Interaction Telemetry Guardrails
Collect useful interaction signal without recording what people type or read.
What it adds
Redaction, sampling, and consent rules applied to interaction events before they leave the browser.
What your agent is told to do
5
What your agent is told to do
5-
1
Set the default to sending no content. An event records that a thing was interacted with, its type and its identifier; it does not record the text inside it unless that field is explicitly listed as safe.
-
2
Redact at the point of collection rather than after ingestion. Once a customer's message body reaches the analytics vendor, deleting it is a support request to a third party and a disclosure you have already made.
-
3
Sample the high-frequency signals — scrolling, hovering, typing, resizing — at a rate recorded on the event itself, so the numbers can be scaled back up correctly instead of being read as raw counts.
-
4
Honour the user's consent choice and the workspace's privacy configuration before anything is queued, and drop the queue when consent is withdrawn rather than sending what was already collected.
-
5
Distinguish an action a person took from a change the interface made. Restored scroll positions, programmatic focus, prefetches, retries, and automated tests all produce interaction-shaped events that are not interactions.
Edge cases it handles
7
Edge cases it handles
7- Private content leaks through the least obvious properties: a page title containing a customer name, a URL path with an email in it, a form label carrying a filename. Redaction must cover titles, paths, labels, and error text, not only field values.
- High-frequency events dominate the volume and the cost while carrying little information per event. Sample them, and record the sampling rate on the event so nobody later reports a tenth of the real number as fact.
- Consent and workspace privacy settings are checked before an event is queued, not before it is sent. A queue built up in advance and flushed after a refusal is exactly the outcome consent was supposed to prevent.
- Events generated by the app rather than the user — restored state, automated retries, synthetic monitoring, test runs — must be excluded or clearly marked, or engagement metrics will measure the software's own behaviour.
- The volume of events must be bounded so a stuck component cannot flood the queue and the network from a single session.
- Some jurisdictions and enterprise workspaces require regional storage or complete opt-out, so the destination and the ability to send nothing at all must both be configurable.
- A retention period has to be set deliberately for interaction data, because the default in most tools is longer than any legitimate use of it.
Definition of done
9
Definition of done
9- Events carry no user-entered text, and safe fields are enumerated explicitly rather than assumed.
- Redaction happens in the browser before any event is transmitted.
- High-frequency events are sampled and each event states the rate it was sampled at.
- Consent and workspace privacy are evaluated before an event is queued, and withdrawal drops the pending queue.
- App-generated interactions are excluded or distinctly marked.
- Per-session event volume is capped.
- Destination region, opt-out, and retention period are configurable and documented.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Data Table Cell Primitives
Data Table Cell Primitives
Render every kind of table cell the same way, wherever the table happens to be.
What it does
A shared set of cell renderers for numbers, dates, people, statuses, links, and row actions, used by every table in the app.
How it works
- 1 Catalogue the cell types the app's tables already render and reduce them to a small set: number and currency, date and relative time, person or avatar, status or badge, link or identifier, and an actions cell.
- 2 Separate each cell's underlying value from its presentation, so sorting, filtering, grouping, and export operate on the raw value while the user sees the formatted one.
- 3 Align and format numerically consistent cells the same way everywhere — figures right-aligned with tabular figures and a fixed precision per column, dates in the user's locale and time zone, currency with its code where more than one is possible.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/data-table-cell-primitives
Segment Event Forwarding
Segment Event Forwarding
Send one clean stream of product events to Segment and let it fan out downstream.
What it does
A documented event schema and a single forwarding path emitting track, identify, group, and page calls with consistent identity.
How it works
- 1 Write the event schema before writing any code: the exact set of event names, the properties each carries with their types, and the traits attached to a user and to an account. Every downstream tool inherits this schema, so a name chosen carelessly is expensive to change later.
- 2 Establish one identity model and apply it everywhere. Use a stable internal user identifier that never changes, associate the anonymous identifier from the first visit with it at signup, and attach the account or workspace so downstream tools can roll events up by customer.
- 3 Route every event through one internal emitter rather than calling the provider from feature code. That emitter validates the event against the schema, drops or flags anything unrecognised, and is the single place where identity and default properties are attached.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/segment-event-forwarding
Google Analytics Server Events
Google Analytics Server Events
Report confirmed outcomes to Google Analytics when browser tracking cannot be trusted.
What it does
Server-side delivery of completed conversions to Google Analytics, joined to the browser session and deduplicated against it.
How it works
- 1 Identify the outcomes the browser cannot see or reports unreliably — a payment confirmed by a webhook, a subscription that renewed, a signup completed after a redirect, anything blocked by an ad blocker — and send those from the server.
- 2 Capture the analytics client identifier from the browser when the visit begins, store it against the session or the record, and send it with the server event so the conversion joins the same session and campaign rather than appearing as a new anonymous visit.
- 3 Generate a stable event identifier at the moment the outcome happens and use it for both the browser and the server send, so the provider can collapse the pair into one event. Assign each event type a primary origin and treat the other as the fallback.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/google-analytics-server-events
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.