Proctoring vs lockdown browsers

Short answer

Lockdown browsers restrict what the browser can do and cannot see other applications. Live and recorded proctoring observes the candidate and their screen but receives a composited image with capture-excluded windows already removed. Desktop detection inspects what is actually running on the machine. They cover different layers and the gap that matters most today — native assistance applications — is only visible to the third.

3 min readUpdated 2026-09-28Assessment Integrity

These three categories get compared as competitors. They are better understood as controls at different layers, each blind to what the others see.

What each one does

Lockdown browsers run the assessment in a restricted browser: no new tabs, no copy-paste, no navigation away, sometimes no other browser processes. Their authority stops at the browser boundary.

Proctoring observes the human — live invigilation, recorded video for later review, or automated flagging of behavioural anomalies. It usually includes a screen recording.

Desktop detection inspects the operating system: which processes are running, which windows exist, whether any are marked excluded from screen capture, whether the session is a remote-access connection or a virtual machine.

Coverage, honestly stated

ThreatLockdown browserProctoringDesktop detection
Second browser tabCoveredPartiallyCovered
Notes on paperNoCoveredNo
Phone or second deviceNoPartiallyNo
Native AI overlay appNoNoCovered
Remote-access takeoverNoSometimesCovered
Virtual machineSometimesNoCovered
Second person off-cameraNoAudio analysisNo
Impersonation / deepfakeNoIdentity checkSupporting signals

The row that matters is the overlay application. Neither of the two most widely deployed categories can see it — lockdown browsers because it is outside the browser, proctoring because the operating system removes capture-excluded windows from the recording before the proctor ever receives it.

Combining them properly

No single layer is sufficient, and the sensible architecture uses each for what it is actually good at:

Evidence quality matters more than flag count

A system that produces many probabilistic flags creates a review burden and a defensibility problem. If you are going to act on a finding — fail an exam, withdraw an offer — the finding must withstand challenge.

Prefer determinations of the form: this named process was running during the session, with this hash, at these timestamps. That is checkable. "Behavioural anomaly score 0.72" is not something you can put in front of an appeals committee.

Keep the two categories clearly separated. Some questions are binary and should produce verdicts; others are probabilistic and should produce signals a human weighs. Presenting a signal as a verdict is how institutions end up in disputes they lose.

Process and fairness

Technical controls sit inside a process that has to be fair, and that process is where most challenges succeed:

Frequently asked questions

Do lockdown browsers still work?

For what they were designed for, yes. They stop tab-switching, copy-paste, and local file access, which remains a real category of cheating. They do not address native applications or remote assistance, and vendors sometimes imply broader coverage than they deliver.

Is automated proctoring accurate enough to act on?

Automated behavioural flagging is best used to prioritize human review, not to decide outcomes. False-positive rates on behavioural signals are high enough — and the consequences serious enough — that acting without human review of the underlying evidence is both unfair and legally risky.

Can we do this without recording video?

Yes, and for some contexts it is preferable. Desktop-level environment detection plus identity verification produces strong technical signal without retaining continuous video, which reduces privacy exposure and data-retention burden considerably. Whether that is sufficient depends on your threat model.

What about in-person exams?

In-person removes remote-access and some device threats but not all of them — phones, smart watches, and earpieces remain. In-person assessment on institution-managed machines with desktop detection is the strongest available configuration.

How do we handle candidates with accessibility tools?

Build an accommodation path that is established before the assessment, with approved assistive software recorded in advance so it is not flagged as unauthorized. A detection system that cannot distinguish a screen reader from a cheating overlay will produce discriminatory outcomes, which is both wrong and actionable.

Guardian Robotics is an AI consultancy.

We build the pipelines, agents, and automation this article describes — for commercial teams and federal agencies alike.