OtisDocs

What Otis records

Users, groups and accounts

How Otis identifies the people who use your product, what it knows about them, and how users roll up into groups and paying accounts.

A user is a person who uses your product. Your app names each user with an ID, and Otis follows that user's activity across sessions. A group is a set of users that your app declares, such as a company or a team. An account is the kind of group that pays you.

These are your product's users. They are separate from the members of your team who sign in to the Otis app. This page explains how users are identified, what Otis stores about them, and how groups and accounts are built.

Purpose of users, groups and accounts

Usage happens one person at a time, and buying decisions usually happen one company at a time. A person can be very active inside a company that is about to cancel. Otis keeps both levels, so that it can describe how individuals use your product and how each paying customer is doing.

User identity

Your app sends a user ID with its telemetry. Identity covers the calls.

With the SDK's defaults, Otis never receives the ID your app uses. The SDK replaces it with a hash before it leaves your app, and Otis hashes that value again with a secret that belongs to your project. Identifier hashing describes both steps.

Hashing has four consequences:

  • Otis can't show you a user's name or email address. The Otis app shows a user as the first eight characters of the hash.
  • The same ID gives the same hash. One user's activity stays together across sessions and devices, as long as your app sends the same ID with the same API key.
  • A different API key gives a different hash. The SDK derives its hashing secret from your API key. If two parts of your product use different keys, or you replace a key, Otis sees the same person as two users.
  • IDs are compared exactly. Alice and alice are two different users.

Anonymous users

A visitor who hasn't signed in has no user ID unless you turn on anonymous IDs in the browser SDK. With that option on, the SDK creates an ID and keeps it in a cookie for one year. Anonymous users describes the option.

When the visitor signs in and your app identifies them, later activity carries the signed-in ID. Otis doesn't merge the two: the anonymous visitor and the signed-in user remain separate users.

The user record

Otis knows what your app tells it. Your app attaches properties to a user with setUserProperties, such as a plan, a role or a team size. Otis uses properties to compare groups of users with one another.

  • The latest value wins. Each property holds one value, and a new value replaces the old one.
  • Some properties keep their first value. signup_source, first_seen_date and the three UTM properties utm_source, utm_medium and utm_campaign are set once. You can add your own. Set-once properties describes how.
  • Properties that name a person are dropped. A property whose key is email, name, username or phone is removed before it is stored, and so are many similar keys, such as customer_email. Property key dropping lists them.
  • A property expires after a year without an update. Otis keeps a property for 365 days after its last write.

Otis also writes a description of what each user is trying to accomplish, once it has seen enough of their activity. Intent covers it.

Groups

A group is a typed set of users. Your app declares membership when it identifies a user, by passing a group type and a group ID, such as company and the company's ID. identifyUser describes the call.

  • A user has one group of each type. A user can belong to a company and a team at the same time. A new company replaces the old one.
  • Group IDs are hashed. Otis treats them like user IDs. The group type is part of the hash, so the same ID under two types is two groups.
  • Groups have properties. Your app sets them with setGroupProperties, and Otis keeps the latest value of each. Group properties describes how they are redacted.

Accounts

An account is the commercial unit: the customer that pays you, upgrades, or cancels. In most business products that is a company.

You tell Otis which group type is the account when you configure your project's lifecycle. Until you do, Otis treats each user as their own account, which suits a product sold to individuals.

Otis attributes activity to an account through the user's current membership. If a user moves from one account to another, their earlier activity moves with them.

Reading users and accounts

  • Sign-in splits a visitor in two. With anonymous IDs on, activity before sign-in belongs to one user and activity after it belongs to another.
  • Accounts appear as IDs unless you name them. The Accounts list takes an account's display name from a group property such as account_name or company. Without one, it shows the hashed ID.
  • The Accounts list starts empty. It fills in after you configure which group type is the account.
  • Development traffic is ignored. Identity and property calls sent with a development API key are discarded.

Users and accounts in Otis

The data browser has a Users list and an Accounts list. Opening a user shows their properties, their sessions and their description. Opening an account shows its sessions.

  • Identity covers identifyUser, setUserProperties and setGroupProperties.
  • Privacy covers hashing, anonymous IDs and the property keys that are dropped.
  • Plan and revenue covers telling Otis about each account's plan and what it pays.

On this page