flowscopeTrust Center
All docs
Rolling out

Running the engagement from the dashboard

Last updated July 27, 2026

Everything here happens on your organization's home page in the dashboard. During setup it leads with a Get set up checklist that walks the rollout top to bottom, with each action on the step it belongs to and a check that fills in as each step is satisfied; below it sit the roster and devices. flowscope creates the organization and grants you access, and your contact can run any step with you.

app.flowscope.com
Your Company
Your Company
Your team and their devices.
Get set up
Work top to bottom. New to this? See how a flowscope engagement works.
  1. Get the agent installer
    The installer IT pushes to the fleet through Intune.
    Agent (.intunewin)
  2. II
    Set up the browser extension
    Force-installs by browser policy, or self-serve from the store.
    Force-install guideChrome Web Store
  3. III
    Mark deployment done
    Flip each on once IT has pushed it. Both required before you add your team.
    Agent (Intune) Extension
  4. IV
    Add your team
    Each person is emailed their pairing link as you add them. Green once everyone's paired.
    Add employee
  5. V
    Begin capture
    Finish the steps above first. It starts capture.
    Begin capture
app.flowscope.com
Your Company
Your Company
Your team and their devices.
Get set up
Work top to bottom. New to this? See how a flowscope engagement works.
  1. I
    Add your team
    Each person is emailed a link to install flowscope and pair. Green once everyone's paired.
    Add employee
  2. II
    Begin capture
    Finish the steps above first. It starts capture.
    Begin capture

1. Get the agent installer

Download the agent installer here; this is the file IT pushes to the fleet through Intune. The guide IT follows is Deploying the desktop agent with Microsoft Intune, and the egress destinations to allow are in Network and security requirements.

2. Set up the browser extension

The browser extension is not a download: it force-installs by browser policy from flowscope's self-hosted build, so IT points the policy at flowscope's update manifest and it installs with no per-person action. The full steps, the extension ID and manifest URL, and the self-serve path are in Rolling out the browser extension.

3. Mark deployment done

Once IT has pushed each piece to the fleet, flip the Agent (Intune) and Extension (browser policy) switches. Both must be on before you can add your team: until then the Add employee action stays disabled, so nobody is invited to open software that is not on their machine yet.

4. Add your team

Use Add employee to add each participant by work email. Because flowscope is already on their machines from the rollout above, each person is emailed their pairing link the moment you add them. You can work through the whole roster here, with each row filling in once that person signs in.

When someone has not paired yet, the Resend control on their pending invitation and the Remind control on their roster row re-deliver the nudge, so there is no separate batch step to remember. Each recipient signs in, accepts the agreement, and pairs their device, which then sits idle, capturing nothing, until you begin capture.

app.flowscope.com
Your Company
Your Company
Your team and their devices.
Your team
Members and the devices they've paired.
Add employee
EmailRoleEULADevicesJoined
alex@yourcompany.commemberaccepted
pairedwindowsv1.0.0ok2m agonot pairedbrowserdeployed, awaiting pairing
May 12, 2026
sam@yourcompany.commembernot yetnone pairedMay 14, 2026
Add employee

Adds them to the roster and emails them their pairing link right away. Their email is verified by one-time code at sign-in.

Email
sarah@acme.com
CancelAdd

Watch the fleet come online

app.flowscope.com
Your Company
Your Company
Your team and their devices.
Your team
Members and the devices they've paired.
Add employee
EmailRoleEULADevicesJoined
alex@yourcompany.commemberaccepted
pairedwindowsv1.0.0ok2m agonot pairedbrowserdeployed, awaiting pairing
May 12, 2026
sam@yourcompany.commembernot yetnone pairedMay 14, 2026

As participants sign in and pair, the Your team table fills in:

  • EULA reads not yet, accepted, or stale (accepted an older version than the one in force).
  • Devices lists each paired device with its platform, agent version, capture-health indicator, and last check-in. A device quiet for more than about ten minutes is flagged.
  • The capture-health indicator reads ok, or flags permission denied or error (most often the agent needs reopening, or UI Automation has not attached yet). A flagged device usually just needs the participant to reopen the app and follow its prompts.

Pending invitations sit in their own section, and you can cancel one sent in error.

A device that has paired is online but is not yet capturing anything: the whole fleet stays idle through setup and starts capturing together when you begin capture, in the next step.

5. Begin capture, and save your recovery key

The recovery key (the capture salt) is what maps pseudonymized activity back to a person. flowscope holds it only during setup and gives it up the moment you begin capture. Begin capture stays locked until flowscope clears your engagement to start, so even with every step above complete the button can read "awaiting flowscope's go-ahead" for a short while. Once we approve it, and when everyone is paired, click Begin capture. The confirmation makes you complete three things:

  1. It shows the recovery key once. Copy it and store it somewhere durable, such as your password manager or secrets vault.
  2. It asks you to paste the key back, to confirm you saved it.
  3. It asks you to acknowledge that your organization is responsible for safeguarding the key and for any re-identification it performs with it.
app.flowscope.com
Your Company
Your Company
Your team and their devices.
Your team
Members and the devices they've paired.
Add employee
EmailRoleEULADevicesJoined
alex@yourcompany.commemberaccepted
pairedwindowsv1.0.0ok2m agonot pairedbrowserdeployed, awaiting pairing
May 12, 2026
sam@yourcompany.commembernot yetnone pairedMay 14, 2026
Begin capture

This starts capture on every paired device and permanently deletes our copy of your recovery key, and neither effect can be undone.

  • Every paired device starts capturing within a few minutes.
  • No more people can be added to this organization.
  • We permanently delete our copy of your recovery key, so captured activity stays pseudonymized. The key below is then the only way to ever map activity back to specific people. Save it now.
Recovery key
••••••••••••••••••••••••••••••••••••••••••••••••
Paste the recovery key back to confirm you've saved it
Paste the key here
CancelBegin capture

On confirm, three things happen at once: every paired device begins capturing within a few minutes, the fleet is sealed (no further people or devices), and flowscope wipes its copy of the key. Because capture starts only now, after the wipe, every event flowscope ever receives is pseudonymized in a way flowscope cannot reverse.

Revoke a device

Revoking a device from its row disables its credential immediately: it stops capturing and cannot upload. During setup, before capture begins, someone who needs to return just pairs again, which issues a fresh device.

Pairing only works during setup. After Begin capture, no device can pair, re-pairs included, so handle late additions and swaps before you begin capture. The running phase is covered in While the engagement is running.

Review the app allowlist

Capture stays inside your organization's App allowlist, so the allowlist page is where you decide the scope. flowscope proposes the list from the systems you named, and keeps proposing as capture runs: business systems that fall inside the workflow scope you confirmed are added for you, and anything flowscope cannot place with confidence waits for your decision. Once capture begins, flowscope emails your admins when new items are waiting for review. Adding a system never turns on screen capture, which is a separate clearance. If you would rather decide every app yourself, switch the automatic additions off on the same page. That applies from then on and does not remove what is already on the list.

Mapping pseudonyms after capture begins

After Begin capture, flowscope no longer holds the recovery key, so the dashboard provides a browser-only tool behind the settings gear in the top right of your organization's home page: paste your saved key and it computes each member's pseudonym locally. The key is never sent to flowscope and is forgotten on refresh. This is the only place the mapping can be done, and only with the key you escrowed.

Capture scope

What the software may observe (the per-organization allowlist) and what it never observes (the permanent denylist) are part of the agreed configuration. Participants can see the scope that applies to them, pause and resume capture, and remove the software. The participant view is in Your privacy and controls; the full posture is in the Discovery trust addendum.