One password,eleven machines.
Every session returns the id of the machine behind it, so a seat shared across a team stops reading as one person.
Two machines do the work on this account
The number of sightings per machine is what makes sharing visible.
The two the account works from sit at 412 and 168 sightings.
SHAREDThree cities held the same session open
A password check never asks which machine is holding the session, so the overlap stays invisible to it.
Your own browser answers every question the roster asks
identity.device_iddevicenetworkidentity.first_seenvelocity.deviceidentity.degradedOne call on the client, one row per machine
import { useTrustSig } from "@trustsig/react";
const { getResponse } = useTrustSig();
const { token } = await getResponse();import { TrustSig } from '@trustsig/server';
const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY });
app.post('/session', async (req, res) => {
const token = req.headers['x-trustsig-response'];
const { identity } = await ts.verifyRemote(token);
// degraded marks an id a large cohort shares, so it names a crowd.
if (identity.degraded) {
return openSession(req, res);
}
// Your table: one row per machine per account, keyed on the id.
await seats.record(req.user.id, identity.device_id, {
first_seen: identity.first_seen,
returning: identity.returning,
});
const seen = await seats.distinctSince(req.user.id, '30d');
if (seen.length > SEAT_LIMIT) {
return flagForReview(req.user.id, { machines: seen.length });
}
return openSession(req, res);
});What a device roster does not claim
- A family shares a laptop and pays for one seat
identity.device_id - A household machine returns one id however many people use it, so the roster can show fewer machines than there are people.
- Travel is not a second person
network - The id is read in the page, so moving to a new city changes the network reading and nothing else.
- Some ids name a cohort
identity.degraded - A locked-down browser can produce an id a crowd shares, which inflates a seat count if you read it as a machine.
- Only machines appear in the set
identity.linked_devices - Two ids that resolve to one machine are reported as linked. Who sits behind them is a question for TrustSig Pro.
Shared logins, answered
By the shape of the set, not its size. A person's own machines recur: the same three ids sign in week after week from the same city. A shared password produces ids that appear once, from networks that have nothing to do with each other, and the account's set keeps growing.
identity.device_id per session, identity.first_seen and identity.returning for whether that machine has been here before, and velocity.device for how often the project has seen it.
No. The reading happens in the page, so the id is the same whichever exit the request arrives from, and the connection is reported separately in the network block. A customer abroad reads as the same machine from a different country.
You can see two different device ids in overlapping sessions, which no password check can show you. Whether both are the account holder is a question about people rather than machines.
identity.degraded marks an id a whole cohort shares, which a locked-down browser can produce, so it shows up before you count seats. A household machine is one id with several people behind it, not an extra seat.
TrustSig Web reports the machines. Linking one device set to another account, and naming the person behind it, is TrustSig Pro.
Give every account its own roster.
One script tag, one server call, and the roster starts filling at the next sign-in.