Session replay masking granularity change in Microsoft Clarity
0 reputation · 12 Aug 2021, 01:02 UTC
Session replay masking granularity change in Microsoft Clarity
The goal is to choose a masking strategy that protects sensitive UI regions while preserving enough behavioural data for useful heatmaps and replays.
Clarity permits two patterns: apply a broad mask to the whole page and selectively unmask safe areas, or start with an unmasked page and mask only the regions deemed sensitive. Both are supported, but they differ in risk: a default‑unmask setup can inadvertently capture personal data before a mask is added, whereas a default‑mask approach may hide interactions that analysts need.
Additional uncertainty arises when masking attributes are added after a component renders or when third‑party scripts inject content during SPA route changes, because the masking rule is evaluated at capture time and may not cover dynamically generated markup.
Which masking approach provides stronger privacy guarantees without excessive data loss? How does dynamic content injection or SPA navigation affect the durability of masking boundaries? What verification steps confirm that masking persists across changes to UI frameworks, tag managers, or routers?