Institutional sign-in
Candidates authenticate with the Microsoft account their institution already issues them. No separate exam password to reset the morning of the paper.
- Microsoft Entra ID
- Single sign-on
Instructions
Six sections, following a sitting from enrolment through to the board of examiners. Every control listed here is a switch your examinations office can set — nothing on this page requires a custom build.
| Section | Covers | Section | Covers |
|---|---|---|---|
| A · Identity | Who is sitting the paper | D · Evidence | What gets written down |
| B · Monitoring | What happens in the room | E · Administration | Who may do what |
| C · Lockdown | What the machine may do | F · Integrations | What it plugs into |
Half of the disputes in remote assessment are about identity. Settle it at check-in, then keep checking quietly for the rest of the sitting.
Candidates authenticate with the Microsoft account their institution already issues them. No separate exam password to reset the morning of the paper.
A capture at check-in is matched against the enrolment record, so the person who logged in is the person at the desk.
The live feed keeps matching against the check-in capture for the duration of the paper. A swap partway through raises an event.
Camera, microphone and resolution are tested against your minimum before the candidate is admitted, not after they have started writing.
Detection runs on the candidate's device throughout the sitting. Each monitor produces a typed event, and each event type is classified in advance as expected or worth a reviewer's attention.
Raises an event when no face is in frame, when the candidate turns away for a sustained period, or when a second person appears behind them.
Matches the live feed against the identity captured at check-in, so a substitution mid-sitting is caught rather than discovered at marking.
Flags phones, tablets, additional screens and printed notes entering the camera's field of view.
Detects speech in the candidate's environment. It records that talking occurred; it does not keep a transcript of what was said.
Monitoring tells you what happened. Lockdown stops most of it happening. Both matter — the second one is what keeps your review queue short.
Each control below is independent. An open-book paper might keep the browser usable while still blocking second displays; a professional board exam turns everything on. The right-hand column is the state each control ships in.
Blocks recording and sharing of the exam screen from the candidate's device.
Refuses the session when the display is being mirrored to another output.
Requires a single connected display. Off by default, since many candidates use a laptop with a dock.
Suppresses OS and browser shortcuts that would move the candidate out of the paper.
Disables clipboard use in and out of the exam window.
Releases the camera the moment the sitting ends, so nothing runs between exams.
Named applications must be closed before the paper will open. The list is maintained by your registry.
Sets the floor a candidate's webcam must meet, in pixels, before check-in passes.
An appeal is decided weeks later by someone who was not there. Everything below exists so that person can reconstruct the sitting without watching it in full.
Webcam stills, webcam video, screenshots and screen recording — all stamped against one session clock so they line up.
Each capture carries the event that produced it, and each event type is pre-classified as expected or requiring review.
Reviewers open on the flagged moments, jump to the frame, and record a decision. Cleared items drop out of the queue.
Per-candidate and per-cohort summaries, built for an academic integrity file rather than for a dashboard screenshot.
Exam data is some of the most sensitive an institution holds. Access is granted by explicit permission, and anything not granted is refused — including on the API, not only in the interface.
Build the roles your institution actually has, and assign them to staff without a code change.
An endpoint with no matching permission refuses the request. Access is never granted by omission.
Staff see only the screens their role allows, so training is about the job rather than about what to ignore.
Override any proctoring control for a named candidate where an access arrangement calls for it.
Publish your own exam guidance to candidates and staff inside the product, so the rules travel with the sitting.
Roles · effective permissions
| Role | Can |
|---|---|
| Registry | Set proctoring policy, manage exams, read every report |
| Faculty | Manage their own courses and see their candidates' sessions |
| Reviewer | Work the review queue and record cleared or flagged decisions |
| Support | Read session status to help a candidate mid-sitting |
| IT | Manage roles, integrations and client releases |
Roles are yours to define. These are the five most institutions start from.
fcProctor is the invigilation layer. Your LMS stays the course record and your directory stays the identity record.
Exam courses are created in Moodle and candidates and teachers are enrolled automatically when the exam is set up here. Enrolment runs in the background so a large cohort does not hold up the page.
Staff and candidates sign in with their institutional Microsoft account. Joiners and leavers follow your directory, and fcProctor never holds a password.
An authenticated REST API and outbound webhooks let your student records system pick up session outcomes without anyone exporting a spreadsheet.
Requiring a particular laptop is how a proctoring rollout fails. The exam client ships for Windows and macOS, the machines students already bring.
| Audience | Runs on | Delivered as |
|---|---|---|
| Candidates | Windows and macOS | Signed desktop application, updated from the admin console |
| Candidates | Modern browsers | Web client for sittings where full desktop lockdown is not required |
| Staff | Modern browsers | Admin console for policy, exams, review and reports |
There is no iOS or Android client. Candidates sit on a desktop or laptop computer.
Exam evidence is personal data with a long tail of obligations. fcProctor is built to be deployed where those obligations can be met.
Run it in your own cloud tenant or on our managed hosting, in a data region you nominate.
Authentication is delegated to Microsoft Entra ID for both the admin console and the exam client.
Every endpoint declares the permission it requires, and denies the request when the caller does not hold it.
Session media and events are kept for the period your academic integrity policy sets, then removed.
The candidate exam service and the staff admin service run separately, so neither exposes the other's surface.
Enrolment, media handling and notification work runs on a background queue, so peak sittings do not queue behind each other.
Send us one paper and the regulations that govern it. We will configure the policy to match and run the sitting with you.