"Can Canvas tell if I switch tabs?" is one of the most searched questions about online quizzes, and most of the answers online are either scare stories or wishful thinking. Here's the factual version: what a Canvas quiz log records, what it doesn't, how instructors actually use it, and why the data is far less conclusive than the internet suggests.

What a quiz log is

Every Canvas quiz attempt generates a log — a timestamped record of what happened during the attempt. For Classic Quizzes, an instructor reaches it through Moderate This Quiz and then a per-student log view. New Quizzes keeps a comparable activity log in its own interface.

The log is not a report anyone receives automatically. It's a diagnostic page an instructor has to deliberately open, one student at a time. That distinction matters, and we'll come back to it.

What the log records

A typical Classic Quizzes log reads roughly like this:

00:00 Session started
00:14 Answered question 1
00:41 Answered question 2
01:03 Stopped viewing the Canvas quiz-taking page
01:22 Resumed viewing the Canvas quiz-taking page
01:35 Answered question 3
02:07 Answered question 2 (changed answer)

Broken down, the log captures four kinds of event:

  • Session start and end — when the attempt was opened and submitted.
  • Answer events — which question was answered, and when. Changed answers appear as separate entries, so the log shows revision history within the attempt.
  • Page focus events — entries indicating the quiz page stopped or resumed being viewed.
  • Timing — the gap between every event, which is really the log's core content.

What the log does not record

This is where most of the fear online is misplaced. A Canvas quiz log is generated by a web page running in your browser, and a web page is heavily restricted in what it can observe. The log cannot see:

  • Your other tabs. Canvas has no visibility into what other pages are open, what's on them, or what you searched.
  • Your browsing history. Nothing outside the quiz page is accessible to it.
  • Other applications. Whether you opened a PDF, a messaging app, or a calculator is invisible to Canvas.
  • Your screen. A quiz page cannot capture or view your display.
  • Your keystrokes outside the quiz. It sees answers you enter into its own fields, nothing more.
  • Other devices. A phone next to your laptop is entirely outside its awareness.

The distinction is between focus and content. The page can tell that it is no longer the thing in front of you. It cannot tell what replaced it. "Stopped viewing the Canvas quiz-taking page" is the full extent of what was observed — the log entry is the whole story, not a summary of a longer one.

This is worth internalizing, because it's the difference between a system that watches you and a system that notices it isn't being watched. Canvas is the second one. Dedicated remote proctoring software — Respondus, Proctorio, and similar — is a different category entirely, with camera and screen access you explicitly grant on install. If your course requires proctoring software, you'll know, because you had to install it.

Why focus events are weak evidence

Here's the part that rarely makes it into the scare stories: a "stopped viewing" event has a long list of innocent causes.

  • A system or app notification taking focus for a moment.
  • Clicking anywhere outside the browser window — including on a second monitor.
  • A password manager, screen reader, or accessibility tool activating.
  • The browser opening a print dialog, a download prompt, or a permission request.
  • On laptops, closing the lid or the machine sleeping.
  • Switching to a calculator or reference the instructor explicitly allowed.
  • On some setups, simply scrolling with a trackpad gesture that shifts window focus.

Because the causes are so varied, a focus event on its own establishes almost nothing. An attempt with fifteen focus events across ninety minutes on a laptop with notifications enabled looks exactly like an attempt where someone checked their phone constantly — and exactly like one where neither happened.

Institutions generally recognize this. Academic integrity policies typically require substantive evidence, and a log showing focus changes is rarely sufficient on its own. Where logs do get used, it's normally as supporting context for a case that started somewhere else, not as the trigger.

The realistic summary: Canvas records that the quiz page lost focus and when. It does not record why, what you did instead, or whether you did anything at all. That's a meaningful difference, and it's why quiz logs are treated as weak signals rather than proof.

How often do instructors actually look?

Almost never, in the ordinary case. Opening a quiz log is a manual, per-student action, and a professor with 200 students is not clicking through 200 logs after every quiz. In practice, logs get opened for three reasons:

1. A technical dispute

By far the most common reason. A student says the quiz submitted early, or froze, or lost their answers. The log is how the instructor checks the timeline and, frequently, confirms the student's account. This is the log working for students, and it's the use case Instructure clearly designed it for.

2. A grade far out of line with everything else

If someone who has been getting 60s suddenly returns a perfect score in four minutes on a forty-question exam, that stands out on its own — the log is opened afterwards to add detail. Note the ordering: the score prompted the check, not the log.

3. An existing investigation

If an integrity case is already open for some other reason, the log becomes one of the documents reviewed.

What doesn't happen is routine surveillance. There's no dashboard flagging students, no automated alert, and no report that lands in an instructor's inbox. The data sits there unless someone deliberately goes to look at it.

The thing that actually looks unusual

If you take one practical point from this article, make it this one: timing patterns are far more visible than focus events.

Answer timestamps show the rhythm of an attempt. Human problem-solving is irregular — some questions take eight seconds, some take four minutes, and people revisit questions they were unsure about. That irregularity is what a normal log looks like.

What reads as anomalous is uniformity: forty questions answered at almost identical intervals, or an entire exam completed in a fraction of the expected time with no revisions. Those patterns are visible at a glance in a way that a scattering of focus events simply isn't.

This is also the honest argument for working through material rather than racing it. An attempt where you actually thought about the questions produces a log that looks like someone thinking about questions, because that's what happened.

What this means in practice

Three takeaways worth holding onto:

  • The fear is overstated. Canvas cannot see your other tabs or your screen. The most alarming claims online are simply false.
  • The log is mostly a support tool. Its most common real-world use is confirming that a student's technical problem actually happened.
  • Understand the material. No amount of knowledge about logging changes the fact that the person who understands the content finishes faster, with a normal-looking attempt, and does better on the parts no tool helps with.

If you want the mechanics of the quizzes themselves — question types, autosave, how grading works — that's covered in how Canvas quizzes work.

Understand the question, not just the answer

Answerly AI explains the reasoning behind Canvas questions, so the concept sticks — which is the part that shows up on the final.

See how it works →

Frequently asked questions

Can Canvas tell if you switch tabs during a quiz?

Canvas can record that the quiz page lost focus, which happens when you switch tabs, switch applications, minimize the window, or when a notification steals focus. It logs that focus was lost and regained — not what you looked at. Canvas cannot see your other tabs, your browsing history, or anything outside the quiz page.

What does a Canvas quiz log actually show?

A timeline of the attempt: when the session started, when each question was answered, when answers were changed, and events indicating the quiz page stopped or resumed being viewed. It shows timing and sequence, not content from outside the quiz.

Do instructors actually check Canvas quiz logs?

Rarely, and usually only when something else prompts it — a grade far out of line with a student's other work, a technical dispute about a submission, or an existing integrity review. The log is not generated automatically or reviewed for every student.

Is losing focus on a Canvas quiz proof of cheating?

No. Focus events have many innocent causes: a notification, an accidental click outside the window, a second monitor, a screen reader, or the browser itself. On its own, a focus event shows only that the page wasn't in the foreground, which is why it's weak evidence and why institutions generally require more than a log to support an allegation.

Does Canvas record quiz activity for New Quizzes too?

Yes. New Quizzes keeps its own activity log with comparable information — session start, per-question answer events, and page visibility events. The format differs from the Classic Quizzes log, but the type of data is similar.