Exam integrity

Online Exam Integrity: What Browser-Based Controls Can and Cannot Prevent

Plan proportionate controls while understanding the limits of visibility, focus, fullscreen, copy/paste, and event logging.

By
MarkingEase Editorial Team
Published
Reading time
9 minute read

Browser-based controls can discourage some behaviours and provide context for review, but cannot guarantee an assessment is free from misconduct. A sound plan combines clear expectations, appropriate question design, proportionate controls, and a fair process for interpreting events.

What browser events can show

A quiz page can observe events exposed by the browser: whether the document becomes hidden, its window gains or loses focus, fullscreen is active, and copy or paste occurs inside the page. These are session signals, not direct evidence of intent.

Common controls and their limits
ControlCan indicateCannot establish
Page visibilityThe quiz tab became hiddenWhy it changed
Focus eventThe window lost focusWhat was viewed elsewhere
Fullscreen stateThe page left fullscreenWhether another device was used
Copy/paste restrictionA page-level action was blocked or loggedOS-wide clipboard control
Event logA timestamped event occurredThat misconduct occurred

Limits of a browser-only environment

A website does not control the operating system or physical room. Second devices, paper notes, another person, external messaging, and unmanaged browser extensions may remain outside its view. Extensions and accessibility tools vary, so a site should not claim universal suppression or system-level lockdown.

  • Do not describe event detection as proof of cheating.
  • Do not promise prevention of activity the browser cannot observe.
  • Plan for connectivity changes and accidental focus loss.

Use proportional controls

Control intensity should match the stakes, learner context, accessibility needs, and institutional rules. A practice quiz may need only clear expectations. A higher-stakes exam may require supervised conditions, an approved secure environment, or design less dependent on recall.

Design questions that reduce opportunity

Questions requiring application to a supplied scenario are harder to answer by copying a generic definition. Reasonable variation, transparent open-resource rules, and follow-up explanation can be more educationally useful than escalating surveillance.

  • Ask students to justify choices.
  • Use course-specific scenarios without obscure trivia.
  • Make permitted resources explicit.
  • Avoid pressure that measures typing speed instead of learning.

Interpret logs fairly

An event should trigger contextual review, not automatic punishment. Notifications, browser behaviour, network recovery, accidental shortcuts, and assistive tools can create events. Look for patterns, corroborating evidence, and the student's explanation under an established process.

  1. Verify timestamp and session context.
  2. Check for a technical interruption.
  3. Compare the event with published rules.
  4. Give the student an appropriate chance to respond.
  5. Record the human decision separately from raw events.

Set expectations before launch

Tell students which controls are enabled, what may be recorded, which resources are allowed, and how to report technical problems. A low-stakes practice attempt helps students test devices and accommodations.

  • Publish concise permitted-resource rules.
  • Provide a technical help route.
  • Explain that event logs are reviewed in context.
  • Have a fallback for device or connection failure.

Practical checklist

  • Controls are proportionate to stakes.
  • Students know what is monitored.
  • Accessibility needs are addressed.
  • A readiness check is available.
  • Events are not automatic proof.
  • Technical-failure procedures are documented.
  • Questions assess application where appropriate.