Click the app. FirmBrowser does the rest.
Identity proves who you are. FirmBrowser governs what happens next — from the moment the managed browser launches to the audit record left behind.
- Step 01
User launches FirmBrowser
The managed browser environment starts under enterprise policy.
- Step 02
User and device context verified
Identity, role, device posture and access period are checked before anything opens.
- Step 03
Recipe Book made available securely
The user's authorised applications and policies are released to the session under policy.
- Step 04
User clicks the application
One click. No usernames, no passwords, no MFA fumbling.
- Step 05
Correct authentication method chosen
SSO hand-off to an approved identity provider, or execution of the authorised login recipe.
- Step 06
Application opens
The user lands inside the app in a controlled browser context.
- Step 07
App Transformation keeps applying
Element, URL and Table Rules — plus workflow restrictions and data-movement policy — stay in force after login.
- Step 08
Security and audit events recorded
Access, blocked actions and policy events become defensible evidence.
- FirmBrowser does not stop working when the login page disappears. Authentication is an event — FirmBrowser governs the session.
Where MFA is enabled, the login pauses for approval
When a user launches a protected App Recipe, FirmBrowser can pause the automated login and send a push notification to the user's enrolled iPhone or Android device. One tap to approve and FirmBrowser completes the login — even for applications that have no native MFA capability.
Download the FirmBrowser App
Install the native FirmBrowser app on an iPhone or Android device and securely enrol the device with the user's FirmBrowser account.
Launch a FirmBrowser App Recipe
The user launches any protected App Recipe from FirmBrowser on their computer. Where MFA is enabled for that Recipe, FirmBrowser pauses the login workflow and requests approval.
Approve on your phone
A standard push notification arrives in the FirmBrowser mobile app. Tap Approve — FirmBrowser continues the automated login. Simple, familiar and consistent.
One experience, two authentication models
FirmBrowser hands off to your identity provider where the application supports it, and executes an authorised App Recipe where it does not.
One click for the user
The user clicks the app. FirmBrowser determines the correct authentication method and takes care of the rest.
Native SSO
Where an application supports your organisation's preferred identity provider, FirmBrowser launches the application and lets authentication be handled by that approved platform — Entra ID, Okta, Google Identity or another approved SAML/OIDC provider.
- Identity stays with your identity platform
- FirmBrowser continues browser and session controls
- Post-login policy still applies
Recipe-driven access
Where an application does not use your preferred SSO mechanism, FirmBrowser can use a secure App Recipe to perform the authorised login workflow on the user's behalf.
- The user never knows or types the password
- Nothing to copy, save, share or remember
- Same controls apply after login
Different authentication technologies underneath. One controlled experience for the user.
Security does not stop when the login page disappears
The same cloud application, presented as the role is permitted to use it.
- Dashboard
- Reports
- Settings
- Users
- Admin
- Export
- Download
- Delete
- Change Password
- Billing
Every user sees every function the application ships with.
- Element Rules
- URL Rules
- Role Policy
- Dashboard
- Reports
- Approved Workflow
- Element Rule — Settings, Admin, Users removed
- URL Rule — password-reset route redirected
- Export — blocked
- Password Reset — restricted
Same cloud application. Different permitted experience.
One control plane for browser-based applications
Manage users, devices, identity providers, applications, Recipe Books, rules, credential policy, audit and compliance evidence from a single place.
Sentinel AI keeps checking that the whole flow still works
Once a Recipe is live, FirmBrowser Sentinel AI executes it on a schedule in a controlled test environment — confirming the login completes, Push MFA is still enforced, App Transformations are still applied and security policy still holds. Administrators are alerted with an explanation of what changed, before users hit the problem.
- Step 01Scheduled AI run
The Recipe's monitoring schedule triggers an agent run.
- Step 02Launch App Recipe
The agent executes the Recipe in a controlled test environment, exactly as a user would.
- Step 03Observe every step
Each stage of the login, transformation and policy sequence is watched and recorded.
- Step 04Validate expected behaviour
Every expected outcome is compared against the Recipe's established baseline.
- Step 05Analyse changes & security signals
Differences are interpreted — what changed, and whether it actually matters.
- Step 06Pass, warning or failure
The run resolves to a Recipe Health status the administrator can act on.
- Step 07Administrator alert + AI analysis
A written explanation of what happened, not a raw stack of logs.
Authentication is an event. FirmBrowser governs the session.
See the full access flow applied to your firm's own cloud application stack.
