Choose what will be used
Anything a product depends on is added for you. Counts update as you go.
Nothing chosen yet
Pick a product on the left to see the URLs it needs and why.
Upload a capture
A HAR file is what the browser records in its Network tab. Comparing one against the registry is the only way to know which hosts a product really needs.
For staff-only hosts it is the other dimension: a staff session and a pupil session of the same product, both unchallenged.
What is kept: host names, how many requests each served, how many failed, and one path per host with the query string removed. The HAR itself is never saved — it contains cookies and sign-in tokens, and none of that is needed to answer which hosts were contacted.
What was this a capture of?
Which products were being used?
Needed to tell "this host is not required" from "the session never opened that screen". Without it a capture can still show what is MISSING, and nothing else.
Anything else worth knowing?
Captures on file
Each one is evidence, and what it can prove depends on what it can be compared with. Two captures that differ in one dimension answer a question; two that differ in both answer nothing.
What the captures propose
Proposals only. Marking a URL staff-only or two-factor-only takes it out of a pupil's list, so nothing here is applied until somebody says so.
Audit
Only checks that can be decided from the data, so every finding is one you can apply yourself and get the same answer. Where judgement is needed it says what to go and find out rather than what to do.