Yes, unless we actively track user activity in the dashboard, this is quite useless when that browser session had a still valid accessToken or OpenID session.
Same goes for apps, only here the platform has even less control and no way to track unless we would inject some javascript, which we really shouldn't