SOPHIA XT

IT setup docs

Set up Safe-Desk for your firm.

For the person who looks after the firm's computers. These pages cover rolling Safe-Desk out to every desk, what it touches, and how to tell that it works. Each page says what runs today. Anything not live yet carries a marker that reads Available after launch.

What Safe-Desk does, in one paragraph

Staff keep using ChatGPT, Claude and the other AI tools they already know. Before a message leaves the browser, Safe-Desk swaps client data such as SSNs, account numbers and client names for placeholders like [SSN_1], so the AI provider only receives placeholders. The staff member who sent it sees the real values again in the answer; nobody else does. The owner gets a log of who sent what kind of data, when, and which rule caught it. The log holds labels, never the values.

Who can do what

RoleCan do
OwnerEverything for the firm: staff, the industry template and rules, alerts, API keys, billing, and the activity log.
IT admin Available after launchEverything in setup: staff (including a bulk add of up to 200 people), rules, client list, topics, devices and device policy, the connector and API keys. Nothing about billing, the account, the AI spending limit, or the firm's log, activity, alerts and reports. Only the owner invites or removes an IT admin. Until this role ships, the owner does these steps or signs in beside you.
StaffUse the AI tools through Safe-Desk, connect their own browser and AI apps, upload files for the connector. They see only their own values and files.
SOPHIA XT platform adminOur own support staff. Sees server errors (scrubbed of client data) and each firm's status, never message text or values.

Owner screens refuse staff at the server, not only in the page.

The recommended order

  1. Owner signs in and confirms the industry template.Owner10 min
    At desk.sophiaxt.com/app, Owner view, Template tab. Set names, places and dates to off, flag or protect, and paste the client list so client names are always caught.
  2. Add staff.Owner5 min, plus 2 min per person
    Owner view, Staff tab. Each person gets a one-time link to choose a password. Seats follow the number of people who can sign in.
  3. Install the browser extension on every computer.IT20 min to set the policy, then up to a few hours for machines to pick it up
    Force-install it through Google Admin, Intune, Group Policy, your RMM tool or a Mac profile. See Install the extension.
  4. Each person signs the extension in once.Staff2 min each
    Click the Safe-Desk icon and sign in, or type a connection code from Settings. Force-installing does not sign anyone in; see how sign-in works.
  5. Install the Windows app where staff use desktop AI apps.IT10 min Available after launch
    Only needed for the ChatGPT, Claude or Copilot desktop apps. See Windows app.
  6. Optional: add the AI connector to Claude or ChatGPT.Each person5 min
    Lets a person's own AI draft from client files with placeholders only. See AI connector.
  7. Optional: put the gate in front of your own software.Owner and a developer30 min
    See Gate API.
  8. Check that it works.IT5 min
    Open desk.sophiaxt.com/connect while signed in. Each check turns green once that connection works. What each green check means.

Before you start

Pages in this guide

PageFor
Install the extensionForce-install for Chrome and Edge with Google Admin, Intune, Group Policy, PowerShell or a Mac profile.
Windows appThe tray app for desktop AI apps: silent install, sign-in, what it gates.
AI connectorOAuth endpoints, scopes, token lifetimes and data flow for the Claude and ChatGPT connector.
Gate APIKeys, protect and restore, errors, limits.
Security reviewArchitecture, storage and retention, encryption, tenancy, audit, subprocessors.
TroubleshootingSymptom, check, fix, for each part.

Questions, or a step that doesn't match what you see: contactus@sophiaxt.com.