The event types
Each event type records a specific, observable behavior during the attempt, and each is only recorded when the corresponding security setting is enabled for the delivery. None of them claims to know intent — they record what happened and when, timestamped signals whose frequency and spacing you read on the timeline. The reviewer decides what it means.
- Tab switch / window blur: the candidate left the exam tab or window; the timeline shows how often and how close together.
- Copy, cut, or paste attempts: the candidate tried them while copy/paste blocking was enabled; print attempts are logged the same way under print blocking.
- Second-screen connect: an extra display was connected mid-exam; it raises a banner for the candidate and logs an event. (An extra display detected before the start blocks the start, with a "check again" option.)
- Fullscreen exit and lockdown pause/resume: leaving fullscreen under lockdown is logged; returning to fullscreen after a pause is recorded as a neutral signal, as is the timer expiring.
- Violation limit exceeded: the attempt passed a configured limit — max violation count, max seconds per leave, or max total seconds away. What happens next depends on the delivery's lockdown policy.
How the timeline reads in evaluation
In evaluation, integrity events appear as a timeline you review alongside the responses, and the same timeline is included in the candidate evidence report. Each attempt also gets a proportionate derived status — clean, minor (a few signals), suspicious (many), or requires review (a lockdown limit was breached) — shown in review, the cohort integrity page, and exports. Neutral signals like heartbeats, timer expiry, and returning to fullscreen never count against a candidate. From the Decision Board, each candidate's Evidence link opens the underlying evidence, including the integrity timeline — risk flags there are context for human review, not conclusions.
Read the pattern, not a single entry. One brief window blur reads very differently from repeated long absences during a high-weight task. The timeline gives you timing and frequency so you can weigh events against what the candidate actually produced.
No auto-rejects: the human-review principle
Nothing in SkillCort auto-rejects a candidate. When lockdown is configured with violation limits, what happens at the limit is the delivery's policy choice: auto-submit closes the attempt with an audit event, while flag-for-review marks the attempt and lets the candidate continue; the warn-only and pause policies never enforce limits at all. Whatever the policy, that is the entire automatic consequence — a human still reviews the attempt and makes the call.
This is deliberate: integrity signals in SkillCort are proportional, disclosed at the consent gate, and human-reviewed. An event tells you that something happened during the attempt; only a reviewer, looking at the responses, the timeline, and the surrounding context, decides whether that event should affect the outcome at all.
Events that are not violations
Some legitimate candidate actions look like violations to naive monitoring, and SkillCort accounts for them. Using an item's own file picker has a grace period, so a candidate choosing a file for a file-upload task does not trigger a violation for leaving the window. If a timeline entry seems to coincide with a file-upload task, check the task before reading it as evasion.
At a glance
- Events include tab switch and window blur episodes, copy/paste and print attempts, second-screen connects, fullscreen exits, and lockdown-limit breaches.
- All monitoring is disclosed to the candidate at the consent gate before the attempt starts.
- Events appear as a reviewable timeline, and each attempt gets a proportionate integrity status: clean, minor, suspicious, or requires review.
- Nothing auto-rejects a candidate — what happens at a violation limit depends on the delivery's lockdown policy, and a human always reviews.
- Using an item's own file picker has a grace period, so choosing a file to upload does not count as a violation.