SOPHIA XT

IT setup docs

Set up Safe-Desk for your firm.

For the person who looks after the firm's computers. Most small firms need none of it: the owner pastes the team's emails into People, and each person presses one button on their own Get protected page. These pages cover rolling Safe-Desk out to every desk by hand or by policy, what it touches, and how to tell that it works. Each page says what runs today. Anything not live yet carries a marker that reads Available after launch.

What Safe-Desk does, in one paragraph

Staff keep using ChatGPT, Claude and the other AI tools they already know. Before a message leaves the browser, Safe-Desk swaps client data such as SSNs, account numbers and client names for placeholders like [SSN_1], so the AI provider only receives placeholders. The staff member who sent it sees the real values again in the answer; nobody else does. The owner gets a log of who sent what kind of data, when, and which rule caught it. The log holds labels, never the values.

Who can do what

RoleCan do
OwnerEverything for the firm: staff, the industry template and rules, alerts, API keys, billing, and the activity log.
IT adminEverything in setup: staff (including a bulk add of up to 200 people), rules, client list, topics, device policy, the Computers page, the connector and API keys. Computers is read only: each person disconnects their own devices in Settings, and to cut off a lost computer at once you switch the person off under People, Advanced, Accounts and passwords; that ends their sessions and signs out every browser and Windows app at its next check-in. Then switch them back on and issue a password link, so the old password stops working; they sign in again on each computer they still have. A person who is still switched off can set a password from the link but can't sign in with it. A password link you issue for a staff member is emailed to that person and never shown to you, so an IT admin can't sign in as a colleague; if Safe-Desk can't send email, only the owner can issue one. Nothing about billing, the account, the AI spending limit, or the firm's log, activity, alerts and reports. Only the owner invites or removes an IT admin. The owner invites you from Your firm, People, Advanced, Setup checklist, IT admins. You get a link to choose a password. The link works once, for 7 days. If it runs out, the owner sends a new one with Password link under Setup, IT admins. When you sign in, the button at the top reads Setup instead of Your firm. Publishing the AI use policy and phone alerts stay with the owner; the setup console marks them "owner". An IT admin takes a seat, billed like a staff member, from the moment the owner invites them until the owner removes them.
StaffUse the AI tools through Safe-Desk, connect their own browser and AI apps, upload files for the connector. They see only their own values and files.
SOPHIA XT platform adminOur own support staff. Sees server errors (scrubbed of client data) and each firm's status, never message text or values. For a done-for-you setup, or when a firm asks for help, can open that firm's setup screens (staff, rules, client list, topics and the API key list) for up to 60 minutes at a time. Every action is written to the firm's Activity as "SOPHIA XT setup (on behalf)". Never billing, the log, alerts or message text.

Owner screens refuse staff at the server, not only in the page.

The recommended order

  1. Owner or IT admin signs in and confirms the industry template.Owner or IT admin10 min
    At desk.sophiaxt.com/app, Your firm (Setup for an IT admin), Rules. Set names, places and dates to off, flag or protect, and paste the client list so client names are always caught. Paste names only, one client per line, first name first (Dana Reyes). Lines written Last, First (Reyes, Dana) are turned round for you. For a business, write the name as staff type it, with or without its ending (Acme Holdings, Acme Holdings LLC); a comma before LLC, Inc. or P.C. is fine, and a name of two words or more is also caught without the ending. For couples, put each person on their own line (John Whitfield, Jane Whitfield); a line such as John & Jane Whitfield is split for you. From a spreadsheet, copy just the name column: rows with extra columns, such as an email or phone number, are listed back to you and not added.
  2. Add staff.Owner or IT admin5 min, plus 2 min per person
    Your firm, People: paste the team's emails into Add your team and press Send. Each person gets a one-time link to choose a password. A seat is billed from the moment a person is added, whether or not they have opened their link yet. Switch someone off under People, Advanced, Accounts and passwords to stop their seat.
  3. Install the browser extension on every computer.ITAbout 5 min each today
    Today each person downloads it from Settings and loads it in Chrome or Edge (steps). Once the Chrome Web Store listing is live, force-install it through Google Admin, Intune, Group Policy, your RMM tool or a Mac profile. See Install the extension.
  4. Each person connects the extension once.Staff2 min each
    Until the store listing is live, use a connection code: Settings, Get a connection code, then type it in the extension popup and press Connect. Sign in with Safe-Desk works once the extension comes from the Chrome Web Store. Force-installing does not sign anyone in; see how sign-in works.
  5. Install the Windows app where staff use desktop AI apps.IT10 min Available after launch
    Only needed for the ChatGPT, Claude or Copilot desktop apps. See Windows app.
  6. Optional: add the AI connector to Claude or ChatGPT.Each person5 min
    Lets a person's own AI draft from client files with placeholders only. See AI connector. The setup console's "Connect your AI" step is required, but a signed-in browser extension or Windows app already completes it, so step 4 covers it.
  7. Optional: put the gate in front of your own software.Owner and a developer30 min
    See Gate API.
  8. Owner publishes the AI use policy and turns on phone alerts.Owner10 min
    Your firm, Rules, Advanced, AI-use policy, then Account, Advanced, Alerts on your phone. The setup console marks both "owner"; it shows the firm as set up only after they are done.
  9. Check that it works.IT5 min
    Open People, Advanced, Computers: each person's devices and last check-in. Ask one staff member to open desk.sophiaxt.com/connect on their own computer to confirm their checks are green. What each green check means.

Before you start

Pages in this guide

PageFor
Install the extensionForce-install for Chrome and Edge with Google Admin, Intune, Group Policy, PowerShell or a Mac profile.
Windows appThe tray app for desktop AI apps: silent install, sign-in, what it gates.
AI connectorOAuth endpoints, scopes, token lifetimes and data flow for the Claude and ChatGPT connector.
Gate APIKeys, protect and restore, errors, limits.
Security reviewArchitecture, storage and retention, encryption, tenancy, audit, subprocessors.
TroubleshootingSymptom, check, fix, for each part.

Questions, or a step that doesn't match what you see: contactus@sophiaxt.com.