IT setup docs
Set up Safe-Desk for your firm.
For the person who looks after the firm's computers. These pages cover rolling Safe-Desk out to every desk, what it touches, and how to tell that it works. Each page says what runs today. Anything not live yet carries a marker that reads Available after launch.
What Safe-Desk does, in one paragraph
Staff keep using ChatGPT, Claude and the other AI tools they already know. Before a message leaves the browser, Safe-Desk swaps client data such as SSNs, account numbers and client names for placeholders like [SSN_1], so the AI provider only receives placeholders. The staff member who sent it sees the real values again in the answer; nobody else does. The owner gets a log of who sent what kind of data, when, and which rule caught it. The log holds labels, never the values.
Who can do what
| Role | Can do |
|---|---|
| Owner | Everything for the firm: staff, the industry template and rules, alerts, API keys, billing, and the activity log. |
| IT admin Available after launch | Everything in setup: staff (including a bulk add of up to 200 people), rules, client list, topics, devices and device policy, the connector and API keys. Nothing about billing, the account, the AI spending limit, or the firm's log, activity, alerts and reports. Only the owner invites or removes an IT admin. Until this role ships, the owner does these steps or signs in beside you. |
| Staff | Use the AI tools through Safe-Desk, connect their own browser and AI apps, upload files for the connector. They see only their own values and files. |
| SOPHIA XT platform admin | Our own support staff. Sees server errors (scrubbed of client data) and each firm's status, never message text or values. |
Owner screens refuse staff at the server, not only in the page.
The recommended order
- Owner signs in and confirms the industry template.Owner10 min
At desk.sophiaxt.com/app, Owner view, Template tab. Set names, places and dates to off, flag or protect, and paste the client list so client names are always caught. - Add staff.Owner5 min, plus 2 min per person
Owner view, Staff tab. Each person gets a one-time link to choose a password. Seats follow the number of people who can sign in. - Install the browser extension on every computer.IT20 min to set the policy, then up to a few hours for machines to pick it up
Force-install it through Google Admin, Intune, Group Policy, your RMM tool or a Mac profile. See Install the extension. - Each person signs the extension in once.Staff2 min each
Click the Safe-Desk icon and sign in, or type a connection code from Settings. Force-installing does not sign anyone in; see how sign-in works. - Install the Windows app where staff use desktop AI apps.IT10 min Available after launch
Only needed for the ChatGPT, Claude or Copilot desktop apps. See Windows app. - Optional: add the AI connector to Claude or ChatGPT.Each person5 min
Lets a person's own AI draft from client files with placeholders only. See AI connector. - Optional: put the gate in front of your own software.Owner and a developer30 min
See Gate API. - Check that it works.IT5 min
Open desk.sophiaxt.com/connect while signed in. Each check turns green once that connection works. What each green check means.
Before you start
- The firm needs an active subscription or trial. Protection stops, visibly, when the subscription lapses; the extension shows OFF on its icon and a notice on the chat page.
- Computers must reach
https://desk.sophiaxt.comover HTTPS (port 443). If your firewall filters by host name, allow that host. The extension holds a paste or a message back rather than sending it unchecked when it can't reach Safe-Desk. - For the security questionnaire, start with Security review. It lists what is stored, for how long, how it is encrypted, and every subprocessor.
Pages in this guide
| Page | For |
|---|---|
| Install the extension | Force-install for Chrome and Edge with Google Admin, Intune, Group Policy, PowerShell or a Mac profile. |
| Windows app | The tray app for desktop AI apps: silent install, sign-in, what it gates. |
| AI connector | OAuth endpoints, scopes, token lifetimes and data flow for the Claude and ChatGPT connector. |
| Gate API | Keys, protect and restore, errors, limits. |
| Security review | Architecture, storage and retention, encryption, tenancy, audit, subprocessors. |
| Troubleshooting | Symptom, check, fix, for each part. |
Questions, or a step that doesn't match what you see: contactus@sophiaxt.com.