You are deciding whether to run an engagement, or about to announce one to your organization. This page is the short version; every claim on it links to the document that backs it.
What an engagement is
A time-boxed observation of how work actually runs, ending in a map. A desktop agent and a browser extension read structured interaction events inside the applications your team approves, so the processes can be described as they are rather than as documented. The controls that bound it are in the Discovery Trust Addendum.
It observes. It does not act. Automating a process is separate, later, and separately agreed; when it happens, flowscope acts through your systems' own interfaces, with a person approving anything consequential. See the Workflow Execution Addendum.
What it asks of your organization
You approve the application list, so the scope is yours. Some categories are beyond anyone's control: personal banking, healthcare, password managers, personal email and similar are denied by design and cannot be enabled by any administrator, including yours. The list is published in the categorical denylist.
Participants are pseudonymous. Activity is labeled with a stand-in identifier derived under a key only your company holds. Your company owns the captured data, can request deletion of any participant's contribution at any time, and it is never used to train any AI model. The platform detail is in the Security and Trust Overview.
Telling your staff
This is the part that determines how the engagement goes. On a managed rollout the software reaches laptops before anyone can be invited, so if nobody has told your team first, the engagement starts with a surprise on their machine.
Send them the employee guide with your announcement, before IT deploys. It opens with a short video and needs no flowscope account.
Going deeper
Counsel reviewing this will want the white paper, a provision-by-provision technical and legal overview written for prospective customers and their advisors. It is available from security@flowscope.com, along with the MSA, the DPA and our formal information-security policies.