A governed place for sensitive work
SkillPod is Skillancer’s governed work environment for sensitive work. Work runs in a client-specific space on the executive’s own, enrolled desktop computer, under the rules your policy sets — what can be copied, moved, printed or captured. The desktop web app is where sessions start; the signed Skillancer Workspace app enforces the rules locally. It is not a remote desktop and it is not available on phones.
What the client controls, per policy version
It is not a remote desktop, and it is not available on phones. A mandate that requires SkillPod can be summarised on mobile, but the work itself only happens on a supported desktop.
- Per policyClipboard and file movementDirection of copy, upload and download, printing
- Per OS capabilityScreen capture and watermarkCapture detection, on-screen watermark
- Per policyStorageOS-encrypted work volume required, or vault fallback
- Per policyApplications and domainsAllowlists for the governed workspace
- Per policySession limitsIdle timeout, maximum duration, geo and time rules
- When configuredEgress and evidenceFixed-egress gateway where allocated; activity summaries only when the mandate enables them
How a session works
Versions are checked when you sign in: if a policy requires a newer app than you have, launch is blocked until you update — the app does not update itself silently.
- Stage 1: Check this computer
Before you commit, here is whether this computer can run SkillPod. Nothing is installed or changed by this check.
- Stage 2: Install the Skillancer Workspace app
The signed desktop app enforces the client’s policy on this computer — encrypted work volume, clipboard and capture rules, the visible secure border. The web app only starts and monitors sessions.
- Stage 3: Enroll this device
A one-time code pairs this computer with your account. It is shown once, expires in 15 minutes, and the app exchanges it for a device credential stored in the OS keychain. Nothing about a client is sent yet.
- Stage 4: Device check
Advisory items don’t block launch but are recorded with the session evidence.
- Stage 5: Acknowledge the policy
This exact version is pinned to every session you launch; if a new version is published you will be asked to acknowledge it again.
- Stage 6: Ready to launch
Every condition below was evaluated by the server. Launch opens the Skillancer Workspace app; this page becomes your session control.
- Stage 7: Session active
The governed workspace is open in the Skillancer Workspace app with the secure border visible. This page shows what is enforced right now and when it was last confirmed.
- Stage 8: Session ended
The device acknowledged the close.
Desktop compatibility
Before you commit, here is whether this computer can run SkillPod. Nothing is installed or changed by this check.
Minimum Skillancer Workspace app version: 0.1.0. Support words come from the capability registry; a control marked “Detect only” is recorded, not blocked.
- macOSMinimum 13
- WindowsMinimum 11 (10 2004 or later for capture defence)
- LinuxMinimum — · not shipped
| Control | macOS 13 | Windows 11 (10 2004 or later for capture defence) | Linux — · not shipped | Since app |
|---|---|---|---|---|
| Copy out of the workspace | Enforced | Enforced | Not supported | 0.1.0 |
| Copy into the workspace | Enforced | Enforced | Not supported | 0.1.0 |
| Downloads | Detect only | Detect only | Not supported | 0.1.0 |
| Uploads | Detect only | Detect only | Not supported | 0.1.0 |
| Printing | Not supported | Not supported | Not supported | 0.1.0 |
| Screen capture of the workspace | Enforced | Enforced | Not supported | 0.1.0 |
| Screen recording detection | Detect only | Detect only | Not supported | 0.1.0 |
| Watermark | Enforced | Enforced | Not supported | 0.1.0 |
| Secure border | Enforced | Enforced | Not supported | 0.1.0 |
| OS-encrypted work volume | Enforced | Enforced | Not supported | 0.1.0 |
| Encrypted file vault | Enforced | Enforced | Enforced | 0.1.0 |
| Idle timeout | Enforced | Enforced | Enforced | 0.1.0 |
| Maximum session length | Enforced | Enforced | Enforced | 0.1.0 |
| Fixed egress (gateway) | When allocated | When allocated | Not supported | 0.1.0 |
| Activity summary | Detect only | Detect only | Not supported | 0.1.0 |
| Application and domain allowlist | When allocated | When allocated | Not supported | 0.1.0 |
| USB and removable media | Not supported | Not supported | Not supported | 0.1.0 |
| Disk encryption check | Enforced | Enforced | Enforced | 0.1.0 |
| Screen lock check | Enforced | Enforced | Enforced | 0.1.0 |
| Firewall check | Enforced | Enforced | Enforced | 0.1.0 |
| Antivirus check | Not supported | Enforced | Not supported | 0.1.0 |
| Root / SIP check | Enforced | Not supported | Enforced | 0.1.0 |
| Signed app attestation | Enforced | Enforced | Detect only | 0.1.0 |
- Copy out of the workspace
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Not supported
- Since app
- 0.1.0
- Copy into the workspace
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Not supported
- Since app
- 0.1.0
- Downloads
- macOS
- Detect only
- Windows
- Detect only
- Linux
- Not supported
- Since app
- 0.1.0
- Uploads
- macOS
- Detect only
- Windows
- Detect only
- Linux
- Not supported
- Since app
- 0.1.0
- Printing
- macOS
- Not supported
- Windows
- Not supported
- Linux
- Not supported
- Since app
- 0.1.0
- Screen capture of the workspace
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Not supported
- Since app
- 0.1.0
- Screen recording detection
- macOS
- Detect only
- Windows
- Detect only
- Linux
- Not supported
- Since app
- 0.1.0
- Watermark
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Not supported
- Since app
- 0.1.0
- Secure border
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Not supported
- Since app
- 0.1.0
- OS-encrypted work volume
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Not supported
- Since app
- 0.1.0
- Encrypted file vault
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Enforced
- Since app
- 0.1.0
- Idle timeout
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Enforced
- Since app
- 0.1.0
- Maximum session length
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Enforced
- Since app
- 0.1.0
- Fixed egress (gateway)
- macOS
- When allocated
- Windows
- When allocated
- Linux
- Not supported
- Since app
- 0.1.0
- Activity summary
- macOS
- Detect only
- Windows
- Detect only
- Linux
- Not supported
- Since app
- 0.1.0
- Application and domain allowlist
- macOS
- When allocated
- Windows
- When allocated
- Linux
- Not supported
- Since app
- 0.1.0
- USB and removable media
- macOS
- Not supported
- Windows
- Not supported
- Linux
- Not supported
- Since app
- 0.1.0
- Disk encryption check
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Enforced
- Since app
- 0.1.0
- Screen lock check
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Enforced
- Since app
- 0.1.0
- Firewall check
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Enforced
- Since app
- 0.1.0
- Antivirus check
- macOS
- Not supported
- Windows
- Enforced
- Linux
- Not supported
- Since app
- 0.1.0
- Root / SIP check
- macOS
- Enforced
- Windows
- Not supported
- Linux
- Enforced
- Since app
- 0.1.0
- Signed app attestation
- macOS
- Enforced
- Windows
- Enforced
- Linux
- Detect only
- Since app
- 0.1.0
Evidence, not assurances
Every enforced control is shown with the time it was last confirmed, the device it ran on and the policy version in force. Versions are pinned: a session runs the exact policy the executive acknowledged.
On mobile this mandate shows a privacy-safe status and a “Continue on desktop” handoff. The work itself only happens here, on an enrolled desktop.
- Policy versions are immutable
Published versions carry a canonical rules hash; a change is a new version that must be acknowledged again.
- Enrolled desktops only
A one-time code pairs the computer with the account; the credential lives in the OS keychain.
- Device check before launch
Blocking posture failures stop the launch; advisory items are recorded with the session evidence.
- Separate client boundaries
Switching client switches the boundary visibly; nothing from another client is loaded inside it.
Set the requirement in the brief
- Not required
Standard workroom. Files and messages stay in Skillancer; no device rules.
- Recommended
The executive may choose SkillPod. You’ll see whether they did.
- Required
Every working session runs in SkillPod on an enrolled desktop. Nothing about the work can be done on a phone.

