
Director is green. Azure workbooks are green. The session hosts are at 40% CPU. The help desk still has a queue of “Epic is slow” and “my desktop took forever.” That gap is not a mystery of bad users. It is a measurement gap. Most of what you watch in a Citrix, Microsoft RDS, or cloud VDI estate never times what appeared on the user’s screen.
On-the-glass APM is the name for closing that gap: application performance monitoring that measures response time and availability from the real user GUI — login-to-shell, published-app launch, and the in-session steps people actually wait on — using the same visual path a person takes. This post is the plain definition for EUC and VDI teams in 2026, and how it fits next to protocol counters, host metrics, and full-stack observability. The short answer page lives on tevron.com as What is on-the-glass APM?.
What “the glass” means
In EUC, the glass is the endpoint screen. HDX and RDP deliver a bitmap. The published desktop or RemoteApp does not hand the client a DOM event that means “the chart appeared.” The user knows the step finished when the pixels say so. On-the-glass monitoring takes that same signal seriously: image recognition and OCR against a baseline of what “done” looks like, then time from the click or key until that state is visible.
A connected session is not a usable desktop. A usable desktop is not a painted chart.
That is why a Workspace URL returning 200, an RDP connection that “succeeded,” or a green ICA RTT tile can all coexist with a nurse waiting fourteen seconds for Hyperspace. The control plane answered. The glass did not.
Four views of the same session

You already run several of these. Keep them. Do not confuse them.
- Host / infra — CPU, memory, disk, profile IOPS. Essential. Green hosts are still not proof the published app painted.
- Protocol — ICA / HDX, RDP round-trip, Gateway health. Useful for the remoting path. Can miss a slow thick client that is already “in session.”
- Full-stack APM / observability — traces, logs, code, infra for the services you own. Strong for web and microservices. Often weak on the published GUI path that HDX and RDP remoting hide behind pixels.
- On-the-glass APM — synthetic transactions that drive the real Workspace, AVD, or Remote Desktop client and time screen-ready states. That is the user SLA for Citrix and RDS.
Protocol metrics answer “is the remoting path healthy.” On-the-glass answers “did the business transaction complete on the screen.” The HDX vs real user experience note on tevron.com is the same split in product language.
How on-the-glass APM typically works
The pattern is synthetic, not agent-on-VDA:
- A robot logs on like a real user — Citrix Workspace, RDP, or a cloud client, including the Gateway or portal hop you actually use.
- It drives keyboard and mouse through a business transaction: open Epic Hyperdrive or Hyperspace, search a patient, open a chart; or launch SAP, search, open the record.
- Image recognition (or equivalent visual checks) waits until the expected screen state appears and records the time for each step.
- Results feed SLAs, alerts, trends, and screenshots on failure — around the clock, not only during a load test.
Nothing needs to be installed on the session hosts, VDAs, or RDSH for that path to work. The synthetic is another client. That matters in locked-down healthcare and finance images where agent politics can stall a project for months.
When the glass view pays for itself
Use on-the-glass APM when the business owns a published experience and the tickets already say so:
- Morning logon storms — shift start, failback, Autoscale powering a cold pool. Host CPU can look fine while FSLogix attach or GPO stretches login-to-shell. Pair this with the logon storm vs density split: storm numbers and density numbers are different jobs.
- EHR and thick clients — Epic, Cerner, and similar apps on Citrix, AVD, or RDS. A Workspace or AVD URL test is not an EHR test. See Epic and EHR on the glass.
- After go-live and image changes — new VDA, new Workspace app, Windows feature update, FSLogix policy, extra published app. Capacity tests size the change. Continuous glass watch catches the regression at 8 a.m. on Tuesday.
- Whenever Director is green and users are not — that is the classic symptom. Do not argue about feelings. Time the glass.
Lab density is not the morning watch

On-the-glass is an idea, not a single product SKU. In the lab, you use it to produce a concurrent-user number a CAB can defend: freeze the image, walk the real path, ramp and sustain, run the login storm separately, stop at a written experience budget. That is the 2026 method in How to Load Test Citrix Virtual Apps and Desktops, Microsoft RDS, and cloud-hosted virtual apps and desktops.
In production, you reuse the same glass path continuously. The lab answered “how many good sessions fit on this SKU.” The morning watch answers “is today’s logon-to-shell and open-chart still inside the SLA.” Tevron’s product names map cleanly: CitraTest VU for capacity from the glass, CitraTest APM for the continuous watch. Same visual approach. Different cadence.
What this is not
- It is not a replacement for Citrix Director, Monitor, or Azure Virtual Desktop workbooks. Keep those for broker and host health.
- It is not an HTTP soak of the Workspace or RD Web URL. Keep that for the front door.
- It is not “we have Dynatrace / New Relic / Datadog, so we are covered.” Those platforms are excellent for services they instrument. Published HDX and RDP GUIs are a different problem.
- It is not a promise that last quarter’s on-prem number travels with a cloud catalog. Re-test density when the SKU, image, Connector, or autoscale schedule changes; keep watching the glass either way.
Write the SLA the glass can keep
A useful on-the-glass SLA is boring and specific. Example language teams already use on capacity plans — schematic only, not a customer dataset:
- Logon to a usable desktop: 45 seconds at p95, 60 seconds at p99.
- Launch the published line-of-business app, search, open the record: 8 seconds at p95.
- Fewer than 1% of synthetic runs fail, disconnect, or hang in the watch window.
Put those numbers next to host and protocol charts on the same timeline. When p95 “open chart” jumps, you want session-host CPU, profile IOPS, and Gateway or Cloud Connector health in the same hour — not a war room guessing which layer broke.
Take the signal users already send
On-the-glass APM is not a new philosophy of monitoring. It is admitting that for Citrix, RDS, AVD, and Windows 365, the user’s truth lives on the bitmap. Measure that truth with synthetics that look like real clients. Keep Director and observability for the layers they own. Size density in the lab; watch the glass every shift.
When you need that path without agents on the session hosts — real Workspace or Remote Desktop client, image and OCR, screenshots on failure — Tevron’s CitraTest APM is built for the continuous watch, and CitraTest VU for the same glass under load. Start from the on-the-glass APM answer or schedule a demo.