How sessions are counted
A session is a container. Analytics groups everything one person does on the site into a single visit, so that a report can say how many times the site was used rather than only how many things happened.
In GA4 the container opens with a session start event, triggered by the first activity from that browser, and closes after a set period of inactivity — the timeout is a setting you can change, not a fixed law. Every event recorded in between carries the same session identifier. Two behaviours surprise people who came from the older Universal Analytics: a GA4 session does not end at midnight, and it does not restart when the visitor arrives again from a different campaign. One person clicking an ad, leaving, and returning from an email a few minutes later stays inside one session.
Sessions also carry their own dimensions. Session source and medium describe how that particular visit started, which is a different question from how the person first found the site, and the two are reported separately for good reason.
Why sessions matter
Sessions are the unit most reporting is built on. Traffic by channel, landing page performance, conversion rate and bounce-style engagement metrics all divide by sessions somewhere, so if the definition is misunderstood every derived number is misread with it.
They are also the closest thing to a visit, which is how business owners naturally think. Someone browsing on the bus, thinking it over, and coming back that evening genuinely is two visits, and describing that as two sessions and one user is an honest account of what happened.
Common mistakes with sessions
The first is treating a session as a person. It is one visit, and a keen prospect can produce a run of them in a week.
The second is expecting sessions to match ad clicks. They cannot: people abandon during loading, decline consent, block scripts, or return within a session that is already open. A stable gap is normal.
The third is a broken journey. If the site sends visitors to a booking or payment page on another domain without cross-domain tracking configured, one visit is split into two sessions and the second is credited to your own site as the source, which quietly rewrites the whole channel report.
The fourth is comparing sessions across tools, or across a change in the timeout setting, without saying so.
How to act on it
Agree one traffic metric for reporting and stick to it, so nobody is comparing sessions in one document with users in another. State the timeout setting somewhere in the documentation and note the date if it is ever changed.
Configure cross-domain tracking wherever the journey leaves the site, and check the session source report for your own domain appearing as a referral — that is the clearest sign it is missing. Then read sessions with engaged sessions and key events alongside, so volume is judged next to whether anything came of it. Getting these definitions right at the start is the least glamorous part of a GA4 setup and the part that saves the most argument later.