It fetches a page, gets a wall or an empty shell, and reports back as if nothing happened. We measure which of your surfaces actually open, which open only for a session a person has already vouched for, and which are closed to you no matter what you do.
eBay search results, measured 7 September 2026 and reproduced on a second independent run the same day. One browser started fresh, the way most agent stacks start every run. One carrying a profile a person had verified once, weeks earlier. The agent code was identical. Walmart, measured in the same batch, went from 1,196 characters to 226,307. Nothing in either cold run told the agent it had been shown a wall.
Every surface is loaded twice. Once in a browser profile created fresh for that request, which is what almost every agent stack does by default. Once in a long-lived profile that has been through any human verification a single time. What gets recorded is the accessibility tree the browser exposes, the same structure a screen reader reads, plus any block signal the page raises.
No language model touches the verdict. That matters for three reasons: a run costs nothing to repeat, it returns the same answer twice, and there is nothing in the pipeline that can invent a finding. Every tree we captured ships with the report, so any line in it can be checked against what the browser actually saw.
When a pass fails for our reasons rather than the site's, we retry, and if it still fails we mark the surface no verdict and say so. A tool timeout is not evidence that a site refused you.
Reads fine on a cold browser. No session, no negotiation.
Nothing to do. Re-test on a schedule.Empty or blocked cold, fully readable once the browser carries a human-verified session.
Fixable this week. Usually the largest single recovery.Bot detection refuses you on every profile tried. No amount of session warming changes it.
Get admitted: the site's API, an allowlist entry, or a signed agent identity.An account wall stands in front of the content on every profile.
Provision a real account, warm it once by hand, read the terms first.Loads, but returns little structure. The content is behind an interaction your agent never performs.
Script the interaction, or find the feed.Passed on one profile and failed on another. The site's posture toward you is not settled.
Re-run, then retire the flagged profile.Every battery we run goes up dated, including the ones that make no case for hiring us. A benchmark you only publish when it flatters you is marketing, and nobody should trust a number from it.
Cloudflare's new AI traffic classes take effect. Traffic classified as Agent, which explicitly covers browser-use agents acting in real time on a person's behalf, is blocked by default on pages that carry advertising. It applies to new Cloudflare domains, newly added sites, and all existing free-tier customers. Search-class crawlers stay allowed, and site owners can opt out.
If your targets are ad-free B2B sites, that particular change is close to a no-op, and we will tell you so rather than sell you a fire. The reason it matters is narrower and more durable: Agent is now a category that sites write policy about. Cloudflare, AWS, Akamai and HUMAN Security are shipping cryptographic agent identity under the IETF's Web Bot Auth work, and a signed agent that a site has chosen to admit skips the challenge entirely.
Which means the question stops being how well your agent blends in, and starts being whether the sites you depend on know who you are and have decided to let you through. Most teams cannot answer that for their own top twenty surfaces. That is the gap this audit closes.
We do not build fingerprint spoofing, we do not automate press-and-hold challenges, and we do not resell CAPTCHA-solving farms. That work violates the terms of the sites you are hitting, it puts your payment processing and your legal exposure somewhere you do not want them, and it decays every time a detection vendor ships.
Real sessions that persist. Accounts provisioned and warmed properly. Official APIs and data feeds where they exist. Allowlist requests to the sites that matter most. Signed agent identity where the site supports it. Slower to set up, and it still works next quarter.
This is not posturing. If your access problem can only be solved by pretending not to be a bot, the honest answer is that you do not have an access problem, you have a business-model problem, and we will say that in the readout.
So you can check whether any of this is real before paying for it.
Two weeks from kickoff.
Sites change without telling anyone. Most teams find out when a pipeline goes quiet.
Name three surfaces your agent depends on. We will run both passes against them and send back what the browser actually saw, whether or not it makes a case for hiring us. If all three come back open, that is a useful thing to know and it costs you nothing.