Aggregate numbers. Zero visitor data.
What the dashboard surfaces about your traffic. Four lifetime tiles. Three charts. A session-level breakdown. Hosted-verification delivery numbers. Audit logs for the operations side. No IPs, no fingerprints, no cross-session tracking in any of it.
Site statistics, three angles.
Four lifetime tiles up top. Activity, rejections, and durations as separate charts, because each one tells a different story. Filter by range and by game; the picture changes, the shape stays.
Sessions, one by one.
A row per verification session: game, outcome, duration. Expand any row to see the timestamp breakdown and the score, the same shape the dashboard shows.
| Started | Game | Outcome | Duration | |
|---|---|---|---|---|
| 5/19/2026, 12:04:21 | bubble-popยท OWL | Verified | 4.2s | |
| ||||
| 5/19/2026, 12:04:08 | pattern-matchยท CAT | Verified | 5.8s | |
| 5/19/2026, 12:03:47 | bubble-pop | Pending | โ | |
| 5/19/2026, 12:03:15 | color-sortยท DOG | Verified | 3.4s | |
| 5/19/2026, 12:02:55 | bubble-pop | Verify rejected | 8.9s | |
| 5/19/2026, 12:02:31 | pattern-match | Expired | โ | |
Hosted verification, delivered.
Same dashboard, different shape. Tile totals plus a time-series for webhook and email destinations, with failure modes broken out so you can tell a timeout from a non-2xx.
Operational visibility
Numbers, charts, sessions, hosted-verification telemetry. Aggregate by default, drillable when you need it. No visitor identity in any of it.
Every change has a row.
Three independent logs (account, troop, site key) record every config change and every authorization failure. Filter by principal, action, target, or time range. Export for compliance review. Retention follows your plan; the schema is identical across all three scopes.
| When | Action | Principal | Target | Outcome |
|---|---|---|---|---|
| 5/19/2026, 12:05:48 | site.create | Personal Access Tokentoken | marketingsite | success |
| 5/19/2026, 12:01:14 | token.create | alice@yourdomain.comsession | ci-deploytoken | success |
| 5/19/2026, 11:54:02 | site.update_cap_config | Troop Access Token ยท trp_maintoken | marketingsite | success |
| 5/19/2026, 11:08:35 | site.create | Troop Access Token ยท trp_testtoken | trp_prodtroop | denied |
| 5/19/2026, 09:24:11 | troop.create | alice@yourdomain.comsession | new-producttroop | success |
Where it fits
Compliance audits (SOC2, ISO 27001), incident investigation, internal review of who-changed-what. Authorization failures land here too, useful for spotting permission misconfigurations and unauthorized access attempts before they become incidents.
Common questions
What the dashboard shows you, with no visitor identity in any of it.
- What does Caputchin track about my visitors?
- Nothing that identifies them. No IPs, no fingerprints, no cross-session tracking. Analytics are aggregate counters plus per-session metadata like game, outcome, score, and duration.
- What metrics does the dashboard show?
- Four lifetime tiles and three charts (activity, rejections, and durations), filterable by time range and game, plus a session-by-session log.
- Can I see why sessions failed?
- Yes. The rejections chart breaks out failed completion, failed verify, rate-limit rejection, and blocked challenges, and you can expand any session row for its timestamps and score.
- Are there audit logs?
- Yes, on the Apex plan. Three independent logs (account, troop, and site key) record every configuration change and every authorization failure, filterable and exportable for compliance review.
- Do I get analytics for hosted verification?
- Yes. Per-channel delivery outcomes for webhook and email destinations, with failure modes broken out, on the same dashboard.
See the numbers without watching the people.
Sign up free, ship the widget, and the dashboard fills up with aggregate counters and charts. Per-session detail unlocks on Alpha; audit logs land on Apex.
Start free