Combined
Product guide

Desktop Capture

Install, enroll, consent to policy, understand local capture, read states, pause, and re-enroll.

Desktop Capture is a signed endpoint application that converts policy-approved on-device activity into structured context. Raw screenshots, video, and audio remain on the employee computer and are never uploaded in v1.

Install and enroll

Use the signed installer supplied by your organization. Open the invitation link or enter the enrollment code shown by the Account administrator. Enrollment binds the application build, Account, Desktop Source, endpoint, enrollment epoch, policy revision/hash, release channel, and endpoint credential.

The application requests Screen Recording only when OCR is enabled and Accessibility only when accessibility text is enabled. Follow the operating-system prompt, then return to the application. If the company changes a capture-sensitive policy, the endpoint requires re-enrollment so the employee consents to the new policy hash.

Policy options

The administrator policy controls:

  • whether the endpoint is assigned to capture;
  • centralized structured retention from 1–30 days;
  • local raw Screenpipe retention from 0–7 days;
  • accessibility text, OCR text, and window-title inclusion;
  • browser URL handling: none, origin only, or origin and path;
  • excluded applications, domains, and window-title patterns.

Baseline exclusions always block password managers, private/incognito windows, authentication and recovery screens, payment/checkout paths, Screenpipe itself, and malformed browser URLs. Secret and payment-card patterns are redacted before encrypted outbox persistence.

Data flow

Screenpipe runs locally with keyboard, clipboard, click, and scroll capture disabled. Combined projects permitted observations into structured application-activity and text records with endpoint, epoch, modality, policy hash, and safe browser/window provenance. The encrypted local outbox uploads bounded, ordered batches. It deletes acknowledged batches only after server acceptance.

States and actions

StateResponse
enrollment_requiredEnter the invitation code or open the link
enrollingWait while identity, policy, and release integrity are verified
permission_requiredGrant the named OS permission or open Settings
starting_captureWait for the protected local component
readyStructured context is flowing
offlineConnectivity is unavailable; encrypted batches remain local
failedUse the displayed retry/settings/re-enroll action and issue code
revokedCapture is stopped; a new enrollment is required

Choose Pause capture on this device to stop local capture and revoke the endpoint. An outbox at its byte bound also pauses new capture until queued structured context uploads.

See Desktop privacy for the trust boundary and Desktop troubleshooting for recovery.

On this page