Academic integrity guide

    How to Prevent Cheating on Online Exams

    Preventing cheating on online exams takes three layers working together: assessment design that resists outsourced answers, a published policy students read before they start, and proctoring that watches the device rather than only the browser tab. Browser-only tools cannot see desktop AI assistants, overlays, or remote control, so they miss the most common forms of assistance. ScreenComply adds operating-system-level detection and an optional Prevent mode that blocks restricted applications from launching during the exam window.

    Layer one: design the assessment to resist assistance

    Questions that require reasoning about course-specific material, in-class artifacts, or a student's own prior work are substantially harder to outsource than recall questions. Randomized item banks and tighter windows reduce answer sharing, and short oral follow-ups on high-stakes items raise the cost of assistance considerably.

    Design alone will not carry a high-stakes assessment once a hidden assistant can run on the same machine, but it removes the easiest opportunities and narrows what enforcement has to cover.

    • Prefer applied reasoning over recall on high-weight items.
    • Use randomized item banks and per-student ordering.
    • Keep high-stakes weight on proctored or verified components.
    • Add brief oral or follow-up verification where the stakes justify it.

    Layer two: state the rules before the session

    Ambiguity is what makes academic-integrity cases painful to resolve. Publish, per assessment, which tools are permitted, what is monitored, how long session data is retained, and what happens when a session is flagged. Students who know what is observed behave differently, and institutions that disclose clearly are in a far stronger position at appeal.

    Why browser-based tools cannot see the assistance

    Browser extensions and lockdown browsers observe the page, the tab, and often the webcam. Their visibility ends where the browser process ends, and that is precisely where modern AI assistance lives.

    Desktop assistants and answer overlays render above every other window, are frequently excluded from screen capture and screen sharing, and never interact with the assessment tab. Remote-control tools, virtual machines, injected keyboard input, and a second device off camera are equally invisible from inside the browser.

    • Native overlay applications draw over the assessment and are often excluded from screen share.
    • Remote-access tools allow another person to drive the machine with no browser-visible trace.
    • Virtual machines let the assessment run inside a controlled environment with helpers outside it.
    • Injected or synthesized keyboard input can enter answers that were never physically typed.
    • A second phone, tablet, or monitor off camera leaves nothing at all in the browser.

    Layer three: prevention at the device, not only detection

    Detect mode observes the session quietly and flags anomalies for human review. Prevent mode goes further and blocks restricted applications from launching while the assessment is open, so the assistance never starts in the first place.

    Inside Canvas this becomes a workflow rather than a second platform. The assignment or quiz stays sealed until the student is genuinely being proctored, then unlocks for that student the moment the session goes live. Faculty configure it once; students launch from a single link in the course they already use.

    What device-level detection observes

    Reliable detection has to happen at the layer where assistance runs: the operating system. ScreenComply pairs a browser-based API with an optional desktop agent that inspects the environment around the assessment rather than only the page inside it.

    The agent enumerates running processes and browser extensions against a maintained list of AI assistants and answer overlays, looks for always-on-top or transparent windows, detects remote access and virtualization, enumerates connected displays from the operating system, verifies that keyboard input originates from local physical hardware, and records focus changes, clipboard events, and typing-cadence patterns.

    No detection system catches everything, and ScreenComply does not claim otherwise. The objective is corroborating, timestamped evidence that lets a human reviewer make an informed and defensible decision.

    • Process and extension enumeration against a maintained AI-assistant list.
    • Overlay, transparency, and always-on-top window detection.
    • Remote access, virtual machine, and screen-capture driver detection.
    • Display enumeration reported by the operating system, not inferred from gaze alone.
    • Input-source integrity, clipboard events, and typing-cadence analysis.

    Turning signals into a report someone can defend

    A detection is only useful if it can be explained to a person who was not in the room. Every session produces a structured integrity report: an executive verdict with a graded risk level, a chronological evidence timeline, and the underlying signal detail behind each entry.

    Language is deliberately factual rather than accusatory, because the institution or employer makes the decision, not the software. Reports export to PDF and can be shared through a secure link for academic-integrity hearings, HR reviews, and compliance audits, with configurable retention including zero-retention operating modes.

    Frequently asked questions

    What is the most effective way to prevent online exam cheating?

    Combining assessment design that resists outsourcing with device-level proctoring. Either one alone leaves a gap: design does not stop a hidden assistant, and monitoring does not fix an exam that can be answered from a generic model.

    Does blocking applications work better than flagging them?

    For high-stakes assessments, many institutions prefer blocking so assistance never starts. Prevent mode blocks restricted applications during the exam window; Detect mode observes and flags for review.

    Do students need to install anything?

    The browser-based API requires no installation. Prevent mode and the deepest device-level signals require the desktop agent, launched for the assessment window and closed afterwards.

    How is student privacy handled?

    Retention is configurable by the institution, including tiers that minimize or eliminate stored artifacts. Report access is role-scoped and the institution controls how long session data lives.

    Is this accessible for students using assistive technology?

    Major screen readers and magnifiers are whitelisted by default and are never treated as restricted tools. Accommodations such as extended time, breaks, dictation, and alternative input devices are configured per session by the institution.

    ScreenComply is under contract with the State of Montana. SOC 2 Type 2 examination in progress.

    See a session, a detection, and a report

    A short walkthrough of live detection, Detect versus Prevent mode, and the integrity report your reviewers would actually receive.