Skip to content
SkillPod

A governed place for sensitive work

SkillPod is Skillancer’s governed work environment for sensitive work. Work runs in a client-specific space on the executive’s own, enrolled desktop computer, under the rules your policy sets — what can be copied, moved, printed or captured. The desktop web app is where sessions start; the signed Skillancer Workspace app enforces the rules locally. It is not a remote desktop and it is not available on phones.

What the client controls, per policy version

It is not a remote desktop, and it is not available on phones. A mandate that requires SkillPod can be summarised on mobile, but the work itself only happens on a supported desktop.

Honest boundary. Local controls reduce leakage and enforce your policy for normal use. They can’t stop every privileged or physical attacker. Evidence below shows what was actually enforced and when.
  • Clipboard and file movement
    Direction of copy, upload and download, printing
    Per policy
  • Screen capture and watermark
    Capture detection, on-screen watermark
    Per OS capability
  • Storage
    OS-encrypted work volume required, or vault fallback
    Per policy
  • Applications and domains
    Allowlists for the governed workspace
    Per policy
  • Session limits
    Idle timeout, maximum duration, geo and time rules
    Per policy
  • Egress and evidence
    Fixed-egress gateway where allocated; activity summaries only when the mandate enables them
    When configured

How a session works

Versions are checked when you sign in: if a policy requires a newer app than you have, launch is blocked until you update — the app does not update itself silently.

  1. Stage 1: Check this computer

    Before you commit, here is whether this computer can run SkillPod. Nothing is installed or changed by this check.

  2. Stage 2: Install the Skillancer Workspace app

    The signed desktop app enforces the client’s policy on this computer — encrypted work volume, clipboard and capture rules, the visible secure border. The web app only starts and monitors sessions.

  3. Stage 3: Enroll this device

    A one-time code pairs this computer with your account. It is shown once, expires in 15 minutes, and the app exchanges it for a device credential stored in the OS keychain. Nothing about a client is sent yet.

  4. Stage 4: Device check

    Advisory items don’t block launch but are recorded with the session evidence.

  5. Stage 5: Acknowledge the policy

    This exact version is pinned to every session you launch; if a new version is published you will be asked to acknowledge it again.

  6. Stage 6: Ready to launch

    Every condition below was evaluated by the server. Launch opens the Skillancer Workspace app; this page becomes your session control.

  7. Stage 7: Session active

    The governed workspace is open in the Skillancer Workspace app with the secure border visible. This page shows what is enforced right now and when it was last confirmed.

  8. Stage 8: Session ended

    The device acknowledged the close.

Desktop compatibility

Before you commit, here is whether this computer can run SkillPod. Nothing is installed or changed by this check.

Minimum Skillancer Workspace app version: 0.1.0. Support words come from the capability registry; a control marked “Detect only” is recorded, not blocked.

  • macOS
    Minimum 13
  • Windows
    Minimum 11 (10 2004 or later for capture defence)
  • Linux
    Minimum — · not shipped
  • Copy out of the workspace
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Not supported
    Since app
    0.1.0
  • Copy into the workspace
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Not supported
    Since app
    0.1.0
  • Downloads
    macOS
    Detect only
    Windows
    Detect only
    Linux
    Not supported
    Since app
    0.1.0
  • Uploads
    macOS
    Detect only
    Windows
    Detect only
    Linux
    Not supported
    Since app
    0.1.0
  • Printing
    macOS
    Not supported
    Windows
    Not supported
    Linux
    Not supported
    Since app
    0.1.0
  • Screen capture of the workspace
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Not supported
    Since app
    0.1.0
  • Screen recording detection
    macOS
    Detect only
    Windows
    Detect only
    Linux
    Not supported
    Since app
    0.1.0
  • Watermark
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Not supported
    Since app
    0.1.0
  • Secure border
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Not supported
    Since app
    0.1.0
  • OS-encrypted work volume
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Not supported
    Since app
    0.1.0
  • Encrypted file vault
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Enforced
    Since app
    0.1.0
  • Idle timeout
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Enforced
    Since app
    0.1.0
  • Maximum session length
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Enforced
    Since app
    0.1.0
  • Fixed egress (gateway)
    macOS
    When allocated
    Windows
    When allocated
    Linux
    Not supported
    Since app
    0.1.0
  • Activity summary
    macOS
    Detect only
    Windows
    Detect only
    Linux
    Not supported
    Since app
    0.1.0
  • Application and domain allowlist
    macOS
    When allocated
    Windows
    When allocated
    Linux
    Not supported
    Since app
    0.1.0
  • USB and removable media
    macOS
    Not supported
    Windows
    Not supported
    Linux
    Not supported
    Since app
    0.1.0
  • Disk encryption check
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Enforced
    Since app
    0.1.0
  • Screen lock check
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Enforced
    Since app
    0.1.0
  • Firewall check
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Enforced
    Since app
    0.1.0
  • Antivirus check
    macOS
    Not supported
    Windows
    Enforced
    Linux
    Not supported
    Since app
    0.1.0
  • Root / SIP check
    macOS
    Enforced
    Windows
    Not supported
    Linux
    Enforced
    Since app
    0.1.0
  • Signed app attestation
    macOS
    Enforced
    Windows
    Enforced
    Linux
    Detect only
    Since app
    0.1.0
Security posture

Evidence, not assurances

Every enforced control is shown with the time it was last confirmed, the device it ran on and the policy version in force. Versions are pinned: a session runs the exact policy the executive acknowledged.

On mobile this mandate shows a privacy-safe status and a “Continue on desktop” handoff. The work itself only happens here, on an enrolled desktop.

  • Policy versions are immutable

    Published versions carry a canonical rules hash; a change is a new version that must be acknowledged again.

  • Enrolled desktops only

    A one-time code pairs the computer with the account; the credential lives in the OS keychain.

  • Device check before launch

    Blocking posture failures stop the launch; advisory items are recorded with the session evidence.

  • Separate client boundaries

    Switching client switches the boundary visibly; nothing from another client is loaded inside it.

Set the requirement in the brief

  • Not required

    Standard workroom. Files and messages stay in Skillancer; no device rules.

  • Recommended

    The executive may choose SkillPod. You’ll see whether they did.

  • Required

    Every working session runs in SkillPod on an enrolled desktop. Nothing about the work can be done on a phone.

We use cookies to keep Skillancer secure, measure usage, and (if you allow) send you product updates. Read our privacy policy.