Also published on the product site: sla-breaches-while-noc-sleeps-citratest-apm.aspx
CitraTest APM continuous overnight watch – when WaitForImage timers breach SLA after hours, alerts and failure screenshots become the morning handoff, not another green Director tile.
Direct answer: CitraTest APM® keeps scoring on-the-glass SLA limits overnight with the same WaitForImage + StartTimer/StopTimer path daytime ops trust. When a Monitor/Timer breaches while the NOC is asleep, the page carries failure screenshots of where the business screen stopped – so morning handoff starts from glass proof. Playback uses real mouse and keyboard on Citrix, Microsoft RDS, Azure Virtual Desktop, browsers, and thick Windows clients. No CitraTest agents on production session hosts for the glass path. Green overnight Director is not usable glass.
At 03:41 an SLA limit tripped. Login-to-shell crossed the band the shift already agreed to. Nobody was live in the NOC chair – and that is normal for overnight coverage. The morning question is not whether someone watched a chart turn red in real time. The question is whether the alert pack already holds on-glass proof of where the path stopped, so the day shift does not reopen a green workbook and stop there.
That is the overnight SLA problem: breaches still happen when eyes are elsewhere, so the watch has to page with evidence, not optimism.
Green Director overnight ≠ usable glass
Control-plane health overnight is useful – and incomplete. Brokers can answer. Hosts can report calm CPU. Gateways can return 200. None of that times whether the published app, shell, or in-session transaction still appeared on screen inside the SLA. Related: Director Watches Brokers. APM Watches the Screen.
After hours the temptation is to treat green infrastructure as "quiet success." Overnight SLA breaches on the glass reject that shortcut. Success is still a timed screen state – even when the floor is dark.

Illustrative / method diagram – not Tevron customer results. Overnight green brokers do not prove usable glass.
Same glass contract – SLA bands that survive the quiet shift
CitraTest APM does not invent a midnight measurement model. Per User Guide / Quick Start guidance, overnight SLA watches use the same contract as any continuous watch:
- Scripts encode the workflow on a Windows desktop.
- Playback sees the UI with bitmap images (and OCR when text is dynamic).
- Playback acts with real mouse and keyboard.
- WaitForImage synchronizes and verifies expected screen state before the next step.
- StartTimer / StopTimer capture on-screen response: StartTimer immediately after the initiating action; StopTimer immediately after WaitForImage confirms completion.
Prefer static bitmaps for sync cues that do not change. Reserve OCR for values that are unknown ahead of time. OCR is not a wait/sync – confirm readiness with image functions first, then read or assert dynamic text if needed. Keep baseline images small and unique; match display properties between capture and playback machines so overnight "image not found" is a real delay, not theme drift that only shows up on the quiet shift.

Illustrative method diagram – not customer results. That pipeline is what overnight SLA limits actually score.
Publish the path so overnight breaches are actionable
An SLA limit only helps if the Scenario that scores it is the known published version – not a laptop copy someone forgot before the weekend. Apply the same Publish → Scenario → SLA lifecycle used for continuous watches, with overnight breach handoff in mind:
| Piece | Overnight SLA / morning-handoff focus |
|---|---|
| Publish | Send the exe and baseline images to the APM Web Console so agents run a known version when a 03:00 timer trips. |
| Scenario schedule | Prove the path on the interval the quiet hours actually need – successive overnight iterations, not a single 09:00 check that discovers last night's breach too late. |
| Groups / monitors | Attach the timers morning ops will ask about first: login-to-shell, app first paint, and the one or two in-session steps that cannot be invented at standup. |
| Playback endpoints | CitraTestAPMAgent machines with access to the real client path – Citrix Workspace, RDS/AVD client, thick client, browser – ready before the NOC thins out. |
| SLA + alerts | Score up to four response-time limits per Monitor/Timer. Page when a glass step breaches or an iteration fails; attach failure screenshots as the first evidence pack for whoever opens the ticket at dawn. |
Availability for summary reporting can still track successful iterations (Monitor Required Availability) separately from response-time bands. Failover agents can stand by when a primary is silent; they still need Group/Scenario membership so an overnight breach does not depend on a single quiet desktop.
For the full fleet lifecycle, see Publish → Scenario → SLA: Running CitraTest APM as a Continuous Watch. For the unattended-eyes operational question, see Overnight Shift Watch: When Nobody's Looking at the Dashboard. This article is the breach-and-handoff question those posts set up: when the quiet-hour timer exceeds SLA, morning must inherit proof.

Illustrative fleet flow based on the Quick Start APM Web Console chapter – not customer results.
Design the overnight alert as the morning handoff
When the NOC sleeps, the alert is the ticket starter. Design it that way:
- Name timers after moments of truth – first useful pixel / login-to-shell, app or workspace ready, key transaction ready – not after protocol hop labels the day shift will not reopen.
- Set SLA bands from agreed operational limits – what the shift already treats as too slow – then let overnight iterations report whether the path still meets them.
- Treat failure screenshots as first evidence – on-glass proof of where WaitForImage stopped, so dawn triage does not begin with a green Director screenshot and a shrug.
- Page for glass breach, not only for host red – overnight infrastructure calm and overnight glass late can coexist; the alert must say which one happened.
- Do not invent accuracy percentages or fictional ROI – the value of overnight SLA watches is honesty across successive iterations and a clean handoff pack.

Illustrative method diagram – not customer results. Geo shapes are example scenario layouts, not benchmarks.
Hygiene so 03:00 breaches are real
Quiet-shift "breaches" that are really environment debt waste the morning. Keep the overnight SLA watch trustworthy:
- Restore a clean desktop between iterations so leftover windows do not poison the 03:00 run.
- Publish cleanup scripts as standalone monitors when residue would strand the next schedule.
- Use script versioning for phased rollout – avoid assigning conflicting versions of the same script to one agent before a long weekend.
- Match display contracts – resolution, color depth, theme, font smoothing – between capture and playback so night-only "image not found" noise stays rare.
If you already sized concurrency with CitraTest VU, reuse the same visual definition of success in APM. VU answers "how many?" under load; APM answers "did tonight's path still meet SLA – and did the alert pack survive until morning?" Related method posts: Control Plane ≠ Farm, What is on-the-glass APM?.
Closing: let overnight breaches arrive with proof
SLA Breaches While the NOC Sleeps is not a different product mode. It is CitraTest APM continuous monitoring under the assumption that quiet-hour timer breaches still need a morning-ready evidence pack – encode the path with WaitForImage and timers, publish it, schedule it across playback endpoints, score SLA limits, and page with failure screenshots when the glass path is late. Infrastructure metrics still matter for hosts and brokers. They do not replace overnight glass proof that the business screen appeared on time – or the screenshot that shows it did not.
FAQ
What does an overnight SLA breach mean in CitraTest APM?
An overnight SLA breach is a published glass Monitor/Timer that exceeds the response-time limit your Scenario scores while the NOC is thin or asleep. CitraTest APM pages with the failure screenshot of where WaitForImage stopped – so morning handoff starts from on-glass proof, not from reopening a green control-plane workbook.
Why can Director stay green overnight while the glass path breaches SLA?
Director, Azure workbooks, and gateway checks report brokers, hosts, and front-door health. They do not time whether login-to-shell or a key in-session screen appeared inside the SLA. Overnight, that gap widens: control plane green is not usable glass.
How should timers be placed for overnight SLA watches?
Place StartTimer immediately after the initiating action. Confirm readiness with WaitForImage (prefer static bitmaps for sync). Place StopTimer after that wait succeeds. OCR may read or assert dynamic text afterward; OCR is not a wait/sync.
Do overnight SLA watches require agents on production session hosts?
No. For the glass path, CitraTestAPMAgent runs on playback machines with Windows access to the client path. No CitraTest agents are required on production session hosts.
How does this differ from Overnight Shift Watch and Publish → Scenario → SLA?
Publish → Scenario → SLA is the fleet lifecycle that turns a glass script into a continuous watch. Overnight Shift Watch is the unattended operational question – keep proving the path when nobody is staring at a dashboard. This article is the breach-and-handoff question: when an overnight timer exceeds SLA, the alert and screenshot must carry morning-ready proof.
When you need that glass path without agents on production session hosts — schedule a demo. Product pages: CitraTest VU, CitraTest APM, and the Tevron.com blog.
Citrix, HDX, ICA, StoreFront, Workspace, Microsoft, Remote Desktop Services, RemoteApp, Azure Virtual Desktop, and related marks are trademarks of their respective owners. Tevron is not affiliated with those vendors. Names are used for identification only.