检查清单
Session replay vs heatmaps before Accept: which should you check first?
Replay records a playable visit. Heatmaps aggregate clicks and scrolls. This FAQ says which to check first on Fresh, and how to label Reject. Not legal advice.
In brief
Session replay records a visit as a playable stream of scripts, beacons, and session IDs. Heatmaps aggregate clicks, scrolls, or mouse movement, usually with lighter beacons and shorter IDs. Check both on a clean Fresh visit. Start with vendors already listed. If the inventory is empty, start with session replay hosts, then heatmap hosts on the same capture. Runtime proof shows what fired before Accept. Counsel decides permission. This FAQ is the comparison. The combined checklist is the sibling guide.
Not legal advice
This FAQ explains how session replay and heatmaps differ for a consent audit, and which surface to check first on a clean visit. It is not legal advice, not a vendor review, and not a GDPR, ePrivacy, CPRA, or other certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.
Last updated September 28, 2026. This page does not rewrite the combined before-Accept guide. That guide owns the checklist. This FAQ owns the comparison and the check order.
Short answer
Session replay tools record a visit as a playable stream of scripts, beacons, and often session IDs. Heatmap tools aggregate clicks, scrolls, or mouse movement into density maps, usually with lighter beacons and shorter-lived IDs. For a consent audit, check both on a clean Fresh visit. Start with whichever category your CMP or tag inventory already lists. If neither is listed, start with session replay hosts. They tend to set more persistent IDs and fan out earlier. Then sweep heatmap and UX-analytics hosts on the same Fresh capture.
Runtime proof answers whether either fired before Accept. It does not answer whether counsel would allow that load. ConsentProbe can label Fresh and Reject evidence with request, cookie, and screenshot links. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP.
How the two surfaces differ
Keep the comparison observational. Write present before Accept when a host or ID shows up on Fresh. Leave allowed and forbidden to counsel. One category on the wire does not tell you the other stayed quiet.
| Surface | What it usually does | Typical audit signals | Check order note |
|---|---|---|---|
| Session replay | Records a visit for later playback | Recording hosts, session IDs, early script injects | Prefer first when the inventory is unknown |
| Heatmaps | Aggregates clicks, scrolls, or movement | Heatmap or UX-analytics hosts, shorter IDs | Check the same Fresh capture after the replay sweep |
| Both on one Fresh visit | Either or both may fire before Accept | Hosts, cookies, and storage labeled Fresh | Do not assume one category implies the other is cold |
Which to check first
Use the inventory you already have, then finish the Fresh sweep. The combined checklist and the party labels live on the sibling pages. Do not copy those pages here.
- If the CMP, GTM, or app list already names a replay or heatmap vendor, start there. Still finish a full Fresh sweep.
- If the inventory is empty or unknown, start with session-replay-looking hosts, then heatmap and UX hosts on the same capture.
- If only one category appears on Fresh, record that. Do not call the other category safe without a Reject or Accept control when the claim needs that control.
- For the combined before-Accept checklist, open the session replay and heatmaps guide. For party labels, open the first-party versus third-party guide.
Fresh and Reject on one capture
These steps falsify both categories on labeled visits. The before-Accept audit and the pre-consent checklist hold the longer method. The testing hub says which scenario to run next.
- Use a clean profile. Load once. Do not click Accept.
- Capture Network, cookies, and storage, plus a banner screenshot. Label the pack Fresh.
- Flag replay-looking hosts and IDs, then heatmap and UX-analytics hosts and IDs.
- If Reject All exists, open a new clean profile, click Reject, navigate once, and label the pack Reject.
- Write one finding sentence per distinct host or ID, such as a replay host on Fresh or a heatmap cookie on Fresh.
When sorting hosts gets slow
Sorting replay and heatmap fan-out across themes and apps is slow when you also need host-level proof. Run ConsentProbe Fresh, and Reject when Reject exists, on the storefront URL. Findings stay tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those claims matter. The free versus paid guide draws that line. ConsentProbe does not install a CMP and does not approve vendors for counsel.
FAQ
What is the difference between session replay and heatmaps for a cookie audit?
Replay records a playable visit stream. Heatmaps aggregate interactions. Both can fire before Accept. Verify each on Fresh.
Which should I check first before Accept?
Start with vendors already in your inventory. Otherwise start with session replay hosts, then heatmap hosts on the same Fresh capture.
If heatmaps are cold, is session replay also cold?
No. Check both. One cold category does not prove the other stayed off.
How is this different from the combined before-Accept guide?
That guide is the combined checklist. This FAQ is the comparison for queries that ask which surface to check first.
Does finding either prove a legal violation?
No. Runtime shows what fired. Counsel decides permission. Observation is not counsel permission.
Is this legal advice?
No. These are technical observations. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
This FAQ compares session replay and heatmaps for a consent audit and gives a check order for a Fresh visit. It is not legal advice, not a rewrite of the combined before-Accept guide, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the combined before-Accept guide for the checklist, the before-Accept audit and the pre-consent checklist for the full method, and the testing hub when you need the next scenario.
- Session replay and heatmaps before Accept: what to check
- How to run a cookie audit before Accept
- Pre-consent audit checklist: what to verify before Accept
- Cookie audit hub: which consent test should you run first?
- First-party vs third-party cookies before consent: what should you check?
- Reject All Still Tracking: What to Check After You Say No
- What belongs in a cookie consent audit evidence pack?
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。