Onboarding guide

Your first hour as an Endpoint AI admin: what the Get started wizard asks you to decide, why each choice matters, and where every setting lives once the wizard is done.

The Admin section covers everything you run from the console as an administrator: rolling Harriet out across the organization, roles and permissions, billing and budgets, and the audit trail behind every tool call. Start here, then branch out:

Rollout playbook

Pilot team first, verify, then enroll team by team.

Roles & permissions

Who can view, manage, audit, and approve.

Plans & pricing

What each Endpoint AI tier unlocks.

The audit log

Every tool call, who made it, and whether it worked.

The Get started wizard

When you first open the console, Harriet walks you through six milestones. Each one is a real decision, not a tour stop, and each writes a setting you can change later. You can complete them in one sitting; the wizard tracks progress and picks up where you left off.

  1. LLM usage & billing. Decide how model calls get paid for: managed billing with free starting credit (no charge until you exceed it), your own API keys (BYOK), or skills and connectors only with no managed LLM billing. This decides whether Harriet can act as the LLM proxy for your devices. Afterwards this lives in Settings → LLM API keys (BYOK) and in Billing.
  2. Choose your desktop app. Pick Claude Desktop (with subscription), Claude Desktop without a subscription, or Harriet Desktop. This sets the account default for newly enrolled devices, so choose the surface most of your organization will use; see the desktop overview for the trade-offs. Afterwards this lives in Settings → Default desktop providers.
  3. Install your desktop app. Sign in to Harriet Desktop, or for the Claude Desktop modes install the background agent. This enrolls your own machine as the first device, so you can test everything before anyone else touches it.
  4. Add your first capability. Choose a simple demo skill, an MCP server, or a GitHub skill package. Harriet provisions your pick when the agent syncs. This decides what your first sync actually delivers; afterwards you manage capabilities in Skills and Connectors.
  5. Try it out. Run a quick read-only action in your chosen app to confirm the pipeline works end to end, or skip for now. A working demo call is the fastest proof that enrollment, sync, and the gateway are all healthy.
  6. Add teammates, then enrol devices. Add people as Harriet users in Manage users, then send each an enrollment invite from People so they can install the agent and link a device. This is where a personal setup becomes an organizational one.
💡

Alongside the milestones, the wizard shows three live signals: Background agent, Device, and Provisioning. They flip to done on their own as your machine checks in, so you always know whether a stalled step is a decision you haven't made or a sync that hasn't happened yet.

After the wizard

Nothing you chose is locked in. Desktop defaults, the LLM proxy, model availability, and API keys all live in Organization settings. Your enrolled machine appears under Devices, and the demo skill under Skills, where you can unassign it once real skills exist.

When your own device works, move to the rollout playbook: it turns milestone six into a staged, team-by-team deployment.