Desktop capture
Enroll Combined Desktop, configure capture policy, understand permissions, and recover unhealthy installations.
Combined Desktop creates a governed Source from permitted on-device activity. It is designed around an explicit account policy and operating-system consent: installing the app alone does not grant capture access.
What the Desktop Source records
Depending on policy and OS permissions, the app can use accessibility data, OCR, window titles, and browser URL metadata to produce structured context. Browser URL policy can be:
none: do not retain URL metadata.origin: retain only the scheme and host.origin_and_path: retain the origin and path, without credentials or fragments.
Account exclusions can prevent selected applications, windows, or URL patterns from entering capture. Configure exclusions before broad rollout and test them on a representative installation.
Enrollment
- In Sources, add or open the Desktop Source.
- Download the app and use the generated enrollment flow.
- Sign in to the intended account and approve the requested OS permissions.
- Confirm the installation becomes
readyand the Source begins reporting freshness.
An enrollment binds the app to one account and Desktop Source. Reinstalling or revoking an installation may require a fresh enrollment rather than reusing an old credential.
App states
| State | Meaning and action |
|---|---|
booting | Local services are starting; wait briefly. |
enrollment_required | Open the Source enrollment flow. |
enrolling | Authorization is being exchanged; keep the app open. |
permission_required | Grant the OS permission named in the app. |
starting_capture | Capture services are initializing. |
ready | Policy is loaded and permitted capture is active. |
offline | The app cannot reach Combined; check network and system time. |
failed | Open diagnostics and retry after correcting the reported issue. |
revoked | The enrollment no longer authorizes this installation; enroll again. |
Retention controls
Workspace policy supports server-side retention from 1 to 30 days and local raw retention from 0 to 7 days. A local raw retention of 0 minimizes local persistence. Changing retention affects future cleanup schedules; use the Settings privacy and retention view to see the active policy.
Deleting the Desktop Source uses the same governed asynchronous deletion workflow as other Sources. Uninstalling the app stops new capture but does not replace Source deletion or workspace retention policy.
Permission and policy troubleshooting
If the app remains in permission_required, open the relevant OS privacy settings, enable the named permission for Combined Desktop, then fully restart the app. If it is offline, verify HTTPS access to the Combined deployment and correct an inaccurate device clock. If it is revoked, do not copy enrollment material from another device; start a new enrollment from Sources.
For support, export the app's diagnostics from the UI. Review the bundle before sharing it and do not add tokens, captured content, or credentials to a support message. See Safe diagnostics.