A test recorder, single sign-on & an audit trail for AI clients
Hawzu learned to record a test in Chrome and keep it as steps and scripts, to sign your team in through your own identity provider, and to show administrators every call a connected AI client made.
- Sign in through your company's identity provider — Okta, Microsoft Entra ID, Google Workspace or any OpenID Connect or SAML 2.0 provider — on every plan. Verify your email domain with one DNS record first, so your provider speaks only for addresses you own.
- Require single sign-on once you have tested it, and a password stops opening the workspace for everyone on your verified domains. People on other domains carry on as they are, and an owner with two-factor authentication keeps a way in if the identity provider is ever unavailable.
- Let a first sign-in bring somebody in, with a role you choose, instead of an invitation — or leave it off and keep inviting people yourself.
- On Enterprise, connect your directory over SCIM so Okta or Microsoft Entra ID adds, updates and removes people in Hawzu as your directory changes. Someone deactivated there loses their workspace access here, including project access, pending invitations and connected AI clients.
- Record a test once in Chrome with the Hawzu Recorder extension, in beta, and the test case keeps it as readable manual steps and two scripts, Playwright (TypeScript) and pytest + Selenium (Python), that your own CI runs, with each result mapping back to the test case by its code.
- The recorder's controls sit in Chrome's side panel, beside the page rather than on top of it, and fields it recognises as passwords, one-time codes or card numbers, or that you mark Secret, are saved only as an environment variable name.
- Write a recording into the test case as its manual steps, replacing or adding after what is there, open the Locators tab to see which locator each script uses and what else was tried, and when a page changes, fix the broken locator once in the project's Object Repository so every test case that uses it gets the new one.
- Workspace managers can review every call a connected AI client made — which tool, when, and whether it was refused — in Settings → MCP activity. The arguments a call sent are kept; what came back never is, so reviewing a connection does not mean storing a second copy of your data.