A session signature is a derived representation of how the operator of a session interacts, established early in the session and used as the baseline that later activity is compared against. It is composed of aggregate numbers and a hash rather than raw input, so it cannot be reversed into keystrokes or pointer traces. Drift past policy thresholds is what indicates the operator may have changed, which is the detection path for session hijacking after login.