Overview
If you’ve already provisioned test accounts in your staging environment, you don’t need Perfai to create new ones. At the very first step of onboarding, the Vision Agent asks how you’d like accounts set up. Choose Manual, enter two sets of credentials, and the agent moves straight to login validation and app mapping. This is the fastest path to your first security scan when accounts already exist.Full walkthrough
1
Paste your app URL
Go to New App, paste your app’s URL into the input field, and hit the arrow button.
Three agents run in sequence: the Vision Agent maps your app, the Security Agent runs permission tests, and the Fix Agent generates verified fixes for every finding.

2
Review the task plan and click Continue
A New app setup modal appears listing the four automated tasks. Click Continue — nothing to configure here.

The Vision Agent launches immediately and starts Task #1: Create Test Accounts.
3
Select Manual when the agent asks how to set up accounts
The first thing the Vision Agent does is ask how you want test accounts handled. The cloud browser shows Vision agent on standby while it waits for your answer.

Click Manual — I’ll provide email/password.
4
Enter your two test account credentials
The credential form appears with two sections. Fill in both sets of credentials and click Save Credentials.

Account 2 is optional if you only have one tenant, but cross-tenant security tests (BOLA, privilege escalation) won’t run without it. You’ll still get full single-tenant coverage.
5
Credentials saved — agent confirms and proceeds
A green Credentials saved successfully confirmation appears along with a summary of what was provided.
The Vision Agent immediately uses the credentials to log in as each account and verify access in a live cloud browser session.
Once both logins are confirmed, App Mapping starts automatically. The agent navigates your entire app, recording every workflow, API endpoint, and data type it encounters.
The left panel logs every step:When mapping completes, the Security Agent begins running permission tests automatically. No trigger needed.



What happens from here
Once accounts are validated and the app is mapped, Perfai runs on its continuous schedule. You won’t be prompted for credentials again — they’re stored encrypted and reused on every subsequent scan.Frequently asked questions
Do both accounts have to be admins?
Do both accounts have to be admins?
They should have the broadest permissions available so the Vision Agent can map your full attack surface. Restricted roles cause the agent to miss endpoints and produce incomplete coverage.
What if I only have one tenant?
What if I only have one tenant?
You can run with a single account. Perfai will still map your app and run same-tenant permission tests. However, cross-tenant BOLA tests — the highest-severity vulnerability class — require two accounts from separate tenants.
My app uses OTP / magic links — can I still use Manual?
My app uses OTP / magic links — can I still use Manual?
Yes. Leave the password field blank and Perfai will handle OTP-based login automatically during the validation phase.
Can I update the credentials after saving?
Can I update the credentials after saving?
Yes. Go to your app dashboard → Tasks → Create Test Accounts to re-open the credential form and update either account at any time.

