Skip to main content
Browser Automations let Comp AI sign in to a vendor’s web app the way a person would — in a real browser — and capture the exact page you need as audit evidence, on a schedule. It reaches logins that API integrations can’t, including ones protected by two-factor authentication (2FA), and keeps evidence fresh without anyone redoing it each cycle.
Automated browser evidence — a captured page with a Comp AI audit banner

Every run produces an audit-ready screenshot, stamped with the requirement, source, and timestamp.

Why it’s powerful

  • It reaches evidence nothing else can. Plenty of tools have no API or integration — Browser Automations sign in and screenshot the page directly, so you can prove a control that would otherwise be a manual screenshot.
  • It handles 2FA on its own. Give it the authenticator setup key once and it generates the codes itself, so scheduled runs never wait on your phone.
  • It stays fresh without you. When a session expires, it re-signs in on its own — evidence keeps updating on schedule instead of going stale between audits.
  • It’s auditor-ready by default. Every capture is stamped with the requirement, source, and timestamp, and can carry a pass/fail verdict.
This is most useful for recurring evidence from admin consoles and security-settings pages that have no export or API — for example, showing that two-factor authentication is enforced, that users have MFA enabled, or that a specific setting is turned on — across as many vendors as you need.

What you can do

  • Collect evidence from web apps that have no API or integration.
  • Sign in on a schedule, including 2FA — Comp AI generates the one-time code for you.
  • Watch a run live and take over in the browser if a step needs a human.
  • Get an audit-ready screenshot stamped with the source and timestamp, plus an optional pass/fail check.
  • Manage every vendor login in one place under Settings → Browser connections.

How it works

There are three parts:
  1. Connections — the vendor logins Comp AI signs in with (Settings → Browser connections).
  2. Browser evidence — the automations that use those logins, created inside an evidence task.
  3. Schedule — Comp AI signs in, captures the page, and re-signs in on its own when a session expires.
You set up an automation inside a task, but the logins it uses are shared across your organization — connect a vendor once and any task can use it.

Prerequisites

Before you start, make sure:
  1. Your organization has the feature enabled.
  2. You have access to Settings and to the evidence task.
  3. You have the vendor login you want Comp AI to use — ideally a dedicated service account rather than a personal one.

Connect a vendor

You can connect from a task’s Browser evidence section, or from Settings → Browser connections → Connect a vendor.
  1. Enter the vendor’s sign-in URL.
  2. Comp AI reads the sign-in page and shows the exact fields it asks for — it detects whether the login uses an email, a username, or extra fields like a workspace.
  3. Choose how Comp AI signs in: with a stored login, or via single sign-on (SSO), where you finish at your identity provider.
  4. Enter the login. Comp AI signs in for you in a live browser. If a step needs you — a 2FA prompt, an email code — you can take over in the same browser and hand it back.
Credentials are stored encrypted in a secure vault. Comp AI keeps only a reference to them — never the raw password in plain text.

Unattended 2FA

This is what makes scheduled runs truly hands-off. If your login uses an authenticator app, give Comp AI the setup key once, and it generates the rotating 6-digit codes itself — so scheduled runs never wait on your phone.
Entering the authenticator setup key, with per-vendor guidance

The setup-key field, with per-vendor steps — 'How do I find this key?' — generated from the vendor's current help docs.

  • Enter the setup key, not the code. The setup key is the long, one-time key shown when you add an authenticator app (the “can’t scan? enter this code” option) — not the rotating 6-digit code your app displays.
  • Not sure where to find it? Select “How do I find this key?” next to the field. Comp AI shows the steps for your specific vendor, checked against its current help docs.
  • You can also turn this on later — open the connection under Settings → Browser connections and add the authenticator key without re-entering your password.
Use a dedicated authenticator (MFA) device for the automation — many vendors let you add more than one. It’s revocable on its own and never touches your personal authenticator.
Comp AI never stores the rotating 6-digit code — only the setup key, encrypted — and generates a fresh code at run time.

Create a browser evidence automation

Inside an evidence task, open the Browser evidence section:
  1. Describe what to capture in plain English — for example, “Open the organization’s security settings and show that two-factor authentication is required for all members.”
  2. (Optional) Add a pass/fail check — for example, “Two-factor authentication is required for everyone.” Without one, the run captures a screenshot only.
  3. Test it. Watch the automation run live, then review the screenshot and result before you commit.
  4. Save. It now runs automatically on the task’s schedule — Daily, Weekly, Monthly, Quarterly, or Yearly, your choice — and keeps the evidence current. You can also run it on demand any time.
Live test run — the AI controlling a browser to capture evidence

Testing an instruction — watch the AI drive a real browser live, then review the screenshot and verdict before saving.

One task can hold several automations — even across different vendors — each producing its own screenshot and verdict.

Schedule and manual runs

Once saved, an automation runs automatically on a schedule — you don’t have to trigger it. You choose how often: set the cadence to Daily, Weekly, Monthly, Quarterly, or Yearly from the schedule control in the Browser evidence header. One cadence applies to all the browser evidence on that task, so a task’s proof refreshes together. You can change it any time. Need proof right now? Run any automation on demand — its screenshot and verdict appear in the row as soon as it finishes, without waiting for the next scheduled run. On each run — scheduled or manual:
  • Comp AI signs in, navigates to the page you described, and captures a screenshot stamped with the requirement, source URL, and capture time. If you added a check, it records a pass or fail with a short reason.
  • If the saved session has expired, Comp AI re-signs in on its own — using the stored login and a freshly generated 2FA code. You don’t have to do anything.
  • If it hits something only a person can clear — a captcha, a “verify it’s you” prompt, or an SSO/passkey step — the run pauses and the connection is flagged Needs reconnect, with a one-click Reconnect.

Manage your connections

The Browser connections settings page

Every vendor login in one place — with health status, search, and per-connection actions.

Under Settings → Browser connections you can:
  • See every connection with its status: Active, Needs reconnect, or Blocked.
  • Search and page through them when you have many.
  • Reconnect, rename, or change the login.
  • Turn Automatic 2FA on or off, or replace the authenticator key.
  • Remove a connection you no longer need.

Best practices

  1. Use a dedicated service account and a dedicated MFA device for each automation.
  2. Point each automation at the specific page or setting so the screenshot shows just that, not a long list.
  3. Prefer a direct sign-in or settings URL — runs are faster and steadier when they start close to the target.
  4. Keep automations meaningful: pair each with a pass/fail check where the requirement is clear.

Troubleshooting

Click Reconnect, sign in again, and enter the 2FA code once in the live browser. To avoid this every time a session expires, add the authenticator setup key so Comp AI can re-sign in on its own.
For well-known vendors, Comp AI shows steps checked against their current help docs. For others it shows the universal steps — the exact menu names may differ, so double-check in your account’s security settings as you go.
Some challenges (captcha, device approval, passkeys) can only be completed by a human. Open the connection and Reconnect in a live browser to clear it, then future runs continue normally.
Your organization may not have the feature enabled, or your user may not have access to Settings. Check with an admin.

Support

If you need help with Browser Automations:
  1. Contact support at support@trycomp.ai
  2. Join our Discord community