Observe a live session
Observe a live Overwatch recording from the Method Platform: review the terminal as it streams in, triage Object Findings into the Ontology, contribute notes and commands back to the Timeline, and draft a Report from the session.
This guide covers the in-platform workflow. For installing the binary and starting a recording, see Run an Overwatch session.
Review the Timeline
Each command run in the terminal appears as a row in the Timeline, with its timestamp, the command, the full output, and any Object Findings tied to it.
- Click a row to open the Selection panel on the right.
- Use the panel’s tabs to inspect the command:
- Details: full command, output, and metadata
- Suggestions: AI-generated next steps for this specific command
- Object Findings: Objects extracted from the command’s output
- Use Star, Add Note, or Add to Report to mark content that should feed the final deliverable.
Triage Object Findings into the Ontology
As commands run in the terminal, Object Findings populate the Object Findings view. Each Object Finding is a candidate Object (host, IP, FQDN, service, credential, and so on) that has not yet entered the Ontology.
- Review each Object Finding against the relationship graph alongside the list.
- Accept Object Findings that are real and belong in the Ontology. Accepted Objects stay in the Ontology and are immediately available to Method AI Agents and other Tools.
Accept early and often. Downstream Chat suggestions improve once Object Findings are in the Ontology.
Push context back to the terminal
Use the action bar at the top of the session view to contribute directly to the Timeline:
- Add Note: drop a written note inline with the terminal commands
- Paste Command: push a suggested command for the person at the terminal to execute
- Upload File: share research, a screenshot, or a context file
Anything you add appears in the terminal view alongside the recorded activity. This is how you direct without interrupting.
Use Chat for deeper reasoning
Your Chat has access to the session’s Timeline and the Ontology. Use it for:
- Sequencing the next several steps of the operation
- Comparing new Object Findings against existing Ontology data
- Drafting Report content from starred commands and notes
To scope a Chat response to a single command and its output, attach that Timeline event as context before asking your question.
Put Agents to work
You do not have to drive every step yourself. Agents run against the same session context you do: the live Timeline, the Ontology, and your notes. Bring them in to:
- Investigate an Object Finding while you keep moving
- Draft Report content from session evidence
- Propose the next command for you to review before you run it
Agent Policies govern what an Agent can run and where, so you stay in control. The more you lean on Agents, the more of the session they can carry.
Draft and export a Report
Ask Chat to write a Report and it will, pulling from the session’s starred commands, accepted Objects, and notes. An Agent can draft one the same way. A Report can cover a focused slice of the session or the full operation. The more disciplined the triage during the session, the higher quality the draft.
You can generate a Report at any point during the session and export it once the session ends.
Tips
- Triage Object Findings as they appear. A backlog of unreviewed Object Findings degrades Chat’s suggestions.
- Star commands as they happen. Reconstructing what mattered after a session ends is much harder.
- Use Paste Command for tradecraft handoffs. The person at the terminal retains discretion to run, modify, or ignore. The command is one click away regardless.
- Delegate to Agents. Hand off investigation and Report drafting so you stay focused on the next move.
Open a live terminal mirror
Overwatch allows you to view a contributor’s terminal in the browser, exactly as they see it on their machine.
Navigate to the Sessions tab. Active recordings appear in the Live Sessions list. Past recordings appear in Archived Sessions. Click into any active session to attach to its real-time feed.