From violation to evidence in StudyDrome

The record an appeal panel can read

StudyDrome Exam Manager turns exam events into an appeal-ready record. The browser reports events. The server decides. Every attempt is classified into one of eight finish categories, with a violation timeline, the sessions behind it, and a per-attempt PDF you can put in front of a panel.

How does StudyDrome decide when to finish an attempt?

  1. 1
    The candidate's browser reports an event. It posts to the server the moment it happens.
  2. 2
    The server validates the request first. It confirms the tenant, the attempt, that the attempt belongs to this candidate, and that the session is still active.
  3. 3
    It then reads the integrity settings that were snapshotted into the published exam, so the rules cannot shift mid-sitting.
  4. 4
    It increments the attempt's violation counter and writes the violation row. The row links to the session, and the session carries the IP address, user agent and device fingerprint.
  5. 5
    It evaluates the thresholds you set. Passing the warning point stamps the row as a warning, and the candidate is told.
  6. 6
    Passing the finish point overrides that stamp with the more severe one, and the attempt is submitted for the candidate.
  7. 7
    Submission runs as a background task, so a grading pass never holds up the response the candidate is waiting on.

What does the exam conduct report record?

What the report holds

What that row carries

Finish classification

The category the attempt landed in, with its display label

Violation timeline

Each violation in order, with its timestamp and the question in view

Sessions

Each session with its IP address, user agent and device fingerprint, and how it ended

Timing

When the attempt was submitted, and the time spent on it

Violation count

The server's own count for the attempt

Gap to previous finish

Seconds since the previous attempt on the same published test finished

Four violation types are detected live in the browser: window leave, fullscreen exit, copy attempt and paste attempt. Each one posts to the server as it happens. The timeline replays them in order.

The paper itself is frozen at publish, so the report and the exam a candidate sat stay in step. See how publishing works and what a written exam delivers.

How are finish reasons classified?

Every attempt carries raw finish fields: a flag, a numeric reason and a lifecycle status. The report collapses them into one of eight categories.

Category

What it means

In progress

The attempt has not finished.

Finished by student

The candidate submitted the attempt.

Time expired

The clock ran out, or the maximum duration was reached.

Test window expired

The availability window closed on the attempt.

Terminated for violations

The attempt was submitted after your violation limit was passed.

Finished by administrator

Staff ended the attempt.

Abandoned / session timeout

The attempt was left, or its session timed out.

Unknown

The attempt auto-submitted with no recorded reason. It is surfaced for investigation.

Those are the labels you read on screen. One mapper produces both the display label and the filter, and the two are kept in lockstep. So what you filter by is exactly what you read.

The report also counts each category. The applied-filter description names the label you chose, which means an exported view states its own scope.

How does the report help spot collusion?

One column does the work. Attempts on a published test are ordered by submission time, and each row is stamped with the gap that preceded it.

  • The interval: each row carries the number of seconds since the previous attempt on that published test finished.
  • The first row: each published test starts with a row that has no gap to report, because nothing finished before it.
  • The grouping: gaps are computed per published test. Two publications of the same exam never contaminate each other.
  • The pattern: a run of near-zero gaps is what synchronised submission looks like in the data, and it is what investigators sort for.
  • The judgement: the interval is a report field. The number is displayed, and the reading of it stays with you.

What can you show an appeal panel?

Surface

What it produces

Attempt drill-down

The finish classification, the full violation timeline and the session list, for one attempt

Attempt PDF

The same content as a document, sized for an appeal bundle

Report in Excel

A Summary sheet and an Attempts sheet

Report in PDF

The whole filtered report as one document

The evidence is event data. Violations carry a timestamp and the question in view. Sessions carry an IP address, a user agent and a device fingerprint, plus the reason each session ended. The finish classification sits on top of both.

That is the bundle an exam office hands to a panel, and the record an IT reviewer asks to see before sign-off.

Where does the report stop and your judgement begin?

  • The report classifies how attempts ended. Adjudication is human.
  • The counter, the thresholds and the finish decision all live on the server. The browser reports events; the server decides what they mean.
  • The thresholds are yours. You set the warning point and the finish point on each exam.
  • A candidate is warned first, and the attempt finishes only once the limit you set is passed.
  • The finish clustering is temporal. It reports the interval between submissions and raises no automatic flag.
  • Every line in the bundle is a recorded event with a time on it. That is what survives a challenge a year later.
  • Where the mapper cannot place an attempt, it says Unknown rather than guessing, and surfaces the row for a human to read.

Who uses the exam conduct report?

The report is quiet until someone challenges a result. Then it is the whole file.

  • Exam offices closing a sitting, who need to state how every attempt ended before results go out.
  • Appeals panels, who need the timeline and the sessions rather than a summary verdict.
  • Assessment leads reviewing a cohort, who want the finish counts per category in one view.
  • Invigilation teams, who follow up the attempts that ended early and record what they found.
  • IT and information-governance reviewers, who want the evidence trail described plainly before sign-off.

Frequently asked questions

Who decides whether a candidate cheated?

You do. The exam conduct report classifies how attempts ended, and adjudication is human. It gives a panel recorded facts: the finish category, each violation with its timestamp and the question in view, and the sessions behind the attempt. It applies no verdict and raises no automatic flag. The decision belongs to the people who own the assessment.

What is in the per-attempt PDF?

The per-attempt PDF carries the finish classification, the full violation timeline and the session list for one attempt. Each violation shows its timestamp and the question in view. Each session shows its IP address, user agent and device fingerprint, plus how it ended. It is the drill-down you see on screen, rendered as a document you can attach to an appeal bundle.

Which violations does the browser report during an exam?

Four violation types are detected live in the browser: window leave, fullscreen exit, copy attempt and paste attempt. Each one posts to the server as it happens, with a timestamp and the question in view. The server counts every violation on the attempt, and that count drives your warning and finish thresholds. The report replays them in order.

How do the finish categories help an exam office close a sitting?

The report collapses raw finish fields into eight named categories and counts each one. An exam office can see how many attempts a candidate finished, how many ran out of time, how many the availability window closed, and how many staff ended. Anything the mapper cannot place lands in Unknown, which is surfaced for investigation rather than hidden.

Can we filter the report by how attempts finished?

Yes. Finish reason is a filter, and the applied-filter description names the label you chose. One mapper produces both the filter and the display label, and the two are kept in lockstep. So what you filter by is exactly what you read. The summary counts move with the filter, so a filtered view still totals correctly.

What does the seconds-since-previous-finish column tell us?

Attempts on a published test are ordered by submission time. Each row carries the number of seconds since the previous attempt finished. The first row in each published test has no gap to report. A run of near-zero gaps is the pattern investigators sort for. The number is displayed, and the reading of it stays with you.

Book a pilot

Bring one sitting. We will run it, then open the exam conduct report and export a per-attempt PDF in front of you.