Skip to main content

Overview

If you’ve already provisioned test accounts in your staging environment, you don’t need Perfai to create new ones. At the very first step of onboarding, the Vision Agent asks how you’d like accounts set up. Choose Manual, enter two sets of credentials, and the agent moves straight to login validation and app mapping. This is the fastest path to your first security scan when accounts already exist.

Full walkthrough

1

Paste your app URL

Go to New App, paste your app’s URL into the input field, and hit the arrow button.
Perfai — paste your app URL to start
Three agents run in sequence: the Vision Agent maps your app, the Security Agent runs permission tests, and the Fix Agent generates verified fixes for every finding.
2

Review the task plan and click Continue

A New app setup modal appears listing the four automated tasks. Click Continue — nothing to configure here.
New app setup — four-task confirmation modal
The Vision Agent launches immediately and starts Task #1: Create Test Accounts.
3

Select Manual when the agent asks how to set up accounts

The first thing the Vision Agent does is ask how you want test accounts handled. The cloud browser shows Vision agent on standby while it waits for your answer.
Vision Agent asking how to create test accounts — Yes, Manual, or Skip
Click Manual — I’ll provide email/password.
4

Enter your two test account credentials

The credential form appears with two sections. Fill in both sets of credentials and click Save Credentials.
Test account credentials form — Admin Tenant A and Admin Tenant B
Account 2 is optional if you only have one tenant, but cross-tenant security tests (BOLA, privilege escalation) won’t run without it. You’ll still get full single-tenant coverage.
OTP-based login? Leave the password field blank. Perfai handles OTP flows automatically during login validation.
5

Credentials saved — agent confirms and proceeds

A green Credentials saved successfully confirmation appears along with a summary of what was provided.
Credentials saved successfully — summary of accounts provided
The Vision Agent immediately uses the credentials to log in as each account and verify access in a live cloud browser session.
Vision Agent logging in with provided credentials to validate access
Once both logins are confirmed, App Mapping starts automatically. The agent navigates your entire app, recording every workflow, API endpoint, and data type it encounters.
App mapping in progress — Vision Agent navigating the application
The left panel logs every step:
When mapping completes, the Security Agent begins running permission tests automatically. No trigger needed.

What happens from here

Once accounts are validated and the app is mapped, Perfai runs on its continuous schedule. You won’t be prompted for credentials again — they’re stored encrypted and reused on every subsequent scan.

Frequently asked questions

They should have the broadest permissions available so the Vision Agent can map your full attack surface. Restricted roles cause the agent to miss endpoints and produce incomplete coverage.
You can run with a single account. Perfai will still map your app and run same-tenant permission tests. However, cross-tenant BOLA tests — the highest-severity vulnerability class — require two accounts from separate tenants.
Yes. Go to your app dashboard → TasksCreate Test Accounts to re-open the credential form and update either account at any time.