot`  | Periodic screenshots of the session                          | `monitor_screenshot`                                                                                                                                            |

<Note>
  `interaction` events are browser-native DOM events observed in the page, not calls to the [computer-control](/browsers/computer-controls) API (those are reported by the `control` category).
</Note>

### The monitor category

`monitor` reports the health of the CDP collector itself: `monitor_disconnected`, `monitor_reconnected`, `monitor_reconnect_failed`, and `monitor_init_failed`.

It isn't directly settable. It flows automatically whenever any of the browser-activity categories are captured. You can still [filter the stream](/browsers/telemetry/streaming) by `monitor` to isolate these events.

## Data sensitivity

Telemetry is off by default, and the default set carries session metadata with one exception: `control` records the source you submit for Playwright execution, because the code is the point of the event. The browser-activity categories are different again: they capture what actually flows through the session, which is your own browser's data and can include credentials and personal information.

| Category                                                 | Can contain sensitive data                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `network`                                                | Request and response headers (including `Authorization` and `Cookie`), request bodies, and truncated response bodies, plus full URLs. A common place for session tokens, credentials, and personal data.                                                                                                                                                                                                                                                                                        |
| `console`                                                | Anything the page logs. Applications often log access tokens, request or response bodies, and personal data through `console.log`.                                                                                                                                                                                                                                                                                                                                                              |
| `page`                                                   | Page URLs and titles, which can embed tokens or identifiers in query strings or fragments.                                                                                                                                                                                                                                                                                                                                                                                                      |
| `interaction`                                            | Text of clicked elements and typed keys, which can include personal data entered into forms.                                                                                                                                                                                                                                                                                                                                                                                                    |
| `screenshot`                                             | A full rendered image of the page - the broadest exposure, capturing anything visible on screen.                                                                                                                                                                                                                                                                                                                                                                                                |
| `control`                                                | The source you submit to the Playwright code-execution endpoint, on the `code` field of `api_call` (clipped to 8192 characters). Whatever your script embeds is captured with it, so a literal password or token in the snippet is captured too. Otherwise session metadata: operation, status, duration, and for `cdp_command` the method, coordinates, and the *length* of submitted text. Typed characters and navigation URLs are never captured; named keys such as `Enter` and `Tab` are. |
| `platform`, `connection`, `system`, `captcha`, `monitor` | Session metadata only (VM-management calls, connection and health events). No page content.                                                                                                                                                                                                                                                                                                                                                                                                     |

Captured events are persisted and can be replayed by [resuming the stream](/browsers/telemetry/streaming#resuming-after-a-disconnect), so this sensitivity applies to the data at rest, not just the live stream. Treat captured telemetry - and anywhere you forward or store it - with the same care as the underlying content. For how Kernel encrypts, retains, and processes data overall, see [Security](/security) and the [Data Processing Addendum](/dpa).

Some exposure is reduced for you automatically: input into sensitive fields such as passwords is suppressed (`interaction_key` isn't emitted for them, and `interaction_click` omits the element text), and `cdp_command` reports how many characters a command submitted rather than the characters themselves (named keys such as `Enter` are reported, since a key name can't be a typed character). Beyond that, because selection is opt-in, the most effective control is to capture only the categories you need - enable `network`, `console`, `page`, `interaction`, or `screenshot` deliberately, and prefer the operational categories when you only need session health.

If you capture `control` and run Playwright code, pass credentials in through variables your snippet reads rather than as literals in the submitted source, so the captured `code` doesn't carry them.

<Warning>
  If you operate under HIPAA, GDPR, or similar obligations, be deliberate about the browser-activity categories: pointing them at a site that handles regulated data captures that data into storage. If your organization has a BAA with Kernel, the `network`, `console`, and `screenshot` categories are disabled and can't be captured. `control` stays available; keep regulated values out of the Playwright source you submit, since that source is captured.

  If you have compliance requirements around what Kernel may process, [contact us](mailto:security@kernel.sh) before enabling them.
</Warning>
