Skip to content

Enterprise

Your sign-in.
Your rules.

Let people in through the identity provider you already use, keep sign-up to invitations, and decide whether AI is involved at all.

Microsoft Entra ID · Google · any OIDC provider

Single sign-on options
Workspace roles
AI required

Entra ID, Google or any OIDC provider. Owner, admin, editor and viewer. And no AI at all unless you choose a provider.

Where it lives

One file holds all of it

Who signs in, who may invite people and whether any AI is involved are agreed with you up front. Nothing is switched on without you.

If you do not want a way in, it is simply not offered. We host and maintain Chronika, so your team only records, edits and shares guides.

Your setupExample
Sign-in
Microsoft Entra ID
or Google, or any OIDC
Passwords
Off
SSO only
Sign-up
Invitations only
nobody walks in
Hosting
Managed by us
nothing to install
AI
On or off
your choice
Sign-in, database and AI are set in one place.

01For organizations

What you control

Chronika records screens that show your internal systems. These are the controls an organization needs over who gets in and where the data lives.

  • 01

    Single sign-on

    Sign in with Microsoft Entra ID, Google or any OIDC provider such as Keycloak, Okta, Auth0 or ADFS. Each switches on when its settings are present. You can turn passwords off and make SSO the only way in.

  • 02

    Invitation-only sign-up

    Set AUTH_OPEN_SIGNUP=false and nobody can create an account by themselves. People join through an invitation link: bound to one email address and used once, or open to anyone who has it until you revoke it or it expires.

  • 03

    Roles that match the work

    Owner, admin, editor and viewer. Editors record and edit. Admins manage members and invitations. Viewers read.

  • 04

    Team workspaces and collections

    A team workspace is shared by its members. Guides are filed into collections, and a guide no one has filed stays unfiled instead of lost.

  • 05

    We run it for you

    Chronika is a managed service. We host and maintain it, so there is nothing to install on a server, only the recorders on your colleagues’ computers.

  • 06

    Your choice of AI

    Anthropic, an OpenAI-compatible service, Google or Ollama on your own hardware, among others. Or none: guides still get sensible titles and step text that people edit by hand.

  • 07

    Recorders on a short leash

    The extension and the Windows app connect with a personal token that is shown once and stored only as a SHA-256 hash. A recorder can do what its owner can do, and each can be disconnected from the Recorder page.

  • 08

    Trash before deletion

    A deleted guide goes to Trash first. It is gone for good only when someone removes it from Trash.

  • 09

    Passwords blurred, not kept

    Password fields are blurred in the screenshot before upload, and what is typed into them is not recorded. A picture that cannot be made safe is left out.

02Roles

Four roles, one rule

Access is one membership per workspace. Each role includes everything the role below it can do.

What each workspace role can do
RoleCan
ViewerRead the workspace’s guides.
EditorRecord guides, edit them, and share them with a public link.
AdminManage members and invitations.
OwnerEverything an admin can do. The owner’s role cannot be changed by anyone else.

03Adoption

How a roll-out goes

We set it up with you, and you decide what is on.

  1. Agree the setup

    Tell us which sign-in you use and who may invite people. We set up the workspace to match.

  2. Set sign-in and AI

    Connect your identity provider. Turn off passwords and open sign-up if you want SSO and invitations only. Choose an AI provider, or leave AI off.

  3. Invite people

    Owners and admins create team workspaces and send invitation links. Roles decide who records, who edits and who reads.

  4. Roll out the recorders

    Each person downloads the extension or the Windows app from their account and connects it with one click. The recorders then record as that person.

04Questions

For IT and security

Can we turn off passwords and use SSO only?
Yes. On an Enterprise setup, passwords can be switched off so people sign in only through your identity provider. You also decide whether someone who signs in with SSO for the first time gets an account automatically.
Where does our data live?
Your guides, screenshots and narration are stored by Chronika for your workspace, and they are visible only to its members and to anyone you share a link with.
Does a recording leave our network?
The recorders send steps only to your Chronika server. If you set an AI provider, the server sends it what it needs to write the guide up. With AI set to none, or a provider you run yourself, such as Ollama, that does not leave your infrastructure.
Do you hold SOC 2, ISO 27001 or HIPAA certification?
No. We do not hold any of them and we do not claim to. The security page lists what Chronika does, and what it does not claim.
Is the Windows app code-signed?
Not yet. Some endpoint tools are wary of any program that watches the mouse and keyboard, so plan to allow-list the file with your IT team.
Windows app: not code-signed yet. Allow-list it with your IT team.

Ready when you are

Talk to us

Tell us how you sign in, where you would run it and who would record. We will tell you what fits.