Workflow Observer

Getting started · managed pilot

Your first workflow Universe

Bring one owned workflow. Leave with a reviewed history, an executable set of rules and a recorded path you can inspect and run again.

Bring the right people and permissions

Workflow owner
Someone who can explain the work, review its history and approve what a successful outcome means.
Source administrator
Someone who can authorize the exact accounts and locations, configure the receivers and qualify the connection.
Engineering or AI lead
Someone who can define the candidate agent and agree which release decision the evaluation should support.
  1. Choose a case with a clear finish

    Start with a job your team already understands. Name its owner, the decision the agent should make and the evidence that would demonstrate a correct outcome.

    Example: qualify one sales opportunity, obtain its required approvals and complete the handoff. This is an illustrative pilot scope.

  2. Approve the sources that belong

    Create a project and open Workflow, then Observe the workflow. Define participants, devices, sources, content modes and retention. A workspace reviewer approves the exact capture scope before a receiver can use it.

    Choose specific email folders, channels, calls, CRM records or pages. Permission for one source never authorizes capture of another.

  3. Connect a receiver and collect the history

    Download the package for the approved source, participant and device. Your administrator supplies the matching account permissions and credentials. Import the receiver export into a named business case. Keep using that case across sessions and waiting periods.

    Service receivers use durable checkpoints. Native companions for macOS and Windows start visibly and record one participant-selected window. Optional screenshots require local masking and review. Optional continuous capture uses a bounded encrypted queue and current permission checks. Capacity or permission pauses remain visible gaps. You can also stop and export manually.

  4. Review the evidence and what belongs

    Inspect included activity, coverage gaps and uncertain events. Exclude unrelated work or restore an event that belongs. Review captured content separately, then have the workflow owner verify the exact case history.

    AI can suggest relevance. Automatic sorting requires measured calibration. New evidence or a correction makes the previous review stale so the owner can review the changed history.

  5. Define the rules and run the Universe

    Propose a workflow from the reviewed history. Set the actions, permissions, conditions and successful outcomes, then approve the rules and source rights. Compile the world, execute a path and branch a recorded checkpoint.

    For a model attempt, approve the model, data boundary and spending control first. The simulation executes your declared rules and does not write back to the source applications.

Choose the smallest useful capture scope

Available receiver types and the source boundary to approve
ReceiverWhat your team selects
BrowserApproved page origin and path; metadata capture.
macOS companionApproved signed application identity and one selected window; optional reviewed screenshots. Native distribution requires qualification.
Windows companionExact executable and signer-certificate SHA-256, approved application name and one selected native window. Click metadata and separately reviewed screenshots; optional closed-session transfer or manual export. Signed distribution and application qualification remain release gates.
Slack or TeamsExact approved channels and account identities.
Microsoft mailSelected folders, optionally narrowed to a conversation.
GongExact approved call records and transcripts.
SalesforceSelected opportunity records and approved fields.

The pilot uses bounded imports and storage. Agree expected volume, retention and recovery with your administrator before a long capture. Text redaction and screenshot masks need human inspection. Observed actions help draft a process; the owner supplies business rules that observation alone cannot establish.

macOS · bounded native pilot

Set up one approved macOS window

  1. In Observer, choose macOS · one selected native window. Enter the target app's exact bundle ID and signing Team ID, source account, device, expiry and retention. Choose metadata, or request reviewed screenshots when the entire selected window is authorized.
  2. Have the scope approved, download its exact receiver package and load it in the macOS companion. Starting opens the system window picker; choose one window of the approved signed app. Switching to unrelated work pauses capture.
  3. Stop the session, then use managed transfer or manually export encrypted evidence for Console import. Review the image content and decide which observations belong before verifying the case history. A local mask only replaces its declared pixels.

macOS 15.2 or later is required. Check desktop app availability and pilot installation before downloading your approved scope JSON. That JSON configures the companion; it is not the app installer. Public distribution still requires Developer ID signing, notarization and application qualification. Opening the companion does not start recording.

Windows · bounded native pilot

Set up one approved Windows window

Check Windows app availability and pilot installation →

Your administrator supplies the exact lowercase executable name, the executable file's SHA-256 and the signer certificate's SHA-256. The certificate store thumbprint used for release signing is a different identifier. A source package does not prove which enterprise account is open inside an application.

  1. In the project's Observer page, choose Windows · one selected native window. Enter the administrator's three exact application identifiers, source account, participant device, expiry and retention. Metadata is the default. Request reviewed screenshots only when the entire window is authorized; an administrator or TDM approves the exact scope.
  2. Download the receiver package for the approved source, participant and device. Load it in the Windows companion, press Start, then focus the approved native window during the countdown. The companion pins that window after checking its identity. Websites use the browser receiver.
  3. For screenshots, obtain separate approval for the whole selected window and the reviewed screenshot content mode. Invoke each capture and refocus the pinned window during the countdown. Draw opaque masks over sensitive regions and accept the reviewed image. Masks cover the declared rectangles; there is no automatic PII detection or guarantee that all sensitive content has been removed.
  4. Stop recording. If you opted in, managed transfer queues the closed session for Console review. For manual transfer, export an encrypted file and use Import an encrypted desktop recording in Observer with its passphrase. Review image content separately before the workflow owner verifies the case history.

The Windows companion protects its local recording and transfer credential in the current user’s encrypted vault. Each launch leaves recording stopped and managed transfer off. Unsigned builds are test artifacts. Public distribution still needs verified Authenticode signing, a valid timestamp and qualification on your approved applications.

Mac and Windows · optional managed transfer

Send each closed session for review

  1. Ask your administrator to register the collector credential for this exact scope, source, participant and device. Enter the trusted HTTPS API origin, exact project ID and credential in the companion, then choose Enable / retry managed transfer. The credential stays in the native encrypted vault.
  2. For continuous batches, select Continue this selected window while encrypted batches queue before Start. Choose your approved window once. A batch closes at five minutes, 400 events, ten accepted screenshots or 20 MB of encoded image data, whichever comes first. After that exact batch is saved in the encrypted queue, capture can continue in the same approved window while its upload runs.
  3. The queue holds at most three batches and 50 MB combined. Recording needs available space, the same window and consent, and current permission. Scope checks run about every eight seconds; authorization expires after fifteen seconds without renewal. A full queue, expired permission or failed check pauses capture and records a coverage gap. The queue does not extend offline recording permission.
  4. An uncertain upload keeps the exact encrypted batch for retry. Transient upload failures retry after thirty seconds while separate permission checks continue. A confirmed receipt removes only that batch, preserving the others. If a closed batch cannot fit, it stays saved locally and capture waits for space. Receipt of a batch does not approve its content or case history.
  5. Pause, Stop, changed window or lost permission cancels continuation. Every app launch requires you to enable transfer, choose continuation and Start again. Screenshots always require a separate capture and review.

You can leave continuous batches off, Stop when ready and transfer the closed session, or use encrypted file export and import. Manual recording is bounded to 500 events, 40 sessions and 12 reviewed screenshots; transfer before capacity is reached. Pending evidence expires under the approved retention policy. Keep using the same business case across batches.

Give the agent reviewed screen text

In Console, inspect a retained screenshot and save its content review. Choose Generate text draft for local English OCR on the Gradia server, or transcribe the image yourself. Check the draft against the image, correct errors and remove sensitive text before confirming and saving it.

A draft stays unapproved. Build and approve a new case edition and Universe to expose the reviewed text at the original event’s permitted time and visibility. The agent receives this source-bound text; screenshot pixels stay outside model requests.

Read-only service collection

Connect the records behind the work

  1. Choose Slack, Microsoft mail, Teams, Gong or Salesforce in Observer. Supply one exact channel, folder, call or opportunity ID and its required account and tenant bindings. Teams also requires its team ID; Slack can be narrowed to one thread timestamp.
  2. Choose metadata, or explicitly request text requiring human review. Salesforce text requires a selection of approved fields. Have the exact scope approved and link it to the business case.
  3. After scope approval, open its receiver package controls and configure the selected collector. Download a configuration containing exact bindings and credential environment references. Your administrator runs the managed collector supplied for your pilot with existing read permissions and durable local checkpoints. The collector checks the live scope and account before collection, and uploads admitted records with text pending review. The Console scope form does not perform provider sign-in.
  4. Keep the same case across sessions. Add renewed or additional approved scopes from the case history when permissions change. Review changes and compile a new Universe; old reviews and worlds become stale. Expired evidence remains unavailable.

For Slack, the collector remembers up to 1,000 discovered thread roots per approved channel and revisits them while retained, even after the root leaves the lookback window. Rate limits and page limits preserve the continuation for retry. An older thread the collector never discovered needs an exact approved thread rule; this is not a complete edit or deletion history.

A long business case can span many bounded sessions. Set lookback and retention deliberately, inspect coverage gaps and qualify each source connection with your enterprise administrator.

Selected AI history

Bring existing agent activity into the case

If your team already uses Hypaware, you can import a selected messages v7 export. In Observer, choose AI activity as the source type, approve its historical window and link that scope to a case. The import panel includes the export command and a preview where you choose the records to retain.

JSON and JSONL exports support source timestamps, models, tools and reported token counts. Prompts, responses and tool arguments are omitted. Each row represents a message part; imported history does not establish complete capture, verified execution or reproducible application state. Case review and approval of Universe rules remain separate steps.

Download a synthetic AI activity example

The example contains eight invented message parts across two sessions on September 1 and 3, 2026. Approve those dates explicitly and choose retention that still covers them. No agent installation or capture is required to inspect this example.

Make the first result useful

Ask the owner whether the approved world represents the job well enough to test. Inspect one complete path, a waiting period and a branch. Record missing coverage. Then reuse the same approved rules when the agent changes so the next evaluation answers a real release question.

Already have an agent running? Start with open-source Guard to capture and verify the activity it covers.