# The scan map

See where your products are scanned, on a map aggregated by place, with a heat layer and a layer of geographically impossible sequences.

Source: https://docs.sealtrust.io/en/console/carte-des-scans/

---

This screen shows where your products are scanned. Scans are grouped by place
and drawn as circles proportional to volume. You open it to read the real
geography of your scans, and to spot geographically impossible sequences
between two scans of the same identifier.

![Console scan map, with its layers and its top locations table](/console/carte-des-scans.en.webp)

## What the screen shows

Three counters at the top: "Total scans", "Locations" and "Countries". Four
period buttons, "7 days", "30 days", "90 days" and "1 year", and a brand
selector.

Four toggles drive the map: "Scans", "Heatmap", "Clones & gray market" and "GPS only". When the screen opens, only
"Scans" is on and "GPS only" is off.

Below the map, a legend: "The map only shows scans whose device sent its own
position. Every dot is therefore a real position, accurate to about 1 km." When
some scans carry no position, a second sentence gives their number and recalls
that they are counted in the totals without appearing on the map.

The "Scan detail" panel gives the location, where it comes from, the number of scans at that spot, the share of the
total, the country and the coordinates. The "Top locations" table lists at most
25 rows.

## What you can do here

Change the period, which is 30 days when the screen opens. Turn each of the
three layers on or off. Restrict the table and the location counter to the
positions sent by a device alone, with "GPS only". Click a table row to center
the map on it and open its detail. "Refresh" restarts the read.

The NFC and QR split does not exist here: the channel is frozen on every scan,
with no selector.

## What conditions access

The "Scan map" entry lives in the "Analysis & Audit" section, with no plan lock
and no profile hiding, and the content waits until the account is recognized as
an administrator. The brand selector is locked and pre-selected when the
account holds a single brand. Scope is applied server-side, every scan being
tied to its product and therefore to its brand. A row only becomes clickable,
and a dot is only drawn, if the latitude and the longitude are there.

## What the screen refuses

The provenance label follows the recorded value, "GPS", "GPS + IP city" or "IP
only". The mere presence of coordinates is only a fallback. A cell that mixes
several provenances carries the least reliable one it holds.

Only the `sdm_verify_url` and `qr_scan` steps feed the map, NFC session
telemetry being left out, as are the link-preview robots. The pair of
coordinates close to zero, a geocoding artefact, is brought back to an absence
of coordinates. Scans are grouped in a grid of cells of about one kilometre,
and the read stops at 25 pages of 200 places, that is 5000 aggregated
locations.

The clone layer only draws segments of the `geo_impossible` type and ignores
two scans with identical coordinates.

<!-- garde-fou-relu: the control described here REFUSES, it lets nothing through; what is published is an inert display toggle, not an open door -->
When it cannot be read, the map stays on screen and its toggle is disabled,
with the "Clone overlay unavailable" tooltip. That is what an account with no
accessible brand gets.
