These three categories get compared as competitors. They are better understood as controls at different layers, each blind to what the others see.
What each one does
Lockdown browsers run the assessment in a restricted browser: no new tabs, no copy-paste, no navigation away, sometimes no other browser processes. Their authority stops at the browser boundary.
Proctoring observes the human — live invigilation, recorded video for later review, or automated flagging of behavioural anomalies. It usually includes a screen recording.
Desktop detection inspects the operating system: which processes are running, which windows exist, whether any are marked excluded from screen capture, whether the session is a remote-access connection or a virtual machine.
Coverage, honestly stated
| Threat | Lockdown browser | Proctoring | Desktop detection |
|---|---|---|---|
| Second browser tab | Covered | Partially | Covered |
| Notes on paper | No | Covered | No |
| Phone or second device | No | Partially | No |
| Native AI overlay app | No | No | Covered |
| Remote-access takeover | No | Sometimes | Covered |
| Virtual machine | Sometimes | No | Covered |
| Second person off-camera | No | Audio analysis | No |
| Impersonation / deepfake | No | Identity check | Supporting signals |
The row that matters is the overlay application. Neither of the two most widely deployed categories can see it — lockdown browsers because it is outside the browser, proctoring because the operating system removes capture-excluded windows from the recording before the proctor ever receives it.
Combining them properly
No single layer is sufficient, and the sensible architecture uses each for what it is actually good at:
- Desktop detection for the technical environment — restricted processes, capture-excluded windows, remote access, VMs. This is where binary, defensible determinations come from.
- Camera and audio analysis for the physical environment — second people, secondary devices, absence, and identity verification against a reference image.
- Lockdown for casual convenience cheating, which is still real and worth preventing.
- Cohort analytics to surface statistical outliers you would not otherwise examine.
Evidence quality matters more than flag count
A system that produces many probabilistic flags creates a review burden and a defensibility problem. If you are going to act on a finding — fail an exam, withdraw an offer — the finding must withstand challenge.
Prefer determinations of the form: this named process was running during the session, with this hash, at these timestamps. That is checkable. "Behavioural anomaly score 0.72" is not something you can put in front of an appeals committee.
Keep the two categories clearly separated. Some questions are binary and should produce verdicts; others are probabilistic and should produce signals a human weighs. Presenting a signal as a verdict is how institutions end up in disputes they lose.
Process and fairness
Technical controls sit inside a process that has to be fair, and that process is where most challenges succeed:
- Disclose before the assessment what is monitored and how.
- Have an appeals path with human review of the underlying evidence.
- Accommodate legitimately — assistive technology, non-standard setups, and disability accommodations must not be treated as evasion.
- Set proportionate consequences and do not act on a single weak signal.
- Retain evidence only as long as the process requires.
Frequently asked questions
Do lockdown browsers still work?
For what they were designed for, yes. They stop tab-switching, copy-paste, and local file access, which remains a real category of cheating. They do not address native applications or remote assistance, and vendors sometimes imply broader coverage than they deliver.
Is automated proctoring accurate enough to act on?
Automated behavioural flagging is best used to prioritize human review, not to decide outcomes. False-positive rates on behavioural signals are high enough — and the consequences serious enough — that acting without human review of the underlying evidence is both unfair and legally risky.
Can we do this without recording video?
Yes, and for some contexts it is preferable. Desktop-level environment detection plus identity verification produces strong technical signal without retaining continuous video, which reduces privacy exposure and data-retention burden considerably. Whether that is sufficient depends on your threat model.
What about in-person exams?
In-person removes remote-access and some device threats but not all of them — phones, smart watches, and earpieces remain. In-person assessment on institution-managed machines with desktop detection is the strongest available configuration.
How do we handle candidates with accessibility tools?
Build an accommodation path that is established before the assessment, with approved assistive software recorded in advance so it is not flagged as unauthorized. A detection system that cannot distinguish a screen reader from a cheating overlay will produce discriminatory outcomes, which is both wrong and actionable.
