How it works

Click the app. FirmBrowser does the rest.

Identity proves who you are. FirmBrowser governs what happens next — from the moment the managed browser launches to the audit record left behind.

  1. Step 01

    User launches FirmBrowser

    The managed browser environment starts under enterprise policy.

  2. Step 02

    User and device context verified

    Identity, role, device posture and access period are checked before anything opens.

  3. Step 03

    Recipe Book made available securely

    The user's authorised applications and policies are released to the session under policy.

  4. Step 04

    User clicks the application

    One click. No usernames, no passwords, no MFA fumbling.

  5. Step 05

    Correct authentication method chosen

    SSO hand-off to an approved identity provider, or execution of the authorised login recipe.

  6. Step 06

    Application opens

    The user lands inside the app in a controlled browser context.

  7. Step 07

    App Transformation keeps applying

    Element, URL and Table Rules — plus workflow restrictions and data-movement policy — stay in force after login.

  8. Step 08

    Security and audit events recorded

    Access, blocked actions and policy events become defensible evidence.

  9. FirmBrowser does not stop working when the login page disappears. Authentication is an event — FirmBrowser governs the session.
Universal Push MFA

Where MFA is enabled, the login pauses for approval

When a user launches a protected App Recipe, FirmBrowser can pause the automated login and send a push notification to the user's enrolled iPhone or Android device. One tap to approve and FirmBrowser completes the login — even for applications that have no native MFA capability.

01

Download the FirmBrowser App

Install the native FirmBrowser app on an iPhone or Android device and securely enrol the device with the user's FirmBrowser account.

iOSAndroidSecure enrolment
02

Launch a FirmBrowser App Recipe

The user launches any protected App Recipe from FirmBrowser on their computer. Where MFA is enabled for that Recipe, FirmBrowser pauses the login workflow and requests approval.

Recipe-level policyLogin paused
03

Approve on your phone

A standard push notification arrives in the FirmBrowser mobile app. Tap Approve — FirmBrowser continues the automated login. Simple, familiar and consistent.

One tapAutomated login continues
Authentication paths

One experience, two authentication models

FirmBrowser hands off to your identity provider where the application supports it, and executes an authorised App Recipe where it does not.

One click for the user

The user clicks the app. FirmBrowser determines the correct authentication method and takes care of the rest.

Path A

Native SSO

Where an application supports your organisation's preferred identity provider, FirmBrowser launches the application and lets authentication be handled by that approved platform — Entra ID, Okta, Google Identity or another approved SAML/OIDC provider.

  • Identity stays with your identity platform
  • FirmBrowser continues browser and session controls
  • Post-login policy still applies
Path B

Recipe-driven access

Where an application does not use your preferred SSO mechanism, FirmBrowser can use a secure App Recipe to perform the authorised login workflow on the user's behalf.

  • The user never knows or types the password
  • Nothing to copy, save, share or remember
  • Same controls apply after login

Different authentication technologies underneath. One controlled experience for the user.

Post-login control · App Transformation

Security does not stop when the login page disappears

The same cloud application, presented as the role is permitted to use it.

app.cloudsuite.com — standard access
  • Dashboard
  • Reports
  • Settings
  • Users
  • Admin
  • Export
  • Download
  • Delete
  • Change Password
  • Billing

Every user sees every function the application ships with.

FirmBrowser policy
  • Element Rules
  • URL Rules
  • Role Policy
app.cloudsuite.com — through FirmBrowser
  • Dashboard
  • Reports
  • Approved Workflow
  • Element Rule — Settings, Admin, Users removed
  • URL Rule — password-reset route redirected
  • Export — blocked
  • Password Reset — restricted

Same cloud application. Different permitted experience.

For CIOs, CTOs and security teams

One control plane for browser-based applications

Manage users, devices, identity providers, applications, Recipe Books, rules, credential policy, audit and compliance evidence from a single place.

FirmBrowser Admin Control Centre
Users
Groups
Roles
Devices
Identity Providers
Applications
Recipe Books
Recipes
App Transformation
URL Rules
Element Rules
Table Rules
Credential Lockdown
Mail Security
Audit
Sessions
Risk
Compliance
Administrators manage access outcomes — not passwords.
Step six · Continuous verification

Sentinel AI keeps checking that the whole flow still works

Once a Recipe is live, FirmBrowser Sentinel AI executes it on a schedule in a controlled test environment — confirming the login completes, Push MFA is still enforced, App Transformations are still applied and security policy still holds. Administrators are alerted with an explanation of what changed, before users hit the problem.

  1. Step 01
    Scheduled AI run

    The Recipe's monitoring schedule triggers an agent run.

  2. Step 02
    Launch App Recipe

    The agent executes the Recipe in a controlled test environment, exactly as a user would.

  3. Step 03
    Observe every step

    Each stage of the login, transformation and policy sequence is watched and recorded.

  4. Step 04
    Validate expected behaviour

    Every expected outcome is compared against the Recipe's established baseline.

  5. Step 05
    Analyse changes & security signals

    Differences are interpreted — what changed, and whether it actually matters.

  6. Step 06
    Pass, warning or failure

    The run resolves to a Recipe Health status the administrator can act on.

  7. Step 07
    Administrator alert + AI analysis

    A written explanation of what happened, not a raw stack of logs.

Authentication is an event. FirmBrowser governs the session.

See the full access flow applied to your firm's own cloud application stack.