Search documentation

Find a guide by title or topic

Deployment & devices

Deploy the desktop agent

Download the installers, create enrollment tokens, install silently with Intune, SCCM or Group Policy, and announce the rollout with the Rollout kit.

ForOwnerAdmin

The desktop agent is what records time, apps and — if your policy allows — screenshots on each computer. You can hand people an installer to run themselves, or push it silently to a whole fleet with Intune, SCCM or Group Policy. Either way, nothing is captured until each person has read the first-run disclosure.

Who can do this:OwnerAdminOwners and admins use the Deployment page. People who install the agent themselves only need the installer and their TimeLogger sign-in.

Before you roll out#

Tell people before the agent arrives. The recommended sequence, which also appears as a Rollout checklist on the Deployment page, is:

  1. Choose and review the tracking policy in plain language.
  2. Share the “what we collect” page with your team before rollout — the Rollout kit below does most of this for you.
  3. Create an enrollment token per MDM group.
  4. Pilot on 3–5 devices and check the Live board.
  5. On macOS, grant screen recording and accessibility permissions with a PPPC profile (once the macOS agent is available).
  6. Roll out to the remaining devices.
  7. Confirm every device shows Healthy on the Devices page.

Download the installers#

Go to WorkspaceDeploymentDeploy the agent. Under Installers, the Windows card offers two downloads for the latest released version:

InstallerWhat it means
MSI (Intune, GPO)Installs for every user on the machine and needs admin rights. Updates are pushed by your MDM, or by the agent when it runs elevated. Use it for fleets.
Setup .exeInstalls for the current user only, with no admin rights, and installs updates itself once the person picks Update now. Use it when people install the agent themselves.

Download links are signed and expire after a few minutes; reload the page for a fresh one. If nothing has been published on your server yet, the card says No installer published yet instead.

Unsigned builds

While a release isn’t code-signed, it shows an Unsigned badge and Windows SmartScreen or antivirus tools may warn before installing. Check the installer’s SHA-256 against the release list on the Devices page before you deploy it.
The Deployment page in the Acme Studio workspace.

Create an enrollment token#

An enrollment token lets the agent join your workspace without anyone typing a password — ideal for silent installs. Create one per MDM group so you can revoke a group on its own.

  1. Start a token

    On the Deployment page, choose New enrollment token.

  2. Describe it

    Give it a Label such as Intune — Finance laptops. Leave Bind to a member (optional) empty for a fleet token — the agent then matches the signed-in Windows user’s email. Pick when it Expires after (1 day to 1 year).

  3. Copy it now

    Choose Create token. The token is shown once: store it in your MDM secret store. If you lose it, create a new one.

Sample dataThe token in the Acme Studio demo workspace
LabelBound toStatus
Demo MDM rolloutAny member (matched by email)Active

Install silently with Intune, SCCM or Group Policy#

Deploy the MSI as a Win32 app or startup script with your server address and token. The agent installs for everyone on the machine, starts at each sign-in, and enrols itself on first start:

cmd
:: Intune / SCCM / GPO: silent, machine-wide, enrols on first start
msiexec /i "TimeLogger Agent_1.0.0_x64_en-US.msi" /qn /norestart ^
  SERVER_URL=https://timelogger.example.com ENROLLMENT_TOKEN=tl_enr_xxx

For people installing on their own account without admin rights, the Setup .exe takes the same values:

cmd
:: Per user, no admin rights (the agent then updates itself)
"TimeLogger Agent_1.0.0_x64-setup.exe" /S /ENROLLMENT_TOKEN=tl_enr_xxx /SERVER_URL=https://timelogger.example.com

How enrolment works#

  • The MSI writes the token and address to HKLM\Software\TimeLogger\Agent; the Setup .exe writes them to %LOCALAPPDATA%\TimeLogger\enrollment.json.
  • The agent also accepts --enroll-token, --server-url and --enroll-email, or the environment variables TIMELOGGER_ENROLL_TOKEN, TIMELOGGER_BASE_URL and TIMELOGGER_ENROLL_EMAIL.
  • A token bound to a person enrols that person. A fleet token also needs an email: the agent uses the signed-in Entra ID / AD account, and asks the person for their work email if there is none.
  • Use short-lived tokens. MSI properties can end up in install logs, and the registry value stays readable on the machine.

To remove the agent:

cmd
msiexec /x "TimeLogger Agent_1.0.0_x64_en-US.msi" /qn

The Deployment page shows the same commands under MDM snippets, pre-filled with your server’s address.

What happens on each computer#

  1. The agent starts at sign-in

    It starts for every user at Windows sign-in and restarts itself after a crash. It’s always visible in Task Manager.

  2. It enrols

    Using the token, or — for a self-install — the person signs in with their TimeLogger email and password.

  3. The person reads the disclosure first

    The agent window opens with a plain-language list of what the policy collects and what it never collects. Nothing is captured until they acknowledge it.

  4. Tracking begins as the policy says

    Automatic policies start inside the capture window; manual policies wait for someone to press Start.

What the member sees

Enrolment never skips the disclosure, including silent MDM installs. The person can open the agent and their MeMy data & privacy page at any time to see what’s being recorded. Share Use the desktop agent with your team.

Tell people with the Rollout kit#

Open WorkspaceDeploymentRollout kit. Everything in it is generated from your live policies, so it says exactly what your workspace collects:

PartWhat it means
Announcement emailA ready-to-send email. Use Copy email or Open in email app, and edit freely before sending.
Printable noticesOne per policy in use: what is collected, what is never collected, how long it’s kept and who can see it. Choose Print notice.
Employee FAQHonest answers to the questions people actually ask. Use Copy FAQ to paste it into your intranet.
Guidance for managersHow to talk about the rollout and how to read the data fairly.
The Rollout kit, generated from Acme Studio’s policies.

Questions#

Can I deploy to macOS or Linux?
Not yet. Version 1.0 ships the Windows agent. The Deployment page shows the macOS card once a macOS installer is published; Linux comes in a later release.
Someone’s agent asked them for an email during a silent install. Why?
The token wasn’t bound to a person and the computer has no Entra ID / AD account signed in, so the agent couldn’t tell who it belongs to. Bind the token to the person, or pass --enroll-email.
How do updates reach devices?
Agents check for a new version shortly after start and then hourly, and install it themselves after verifying it. You can pause updates or pin a version — see Devices and agent versions.
A token leaked. What do I do?
Create a new token for future installs and revoke the old one. Use Revoke on the token’s row in Deployment › Enrollment tokens (it’s audited). Devices that already enrolled keep working; a revoked or expired token can’t enrol anything new. Short expiry times limit the risk.

Something unclear or out of date? Tell your workspace admin, or write to the TimeLogger team from Settings — we update these guides with every release.