Docs
Safety
Simulating a real user means the agent really clicks, submits and pays. Safety is built in from the first step, so a run never charges a real card, deletes real data or emails your customers.
The short version
- Staging first. Each environment is labelled staging or production. Staging is recommended.
- Production safe mode. On production, delete, pay, invite and send are blocked by default.
- Live payment guard. The agent checks for live payment keys before it types a card, and stops if it finds one.
- Official test cards only. See Test cards.
- Verified ownership. Nobody can run the agent on a site they do not own. See Verify ownership.
- Tagged traffic. Agent visits can be excluded from your analytics.
- No code access. WitnessQA reads issues and uses your app. It never reads your repository.
Staging first
Label every environment when you add it. The label decides what the agent is allowed to do. Staging should use your payment provider's test mode and a copy of data you do not mind changing.
-
Label the environment
When you add an environment, pick Staging or Production. You can change it later in the environment settings.
Each environment shows its label. Production is marked in red.
Production safe mode
On production, the agent can browse, search, fill forms and check pages, but it does not finish actions that change real data or reach real people. Before each click, it checks the button and the request it is about to send. A blocked step is shown as skipped for safety, never as a pass or a fail.
| Blocked on production | Examples |
|---|---|
| Delete | Delete, remove, cancel subscription, close account |
| Pay | Submit a payment form or confirm a purchase |
| Invite | Invite a teammate or share access by email |
| Send | Send a message, email, SMS or notification to someone else |
-
Review what is allowed
Open the production environment and go to Safe mode. Everything is blocked by default. Allow an action only if the run cannot cause harm, for example sending messages to an internal test inbox.
Safe mode on production. Each action is blocked until you allow it. -
See skipped steps in the report
The run continues after a skipped step when it can, so the rest of the flow is still checked.
A delete step skipped for safety on production.
Live payment guard
Before the agent types a card, on any environment, it inspects the page for signals that the payment form is live. If it finds one, or cannot tell, it stops and marks the step skipped for safety. Examples of what it checks:
| Provider | Test | Live |
|---|---|---|
| Stripe | pk_test_ key | pk_live_ key |
| Paddle | Paddle.Environment.set('sandbox'), test_ token | live_ token |
| PayPal | SDK from sandbox.paypal.com or client-id=sb | Anything else, unless you mark the client ID as sandbox |
| Braintree | sandbox_ key | production_ key |
| Adyen | test_ client key | live_ client key |
| Checkout.com | pk_sbox_ key | Any other pk_ key |
-
The guard stops on a live key
Nothing is typed into the card field. The rest of the run goes on, and the report says exactly why the payment was skipped.
A live Stripe key was found, so the payment step was skipped.
Exclude agent traffic from analytics
Every request from the agent has WitnessQA in its user agent and an X-WitnessQA-Run header with
the run ID. Sign-ups from the agent inbox use @inbox.witnessqa.com addresses.
-
Filter it out
Add a filter for the
WitnessQAuser agent in your analytics tool, or drop the event at your server or CDN when theX-WitnessQA-Runheader is present. Exclude@inbox.witnessqa.comusers from your sign-up metrics.Settings show the exact user agent and header the agent sends.
Your data
- Credentials, TOTP secrets and bypass tokens are stored encrypted and never appear in screenshots, videos or logs.
- Evidence is kept for 7, 30 or 90 days depending on your plan, then deleted.
- During early access, a person reviews every report before it is published.