Everything here happens on your organization's home page in the dashboard. During setup it leads with a Get set up checklist that walks the rollout top to bottom, with each action on the step it belongs to and a check that fills in as each step is satisfied; below it sit the roster and devices. flowscope creates the organization and grants you access, and your contact can run any step with you.
- ✓Get the agent installerThe installer IT pushes to the fleet through Intune.Agent (.intunewin)
- IISet up the browser extensionForce-installs by browser policy, or self-serve from the store.Force-install guideChrome Web Store
- IIIMark deployment doneFlip each on once IT has pushed it. Both required before you add your team.Agent (Intune) Extension
- IVAdd your teamEach person is emailed their pairing link as you add them. Green once everyone's paired.Add employee
- VBegin captureFinish the steps above first. It starts capture.Begin capture
- IAdd your teamEach person is emailed a link to install flowscope and pair. Green once everyone's paired.Add employee
- IIBegin captureFinish the steps above first. It starts capture.Begin capture
1. Get the agent installer
Download the agent installer here; this is the file IT pushes to the fleet through Intune. The guide IT follows is Deploying the desktop agent with Microsoft Intune, and the egress destinations to allow are in Network and security requirements.
2. Set up the browser extension
The browser extension is not a download: it force-installs by browser policy from flowscope's self-hosted build, so IT points the policy at flowscope's update manifest and it installs with no per-person action. The full steps, the extension ID and manifest URL, and the self-serve path are in Rolling out the browser extension.
3. Mark deployment done
Once IT has pushed each piece to the fleet, flip the Agent (Intune) and Extension (browser policy) switches. Both must be on before you can add your team: until then the Add employee action stays disabled, so nobody is invited to open software that is not on their machine yet.
4. Add your team
Use Add employee to add each participant by work email. Because flowscope is already on their machines from the rollout above, each person is emailed their pairing link the moment you add them. You can work through the whole roster here, with each row filling in once that person signs in.
When someone has not paired yet, the Resend control on their pending invitation and the Remind control on their roster row re-deliver the nudge, so there is no separate batch step to remember. Each recipient signs in, accepts the agreement, and pairs their device, which then sits idle, capturing nothing, until you begin capture.
| Role | EULA | Devices | Joined | |
|---|---|---|---|---|
| alex@yourcompany.com | member | accepted | pairedwindowsv1.0.0ok2m agonot pairedbrowserdeployed, awaiting pairing | May 12, 2026 |
| sam@yourcompany.com | member | not yet | none paired | May 14, 2026 |
Adds them to the roster and emails them their pairing link right away. Their email is verified by one-time code at sign-in.
Watch the fleet come online
| Role | EULA | Devices | Joined | |
|---|---|---|---|---|
| alex@yourcompany.com | member | accepted | pairedwindowsv1.0.0ok2m agonot pairedbrowserdeployed, awaiting pairing | May 12, 2026 |
| sam@yourcompany.com | member | not yet | none paired | May 14, 2026 |
As participants sign in and pair, the Your team table fills in:
- EULA reads not yet, accepted, or stale (accepted an older version than the one in force).
- Devices lists each paired device with its platform, agent version, capture-health indicator, and last check-in. A device quiet for more than about ten minutes is flagged.
- The capture-health indicator reads ok, or flags permission denied or error (most often the agent needs reopening, or UI Automation has not attached yet). A flagged device usually just needs the participant to reopen the app and follow its prompts.
Pending invitations sit in their own section, and you can cancel one sent in error.
A device that has paired is online but is not yet capturing anything: the whole fleet stays idle through setup and starts capturing together when you begin capture, in the next step.
5. Begin capture, and save your recovery key
The recovery key (the capture salt) is what maps pseudonymized activity back to a person. flowscope holds it only during setup and gives it up the moment you begin capture. Begin capture stays locked until flowscope clears your engagement to start, so even with every step above complete the button can read "awaiting flowscope's go-ahead" for a short while. Once we approve it, and when everyone is paired, click Begin capture. The confirmation makes you complete three things:
- It shows the recovery key once. Copy it and store it somewhere durable, such as your password manager or secrets vault.
- It asks you to paste the key back, to confirm you saved it.
- It asks you to acknowledge that your organization is responsible for safeguarding the key and for any re-identification it performs with it.
| Role | EULA | Devices | Joined | |
|---|---|---|---|---|
| alex@yourcompany.com | member | accepted | pairedwindowsv1.0.0ok2m agonot pairedbrowserdeployed, awaiting pairing | May 12, 2026 |
| sam@yourcompany.com | member | not yet | none paired | May 14, 2026 |
This starts capture on every paired device and permanently deletes our copy of your recovery key, and neither effect can be undone.
- Every paired device starts capturing within a few minutes.
- No more people can be added to this organization.
- We permanently delete our copy of your recovery key, so captured activity stays pseudonymized. The key below is then the only way to ever map activity back to specific people. Save it now.
••••••••••••••••••••••••••••••••••••••••••••••••On confirm, three things happen at once: every paired device begins capturing within a few minutes, the fleet is sealed (no further people or devices), and flowscope wipes its copy of the key. Because capture starts only now, after the wipe, every event flowscope ever receives is pseudonymized in a way flowscope cannot reverse.
Revoke a device
Revoking a device from its row disables its credential immediately: it stops capturing and cannot upload. During setup, before capture begins, someone who needs to return just pairs again, which issues a fresh device.
Pairing only works during setup. After Begin capture, no device can pair, re-pairs included, so handle late additions and swaps before you begin capture. The running phase is covered in While the engagement is running.
Review the app allowlist
Capture stays inside your organization's App allowlist, so the allowlist page is where you decide the scope. flowscope proposes the list from the systems you named, and keeps proposing as capture runs: business systems that fall inside the workflow scope you confirmed are added for you, and anything flowscope cannot place with confidence waits for your decision. Once capture begins, flowscope emails your admins when new items are waiting for review. Adding a system never turns on screen capture, which is a separate clearance. If you would rather decide every app yourself, switch the automatic additions off on the same page. That applies from then on and does not remove what is already on the list.
Mapping pseudonyms after capture begins
After Begin capture, flowscope no longer holds the recovery key, so the dashboard provides a browser-only tool behind the settings gear in the top right of your organization's home page: paste your saved key and it computes each member's pseudonym locally. The key is never sent to flowscope and is forgotten on refresh. This is the only place the mapping can be done, and only with the key you escrowed.
Capture scope
What the software may observe (the per-organization allowlist) and what it never observes (the permanent denylist) are part of the agreed configuration. Participants can see the scope that applies to them, pause and resume capture, and remove the software. The participant view is in Your privacy and controls; the full posture is in the Discovery trust addendum.