Skip to main content
WAIMAKERS
About UsCareersContact
|
Schedule Free Call
Tools working on your laptop

AI Tooling & Setup Guide

Get every AI tool you use working on your own laptop, from browser access to IT approval

Before you start

Copy link to Before you start

Use this guide to set up only the AI tools you actually use, including the accounts, installations and approvals each one needs. The biggest gains come when AI can reach your real documents and mail, which is exactly where corporate laptops and tenant policy often get stuck, so involve IT early and test on the managed device you will use.

Tools

Copy link to Tools

Filter by setup type or search for a tool by name. Open any tool for what you need, the exact install path, the important nuances, and what to do if it will not work.

15 tools

ToolStatusSetupOpen details

ChatGPT

Compare models, research a topic and practise prompting in the browser.

AvailableBrowser onlyOpen details

ChatGPT Desktop

Use ChatGPT and Codex with approved local folders from a desktop app.

AvailableInstall neededOpen details

Claude

Prompt, analyse documents and complete important knowledge-work tasks.

AvailableBrowser onlyOpen details

Claude Desktop

Give Claude access to approved local files for hands-on agentic work.

AvailableInstall neededOpen details

Claude Cowork

Hand Claude a goal and let it work through your files while you steer.

AvailableInstall neededOpen details

Claude Code

Run a terminal-based agent that can build and change files step by step.

AvailableInstall neededOpen details

Claude in Chrome

Read a live web page, fill forms and work across browser tabs with review.

BetaInstall neededOpen details

Claude for Word

Draft and revise text inside the document you already have open.

BetaIT involvement likelyOpen details

Claude for Excel

Analyse and edit the workbook that is open in front of you.

AvailableIT involvement likelyOpen details

Claude for PowerPoint

Build, restyle and refine slides inside the current presentation.

AvailableIT involvement likelyOpen details

Claude for Outlook

Summarise the open thread and prepare an unsent draft for your review.

BetaIT involvement likelyOpen details

Microsoft Copilot

Bring the work AI account you already have and compare it using uploaded material.

Included with Microsoft 365Browser onlyOpen details

Wispr Flow

Turn speech into text across desktop apps using your own shortcut.

AvailableInstall neededOpen details

Weavy, now Figma Weave

Build visual generation workflows in the browser with model-by-model controls.

AvailableBrowser onlyOpen details

Lovable

Turn a prompt into a working prototype in a managed browser workspace.

AvailableBrowser onlyOpen details

ChatGPT

Compare models, research a topic and practise prompting in the browser.

AvailableBrowser only

What you need

  • Use a paid ChatGPT account. Use your company's managed workspace when one is available, especially if you need to share custom GPTs privately with colleagues. Check the official ChatGPT pricing page for current plans.

How to install

  1. Open chatgpt.com in a current browser.
  2. Sign in with the approved account you will use for work.
  3. Upload a harmless test document and confirm you can start a chat.
  4. Open Settings > Apps and confirm that only services approved by your organisation are connected.

Nuances

  • Need local folders or Computer Use? See ChatGPT Desktop, the installed surface in this guide.
  • Building and editing a custom GPT is web-only. A paid plan can create one, while private sharing with colleagues requires a managed Business or Enterprise workspace.
  • A ChatGPT subscription does not include API access. The API is a separate service and is not needed for browser-based use.
  • Use your approved work account and your organisation's data rules. Prefer synthetic or anonymised material where possible.

If it will not work

  • If sign-in or uploads are blocked, ask IT whether ChatGPT is disabled or filtered on the corporate network.
  • If Settings > Apps is missing or disabled, ask the ChatGPT workspace owner whether Apps are allowed for your role.
  • If it is still blocked, ask IT to test the same action on your managed device.

ChatGPT Desktop

Use ChatGPT and Codex with approved local folders from a desktop app.

AvailableInstall needed

What you need

  • Use a ChatGPT account. The app works with Free, Go, Plus, Pro, Business, Enterprise and Edu. Check the official ChatGPT pricing page for current plan details.

How to install

  1. Go to the Download ChatGPT page.
  2. On macOS, choose Download for macOS (Apple Silicon), or use the arrow for another build, then open the disk image and drag the app into Applications. On Windows, run the Microsoft web installer offered on the page and let it finish; you do not need to open Microsoft Store yourself.
  3. Open the app and sign in with your ChatGPT account.
  4. Choose where to work: start a chat, create a project or open a folder. The app can read and change files in the folder you select.
  5. Send a first message. Use the ChatGPT / Codex selector and the Chat / Work toggle above the composer.

Nuances

  • Prefer the browser? See ChatGPT in this guide. Since 9 July 2026, Codex is part of the ChatGPT desktop app on macOS and Windows, so there is no separate Codex desktop app. The Codex CLI, IDE extension and cloud service still exist separately.
  • Codex runs natively on Windows through PowerShell and the Windows sandbox. WSL2 is optional, not required.
  • The macOS installer is still named Codex.dmg and a compatibility bundle remains at /Applications/Codex.app. Intel Macs are supported, but Intel users must choose their build from the download dropdown.
  • There is no Linux desktop app. Linux users can use the Codex CLI.
  • Computer Use on macOS needs System Settings > Privacy & Security > Screen Recording and Accessibility for Codex Computer Use. On Windows it controls the pointer on the active desktop.
  • For users in the EEA, the UK and Switzerland, memories are off by default.

If it will not work

  • If a feature works in the Codex CLI but not in the app, compare codex --version with /Applications/Codex.app/Contents/Resources/codex --version; the two surfaces can bundle different Codex versions.
  • If macOS keeps asking for folder access, approve access to Music, Downloads or Desktop, or choose a narrower folder.
  • If a chat looks stuck, check whether it is waiting for an approval, then start a new chat with a smaller prompt.
  • If Computer Use cannot see or control an app, check Screen Recording and Accessibility for Codex Computer Use. On Windows, make sure the target app is visible on the active desktop.
  • If it is still blocked, tell us before the session, not on the day.

Claude

Prompt, analyse documents and complete important knowledge-work tasks.

AvailableBrowser only

What you need

  • Use a paid Claude account or an approved company workspace. Check the official Claude pricing page for current plans.

How to install

  1. Open claude.ai in a current browser.
  2. Sign in with the approved account you will use for work.
  3. On a personal account, open Privacy Settings > Model Improvement and confirm the setting matches your organisation's data policy.
  4. Upload a harmless test document. If you need a connector, open Settings > Connectors and connect only an approved service.

Nuances

  • On personal plans, conversation and coding data is not used for model improvement by default. It is used only if you explicitly enable Privacy Settings > Model Improvement, or if content is flagged for safety review.
  • On Team and Enterprise, Anthropic's Commercial Terms contractually exclude customer content from model training.
  • Incognito chats are never used for model improvement. They are still subject to your organisation's data policy.

If it will not work

  • If a feature is missing, check whether you are in the intended account and workspace before changing anything.
  • If a connector shows Request instead of Connect, a Team or Enterprise Owner must approve it under Admin settings > Connectors > Requested by your team.
  • If it is still blocked, ask the workspace owner to check the organisation policy.

Claude Desktop

Give Claude access to approved local files for hands-on agentic work.

AvailableInstall needed

What you need

  • Use the same paid Claude account as in the browser. Start from the official Claude download page and use the installer offered for your operating system.

How to install

  1. Go to claude.com/download and choose the current macOS or Windows download.
  2. Install the app and sign in with the same approved Claude account you use in the browser.
  3. Open a harmless local file from a folder you deliberately grant access to and confirm the app can use it.
  4. Check for app updates before relying on Desktop for local work.

Nuances

  • Desktop is the full route when a task needs local files, browser use or computer access. Keep an active internet connection while working.
  • On managed Windows, IT should support deployment of the MSIX. A standard user can install it, but full feature support, including Cowork, requires administrator-supported deployment.
  • For local server configuration, always open the file through Settings > Developer > Edit Config instead of browsing to a guessed %APPDATA% path.
  • Grant access only to the folders needed for the task, not an entire drive.

If it will not work

  • If the MSIX install is blocked, send the IT section of this guide to your endpoint administrator.
  • If the app opens but Cowork is missing on Windows, the standard-user installation has reached its feature ceiling; IT must support the deployment.
  • If Cowork will not start, check pending Windows updates and features with IT.

Claude Cowork

Hand Claude a goal and let it work through your files while you steer.

AvailableInstall needed

What you need

  • Use a paid Claude plan (Pro, Max, Team or Enterprise; Cowork is not on the free plan) and install Claude Desktop first. Cowork runs inside that app.

How to install

  1. Install Claude Desktop and sign in, as described in the Claude Desktop card.
  2. Open Cowork from Claude Desktop.
  3. Select a short local folder that you deliberately grant access to.
  4. Give it a small harmless task and watch the full run before using it on important work.

Nuances

  • Cowork is where you describe an outcome and step away, rather than chatting turn by turn. Keep an active internet connection while it works.
  • On managed Windows, full Cowork support needs the Claude Desktop app deployed with administrator support. A standard-user install may leave Cowork unavailable.
  • Versions on the web and on mobile are still in beta and roll out gradually. Desktop remains the full route for local files, browser use and computer access.
  • Connectors are called from Anthropic's cloud rather than from your laptop, so systems that are only reachable inside your network will not work.
  • Cowork activity is not included in enterprise audit logs or the Compliance API. Worth telling your security contact before you point it at sensitive material.

If it will not work

  • If Cowork does not appear in the app, confirm the app is up to date and that IT deployed it with administrator support.
  • If Cowork will not start on Windows, check pending Windows updates and features with IT.
  • If a connected internal system cannot be reached, confirm that it has a secure public endpoint.

Claude Code

Run a terminal-based agent that can build and change files step by step.

AvailableInstall needed

What you need

  • Use a paid Claude account and a supported terminal. The native installer is self-contained. Follow the official Claude Code installation guide for current requirements.

How to install

  1. Windows: open a normal PowerShell window and run irm https://claude.ai/install.ps1 | iex.
  2. macOS: open Terminal and run curl -fsSL https://claude.ai/install.sh | bash.
  3. Close and reopen the terminal, then run claude --version and claude doctor.
  4. On Windows, start from a short local working folder such as C:\ai, outside Documents and OneDrive.

Nuances

  • Claude Code no longer needs Node or Git, and its native installer does not need administrator rights. Git for Windows is optional but useful; without it Claude Code uses PowerShell.
  • Native Windows is supported and WSL is not required. Sandboxing is not available on native Windows; use WSL 2 only when your IT policy or Linux toolchain requires it.
  • The Windows installer supports Windows 10 1809 or later, installs to %USERPROFILE%\.local\bin\claude.exe and does not need an elevated terminal.
  • On Windows, keep your working folder short and local, such as C:\ai, outside Documents and OneDrive. Keep CLAUDE_CONFIG_DIR local too.

If it will not work

  • If claude is not found, fully close and reopen the terminal before trying anything else.
  • If Git is installed but not detected, point CLAUDE_CODE_GIT_BASH_PATH at the Git Bash executable.
  • If Claude reports a write as successful but no file appears, move the project to a short local path and confirm Windows long paths are enabled.
  • If the installer is blocked by policy, ask IT to allow the user-space native installer.

Claude in Chrome

Read a live web page, fill forms and work across browser tabs with review.

BetaInstall needed

What you need

  • Use a paid Claude plan and Google Chrome. Check the official Claude pricing page for current plan details.

How to install

  1. Open the official Chrome Web Store listing called Claude and verify that the publisher is Anthropic.
  2. Click Add to Chrome, then pin the extension and sign in with your Claude account.
  3. Start with manual approvals and allow only the sites needed for the task.
  4. Open a harmless page and confirm the extension can read it before allowing actions.

Nuances

  • Edge is not supported, even though it is Chromium-based. If your company standardises on Edge, Chrome must be installed alongside it.
  • Team organisations enable Claude in Chrome by default. Enterprise organisations disable it by default until an admin enables it at Organization settings > Claude in Chrome.
  • IT can force-install the extension with Chrome policy ExtensionSettings or ExtensionInstallForcelist.
  • There is no Claude app for Microsoft Teams. Teams content is reached through the Microsoft 365 connector, subject to your existing permissions.

If it will not work

  • If the store or the extension is blocked, ask IT to allow it. They will need the extension ID fcoeoabgfenejglbffodgkkbkcdhcgfn, which is also in the IT page at the end of this guide.
  • If it opens but cannot act, check the site's permission and your organisation's Claude in Chrome setting.
  • If it is still blocked, ask IT to test the policy with your managed Chrome profile.

Claude for Word

Draft and revise text inside the document you already have open.

BetaIT involvement likely

What you need

  • Use a paid Claude plan and a Microsoft 365 subscription build of Word. Check the official Claude pricing page for current plan details.

How to install

  1. Start at claude.com/claude-for-microsoft-365 rather than searching the store for “Claude”.
  2. Follow the link on that page to the Microsoft Marketplace listing called Claude for Microsoft 365. One listing covers Word, Excel and PowerPoint.
  3. In Word, open Home or Insert > Add-ins, select the official add-in and sign in.
  4. Open a harmless document and confirm Claude can read the selected text.

Nuances

  • Word is in beta. Do not use it for final client work, counterparty sends, litigation filings or audit-critical documents without human review.
  • The add-in does not work on perpetual Office 2016 or 2019. It requires a Microsoft 365 subscription build.
  • Claude for Word is not supported on iPad.
  • Work across Microsoft 365 apps is on for personal paid plans and off by default for Team and Enterprise until an owner enables Organization settings > Office agents > Let Claude work across apps.

If it will not work

  • If the add-in is missing, IT should deploy asset WA200010725 or use the verified Word manifest in the IT section.
  • Allow 24 to 72 hours after admin deployment for it to appear on the ribbon.
  • If the add-in appears but its pane stays blank, ask IT to allow pivot.claude.ai.

Claude for Excel

Analyse and edit the workbook that is open in front of you.

AvailableIT involvement likely

What you need

  • Use a paid Claude plan and a Microsoft 365 subscription build of Excel. Check the official Claude pricing page for current plan details.

How to install

  1. Start at claude.com/claude-for-microsoft-365 rather than searching the store for “Claude”.
  2. Follow the link on that page to the Microsoft Marketplace listing called Claude for Microsoft 365. One listing covers Word, Excel and PowerPoint.
  3. In Excel, open Home or Insert > Add-ins, select the official add-in and sign in.
  4. Open a harmless workbook and confirm Claude can read a selected range.

Nuances

  • Excel is the dependable spreadsheet add-in and also works on iPad. Review formulas, citations and changed cells before you rely on the result.
  • The add-in does not work on perpetual Office 2016 or 2019. It requires a Microsoft 365 subscription build.
  • The Office add-ins do not inherit an organisation's custom retention setting, and their activity is absent from Enterprise audit logs, the Compliance API and data exports.
  • Work across Microsoft 365 apps is on for personal paid plans and off by default for Team and Enterprise until an owner enables Organization settings > Office agents > Let Claude work across apps.

If it will not work

  • If the add-in is missing, IT should deploy asset WA200010725 or use the verified Excel manifest in the IT section.
  • Allow 24 to 72 hours after admin deployment for it to appear on the ribbon.
  • If the add-in appears but its pane stays blank, ask IT to allow pivot.claude.ai.

Claude for PowerPoint

Build, restyle and refine slides inside the current presentation.

AvailableIT involvement likely

What you need

  • Use a paid Claude plan and a Microsoft 365 subscription build of PowerPoint. Check the official Claude pricing page for current plan details.

How to install

  1. Start at claude.com/claude-for-microsoft-365 rather than searching the store for “Claude”.
  2. Follow the link on that page to the Microsoft Marketplace listing called Claude for Microsoft 365. One listing covers Word, Excel and PowerPoint.
  3. In PowerPoint, open Home or Insert > Add-ins, select the official add-in and sign in.
  4. Open a harmless deck and confirm Claude can read the current slide.

Nuances

  • PowerPoint is the dependable presentation add-in. Review facts, structure and visual consistency before sharing a deck.
  • The add-in does not work on perpetual Office 2016 or 2019. It requires a Microsoft 365 subscription build and is not supported on iPad.
  • Work across Microsoft 365 apps can read context in one supported Office app and use it in another. It is off by default for Team and Enterprise until an owner enables Organization settings > Office agents > Let Claude work across apps.
  • The Office add-ins do not inherit an organisation's custom retention setting, and their activity is absent from Enterprise audit logs, the Compliance API and data exports.

If it will not work

  • If the add-in is missing, IT should deploy asset WA200010725 or use the verified PowerPoint manifest in the IT section.
  • Allow 24 to 72 hours after admin deployment for it to appear on the ribbon.
  • If the add-in appears but its pane stays blank, ask IT to allow pivot.claude.ai.

Claude for Outlook

Summarise the open thread and prepare an unsent draft for your review.

BetaIT involvement likely

What you need

  • Use a paid Claude plan, Outlook and an Exchange Online mailbox. Check the official Claude pricing page for current plan details.

How to install

  1. Start at claude.com/claude-for-microsoft-365 rather than searching the store for “Claude”.
  2. Follow the link on that page to the separate listing called Claude for Outlook.
  3. Open Outlook, add the listing, sign in and open a harmless test message.
  4. Ask Claude to summarise the open message and confirm the reply remains an unsent draft.

Nuances

  • Outlook is in beta. Do not use it for final client work, counterparty sends, litigation filings or audit-critical documents without human review.
  • Claude never sends mail or invitations on its own. Every draft remains unsent for your review.
  • The add-in is Exchange Online only. It is governed by Exchange add-in policies and AppsForOfficeEnabled, not by the Office Store toggle used for Word, Excel and PowerPoint.
  • The Office add-ins do not inherit an organisation's custom retention setting, and their activity is absent from Enterprise audit logs, the Compliance API and data exports.

If it will not work

  • If the listing is missing, IT should deploy asset WA200010724 or use the verified Outlook manifest in the IT section.
  • If sign-in or Graph access fails, ask a Global Administrator to confirm the one-time Outlook consent.
  • If the add-in appears but its pane stays blank, ask IT to allow pivot.claude.ai.

Microsoft Copilot

Bring the work AI account you already have and compare it using uploaded material.

Included with Microsoft 365Browser only

What you need

  • Use your eligible work Microsoft 365 account at m365copilot.com. See the official Microsoft plan page to check current licensing and capabilities.

How to install

  1. Open m365copilot.com in a browser and sign in with your work account.
  2. Read the in-product label: M365 Copilot (Premium) indicates the paid add-on; M365 Copilot (Basic) or Copilot Chat (Basic) indicates the basic work experience.
  3. Upload a harmless test file and confirm the chat can use it.
  4. Ask one question that requires the uploaded file and one that requires a web result.

Nuances

  • Copilot Chat is included with eligible Microsoft 365 subscriptions, but it is web-grounded only. It cannot read your own mail, SharePoint or OneDrive content without the broader Microsoft 365 Copilot capability.
  • Uploading or pasting a document works in the basic experience, so use that route when you need the chat to work with your own material.
  • Do not use the Windows taskbar route for a commercial work account. Use m365copilot.com. IT can disable Copilot or web search at tenant level.

If it will not work

  • If Copilot is missing, ask IT whether it is disabled under Integrated Apps for your tenant.
  • If it has no web results, ask whether optional connected experiences or web search have been disabled.
  • If it is still blocked, ask IT to test your account at m365copilot.com.

Wispr Flow

Turn speech into text across desktop apps using your own shortcut.

AvailableInstall needed

What you need

  • Use a Wispr Flow account and sign in with Google, Apple, Microsoft, SSO, or email and password. Plans include Flow Basic, Flow Pro with a team variant, and Flow Enterprise. Check the official Wispr Flow pricing page for current plan details.

How to install

  1. Go to wisprflow.ai/downloads and choose Mac with Apple Silicon, Mac with Intel, or Download for Windows.
  2. On macOS, open the download, drag Wispr Flow into Applications and launch it from the menu bar. On Windows, run the installer and launch Wispr Flow from the Start menu; its icon appears in the system tray.
  3. Click Sign in via browser, complete sign-in in the browser and return to the app. If the handoff times out, start it again.
  4. Grant permissions. On macOS, click Allow on the microphone card and macOS dialog, then Allow on the accessibility card. On Windows, allow microphone access if prompted.
  5. Finish the tutorial: test the microphone, press the keys you want for your shortcut, and choose your languages or keep auto-detect on. Setup is complete when the Flow Hub appears.

Nuances

  • On macOS, System Settings > Privacy & Security > Microphone and Accessibility must both allow Wispr Flow. Accessibility is what lets Flow insert speech into other apps.
  • Screen Recording is needed only for Notetaker on macOS 13 or earlier, not for normal dictation.
  • Supported devices run macOS 12 or later, or Windows 10 or 11 on x64. ARM Windows, Linux, iPad, virtual machines and remote desktop environments are not supported.
  • By default, dictation data may be used to evaluate, train and improve models. Settings > Data & Privacy > Privacy Mode turns that off. Private Cloud Sync separately controls whether transcripts are stored server-side.
  • Flow needs an internet connection and does not transcribe offline. All customer data is processed and stored in the United States, with GDPR covered through a DPA and EU Standard Contractual Clauses.

If it will not work

  • If dictation records but no text appears, recover it with Ctrl+Cmd+V on Mac or Shift+Alt+Z on Windows. On macOS, toggle Wispr Flow off and on under System Settings > Privacy & Security > Accessibility. Test in Notes to see whether the target app is blocking paste.
  • If the shortcut is dead in Terminal, iTerm2, a password field or Slack on Mac, leave the password field, uncheck Terminal > Secure Keyboard Entry or quit the offending app. Hold-to-talk usually still works.
  • If permissions stop working after an update, quit Flow from the menu bar, toggle each permission off and on, then reopen it.
  • Flow does not work inside Citrix, RDP or VDI. Install it on the local machine, never inside the remote session.
  • If it is still blocked, tell us before the session, not on the day.

Weavy, now Figma Weave

Build visual generation workflows in the browser with model-by-model controls.

AvailableBrowser only

What you need

  • Use a Google, Figma or Microsoft account. There is no email and password option. Plans include Free, Starter, Professional, Team and Enterprise. Figma Weave credits are separate from Figma credits, so a paid Figma seat does not include Figma Weave. Check the official Figma Weave pricing page for current plan details.

How to install

  1. Open weave.figma.com. The old weavy.ai address redirects there.
  2. Click Start Now, or Sign In in the top navigation.
  3. On app.weavy.ai/signin, complete Verify you are human. The sign-in buttons remain greyed out until it succeeds.
  4. Choose Log in with Google, Log in with Figma or Log in with Microsoft.

Nuances

  • The rebrand is still in progress. Marketing is at weave.figma.com, the application at app.weavy.ai and the help centre at help.weavy.ai, so expect to see both Weavy and Figma Weave.
  • Credits gate every action. Different models use different amounts, video uses more than images, and the free tier cannot buy top-ups, so credits can run out during a session.
  • For Verified models, the provider is contractually prohibited from training on your content. An Unverified model provider may have the right to train on it, so check the current model list.
  • The vendor says it does not train on your images or prompts, but anonymised usage data is used for training and Unverified model providers may train on your content. There is no opt-out toggle, and the main Figma product's content-training toggle does not apply to Figma Weave.
  • Commercial use is allowed on the free tier, but the vendor says most, not all, models are cleared for it. Check each model.
  • The terms say content should not include personal data and that Figma Weave is not a storage or backup service. Download anything you want to keep.

If it will not work

  • If the sign-in buttons stay greyed out, Verify you are human has not passed. A corporate VPN, shared egress address or browser that blocks third-party scripts can cause this quietly. Try another network or a clean browser profile.
  • If your employer blocks Google, personal Microsoft accounts or third-party sign-in consent, there is no email and password fallback. Confirm in advance that at least one of the three sign-in routes works.
  • If the help centre will not open, ask IT to test help.weavy.ai from the corporate network.
  • If nothing generates, check whether the account has run out of credits. The free tier cannot buy more before the monthly reset.
  • If it is still blocked, tell us before the session, not on the day.

Lovable

Turn a prompt into a working prototype in a managed browser workspace.

AvailableBrowser only

What you need

  • Use an existing Lovable workspace or arrange one through your organisation. Check the official Lovable pricing page for current plans and usage limits.

How to install

  1. Open lovable.dev in a current browser.
  2. Sign in and open the workspace approved by your organisation.
  3. Open an existing project or create a harmless test project.
  4. Enter a small prompt and confirm that the preview builds.

Nuances

  • Build credits are pooled per workspace and prompts consume different amounts. Check the workspace allowance before starting a substantial build.
  • Supabase is no longer required for setup; Lovable Cloud provides the built-in backend.
  • Published apps are public on Free and Pro. Put nothing real, confidential or personal into a published app.
  • Abandoned projects can be removed automatically, so keep working on or export anything you need to preserve where your plan permits it.

If it will not work

  • Lovable publishes no firewall allowlist. If the site is blocked, IT should test access from the corporate network.
  • If workspace access or build allowance is missing, contact the workspace owner rather than changing plans yourself.
  • If the editor opens but the preview does not build, ask IT to test lovable.dev and the generated preview domain.

This field moves fast

Copy link to This field moves fast

This guide is a dated snapshot. Product names, plan entitlements and install paths can change within weeks, so we review it regularly and keep the version date visible.

Set up only the tools you actually use. Start any account, endpoint or tenant approval early enough for IT to deploy and test it on your managed device.

If a step here does not match what you see on screen, paste that section into Claude and ask it to walk you through the current screen. Then tell us so we can update the guide.

One page for your IT team

Copy link to One page for your IT team

This section can be forwarded as-is to the people responsible for managed laptops, browser policy, network access and the Microsoft tenant.

Complete the applicable items below for the people who need these tools.

1

Network, proxy and TLS inspection

Can the managed device reach the domains below, which proxy type and URL are active, and is TLS inspection enabled?

  • Provide the corporate root CA as a .pem and make sure the operating system trusts it. For Claude Code, set NODE_EXTRA_CA_CERTS to that file if OS trust alone is insufficient.
  • If desktop or web surfaces open as a blank page rather than showing an error, check the Desktop/web domains below first.
  • Do not disable certificate validation. SOCKS and directly authenticated NTLM or Kerberos proxies are not supported.
  • Allow registry.npmjs.org only when npm or npx-based local servers are actually used.
2

ChatGPT Desktop on managed devices

Use the Microsoft Store distribution lane on Windows and set central policy before users work with local folders or Computer Use.

  • Install with winget install --id 9PLM9XGG6VKS -s msstore. The Microsoft Store product ID is 9PLM9XGG6VKS and the listing is ChatGPT from OpenAI. Use Intune, MECM or another MDM that supports Store apps.
  • Where Microsoft distribution cannot be used, deploy the Store-signed ChatGPT-x64.msix or ChatGPT-arm64.msix with ChatGPT-License.xml. There is no standalone MSI or non-Store EXE. If policy prohibits MSIX, there is no supported alternative.
  • Allow updates through persistent.oaistatic.com. OpenAI does not publish a full client allowlist, so ask OpenAI for the current list when deny-by-default policy needs more.
  • Deliver central policy as requirements.toml at /etc/codex/requirements.toml on macOS or %ProgramData%\OpenAI\Codex\requirements.toml on Windows. Constrain approvals, permission profiles, filesystem and network access, MCP servers and features. Disable Computer Use where needed with [features] computer_use = false. Cloud-delivered requirements override the local file.
  • Managed deployment on macOS is undocumented. A ChatGPT.pkg exists on the vendor CDN, but confirm the route with OpenAI before building a Jamf policy.
  • Symptom: the app is installed, but updates, Git-backed features, scripts or elevated commands do not work.
  • Check first: reachability of persistent.oaistatic.com and, on Windows, whether the command needs elevation, PowerShell execution policy is at least RemoteSigned, and Git is available when a Git-backed feature needs it.
  • Check next: collect app logs from ~/Library/Logs/com.openai.codex/YYYY/MM/DD and session transcripts from ~/.codex/sessions.
  • Escalate: type / in the composer, file feedback, record the session ID and send it with the logs to OpenAI. Ask OpenAI for the full client allowlist as well if network policy still blocks the app.
3

Wispr Flow on managed devices

Deploy the app centrally where needed, set organisation controls in advance and test dictation on one real managed device.

  • Allow wisprflow.ai and api.wisprflow.ai. On a strict deny-by-default firewall these may not be enough because dictation uses additional transcription endpoints. Ask Wispr support for the full list.
  • Use the enterprise MSI on Windows, which installs into Program Files. There is no public download URL and no published macOS PKG, Intune, Jamf or SCCM guidance, so ask Wispr for the package and deployment guidance.
  • Manage SSO, SCIM and organisation policy at admin.wisprflow.ai. The IT Admin role does not consume a billed seat. Admins can lock Privacy Mode, Private Cloud Sync and Context Awareness. Organisation-level zero data retention overrides other settings.
  • Symptom: dictation will not start, inserts no text or shows an organisation-restriction screen.
  • Check first: the device is not ARM Windows or a virtual machine, and Microphone and Accessibility have been toggled off and on before relaunching the app.
  • Check next: dictate into Notes or Notepad to separate a Flow problem from a target-app paste block, check for a hotkey conflict under Settings > General > Shortcuts and retry on an approved network when organisation access is restricted.
  • Escalate: ask Wispr support for the full transcription endpoint list when the test still fails on a supported local device.
4

Weavy, now Figma Weave in the browser

There is no vendor-published firewall allowlist. Treat the hosts below as observed, not as a complete vendor list.

  • The observed hosts are weave.figma.com, app.weavy.ai, content.weave.figma.com and help.weavy.ai. Also allow the human-verification endpoint and the identity provider in use.
  • Sign-in uses Google, Figma or Microsoft OAuth only. In Entra ID, confirm the app is not blocked by an admin consent policy. SAML, OIDC and SCIM are not documented.
  • A team administration console is available from the Team tier, with unified billing and a shared credit pool.
  • Symptom: Verify you are human fails quietly, the sign-in buttons remain greyed out or the help centre will not open.
  • Check first: the proxy is not intercepting the human-verification challenge on app.weavy.ai and the identity provider consent flow is allowed.
  • Check next: allow all four observed hosts, not only the marketing domain.
  • Escalate: contact the vendor. There is no status page to send users to.
5

Microsoft 365 bundle: Word, Excel and PowerPoint

Use Microsoft 365 admin center > Settings > Integrated apps. Search Claude and match publisher Claude by Anthropic for Office, or go directly to the asset below.

  • Deploy Claude for Microsoft 365, asset WA200010725, for Word, Excel and PowerPoint.
  • Global Administrator, Global Reader, AI Administrator and Exchange Administrator can deploy the add-ins. Do not use nested groups for assignment.
  • The add-ins require Microsoft 365 subscription builds and do not work on perpetual Office 2016 or 2019.
  • If Let users access the Office Store is disabled, an admin-deployed add-in may still fail to appear.
  • Allow 24 to 72 hours for ribbon propagation. Start the deployment at least one week before users need it and test one real account in all three apps.
6

Outlook: separate admin lane

Deploy Outlook separately from the Microsoft 365 bundle. It requires an Exchange Online mailbox and is not governed by the Office Store setting used for Word, Excel and PowerPoint.

  • Deploy Claude for Outlook, asset WA200010724. Confirm Exchange Online role assignment policies for My Custom Apps, My Marketplace Apps and My ReadWriteMailbox Apps, plus AppsForOfficeEnabled.
  • A Global Administrator must grant one-time Microsoft Graph admin consent for Entra client ID c2995f31-11e7-4882-b7a7-ef9def0a0266 using the admin consent URL.
  • The delegated scopes are Mail.ReadWrite, Calendars.Read, People.Read, User.Read and offline_access.
  • Allow the same 24 to 72 hours for ribbon propagation and test an unsent draft.
7

Manifest fallback

When Microsoft Marketplace is blocked, use Microsoft 365 admin center > Settings > Integrated apps > Upload custom apps > Office Add-in:

manifest-word.xml, manifest-excel.xml, manifest-powerpoint.xml, manifest-outlook.xml

Use this route as well for GCC, GCC High, DoD and 21Vianet tenants where Integrated Apps or Microsoft Marketplace is unavailable.

8

Claude in Chrome

  • Allow or force-install the Chrome Web Store listing Claude by publisher Anthropic, extension ID fcoeoabgfenejglbffodgkkbkcdhcgfn.
  • Team organisations enable Claude in Chrome by default. Enterprise organisations disable it by default until an admin enables Organization settings > Claude in Chrome.
  • For managed Chrome, use ExtensionSettings or ExtensionInstallForcelist. Edge is not supported, even though it is Chromium-based.
9

Microsoft 365 connector

A Microsoft Entra Global Administrator must complete one-time tenant consent before anyone can connect. In Team and Enterprise, a Claude Owner first enables Microsoft 365 under Organization settings > Connectors.

Add both service principals, grant tenant-wide admin consent to both and, when Assignment required is Yes, assign the same users or supported groups to both:

  • M365 MCP Server for Claude: 07c030f6-5743-41b7-ba00-0a6e85f37c17
  • M365 MCP Client for Claude: 08ad6f98-a4f8-4635-bb8d-f1a3044760f0
  • Test with one user by searching Outlook and SharePoint. If the test fails, check both enterprise-app assignments first.
  • Re-consent may be needed for newer write permissions. Access can be revoked in Entra at any time and revocation takes effect immediately.
10

Claude Desktop and Claude Code on managed Windows

  • Provision Claude Desktop machine-wide with Add-AppxProvisionedPackage -Online -PackagePath "Claude.msix" -SkipLicense. A standard user can install the MSIX, but full Windows feature support, including Cowork, needs administrator-supported deployment.
  • Do not deploy the MSIX as an Intune line-of-business app for standard users. Use a Win32 wrapper or PowerShell deployment, and permit packaged apps in AppLocker or WDAC.
  • Allow the Claude Code native installer in user space. It needs no elevated terminal, Node or Git; Git for Windows is optional.
  • Allow a short local folder outside OneDrive, such as C:\ai, and a local CLAUDE_CONFIG_DIR.
  • Test Desktop, Cowork and Claude Code end to end on one real managed Windows laptop before wider rollout.
11

Diagnose: blank page or certificate error

  • Symptom: a desktop or web surface stays blank without an error, or the client reports a certificate or TLS error.
  • Check first: compare every domain group below with the active firewall and proxy policy. Treat a blank page as a domains problem until proven otherwise, not as evidence of an outage.
  • Check next: confirm whether TLS inspection is active, whether the operating system trusts the corporate root CA and, for Claude Code, whether NODE_EXTRA_CA_CERTS points to the supplied .pem. Never disable certificate validation.
  • Escalate: ask OpenAI for the full ChatGPT client allowlist, Wispr support for the full transcription endpoint list, or the Figma Weave vendor for network support when the published or observed hosts are insufficient.
12

Diagnose: Office pane or tenant consent

  • Symptom: the Office add-in is installed but its pane stays empty, or Microsoft 365 tenant consent looks granted while the user still cannot connect.
  • Check first: for an empty add-in pane, allow pivot.claude.ai, claude.ai, api.anthropic.com and appsforoffice.microsoft.com. Also check the Office Store setting for Word, Excel and PowerPoint and the separate Exchange Online policies for Outlook.
  • Check next: for the connector, inspect both enterprise applications, tenant-wide admin consent for both and, when Assignment required is Yes, assignment of the same user or supported group to both. Re-consent when newer write permissions are missing.
  • Escalate: have a Microsoft 365 administrator test the add-in pane with one real account and a Microsoft Entra Global Administrator inspect both service principals and consent. Send the concrete result to Anthropic only after both admin layers are proven correct.
13

Diagnose: extension present but disabled

  • Symptom: Claude is present in Chrome but appears as disabled by organisation or cannot work on any page.
  • Check first: a Claude Owner has enabled Organization settings > Claude in Chrome for Enterprise, and the managed Chrome profile allows extension ID fcoeoabgfenejglbffodgkkbkcdhcgfn.
  • Check next: verify that ExtensionSettings or ExtensionInstallForcelist is applied to the active managed profile and that the required site permission is allowed. Test in Chrome, not Edge.
  • Escalate: have the Chrome endpoint administrator inspect effective browser policy and the Claude workspace owner inspect the organisation setting. Escalate to Anthropic only with both results.
14

Diagnose: Claude Desktop or Claude Code stays broken

  • Symptom: Claude Desktop opens without full features, Cowork will not start or Claude Code still fails after the standard installation.
  • Check first: Claude Desktop was provisioned machine-wide through MSIX, Windows updates are complete, and claude --version and claude doctor return a useful result.
  • Check next: move the work to a short local folder outside OneDrive, keep CLAUDE_CONFIG_DIR local and check the corporate root CA and NODE_EXTRA_CA_CERTS for TLS errors.
  • Escalate: record the product, version, managed-device configuration and exact error, then send them to Anthropic support and WAIMAKERS before the session.

Network allowlist

Domains to allow

Claude core

  • api.anthropic.com
  • claude.ai
  • claude.com
  • platform.claude.com
  • downloads.claude.ai
  • code.claude.com

Claude feature-specific

  • pivot.claude.ai
  • appsforoffice.microsoft.com
  • mcp-proxy.anthropic.com
  • bridge.claudeusercontent.com
  • storage.googleapis.com
  • raw.githubusercontent.com
  • registry.npmjs.org

Claude Desktop/web

  • anthropic.com
  • a-api.anthropic.com
  • a-cdn.anthropic.com
  • s-cdn.anthropic.com
  • assets-proxy.anthropic.com
  • a.claude.ai
  • a-cdn.claude.ai
  • assets.claude.ai
  • *.livepreview.claude.ai
  • *.livepreview.claude.app
  • *.claudeusercontent.com
  • *.claudemcpcontent.com

ChatGPT and Wispr Flow

  • chatgpt.com
  • persistent.oaistatic.com
  • wisprflow.ai
  • api.wisprflow.ai

Observed Figma Weave hosts

  • weave.figma.com
  • app.weavy.ai
  • content.weave.figma.com
  • help.weavy.ai

If you only read one line

Please test one real managed device end to end, deploy the required desktop apps and add-ins, allow the listed and observed hosts, keep the corporate root CA trusted, and ask the relevant vendor for every unpublished allowlist before the session.

Data and privacy in one minute

Copy link to Data and privacy in one minute

Training

Commercial Claude plans contractually exclude customer content from model training. On consumer Claude plans, Model Improvement is opt-in under Privacy Settings; Incognito chats are never used for model improvement.

Retention

Office add-ins

The four add-ins do not inherit custom organisation retention, and their activity is not in Enterprise audit logs, the Compliance API or data exports. Inputs and outputs are deleted within 30 days.

Residency

Location and transfer

Anthropic does not offer first-party EU data residency. International transfers are covered by EU Standard Contractual Clauses in Anthropic's DPA, which is incorporated into the Commercial Terms.

Connectors

Third-party connectors fall outside Anthropic's DPA. The connector vendor's terms and DPA govern the data sent to that service, so approve each connector separately.

Read the tool-by-tool position:WAIMAKERS GDPR Compliance Guide

Find the blocker early and involve IT before you need the tool.

Schedule Free Call
WAIMAKERS

Learn. Lead. Make.

AI Transformation Boutique · Amsterdam

Make work exciting, make businesses unstoppable.

Who We Help

View all roles & industriesCEOs & Board MembersPE & Investment ManagersCFOs & Finance LeadersInnovation DirectorsCTOs & IT LeadersCommercial Directors

What We Do

View all servicesOur ApproachLearnTailored Training ProgrammesAI Champions ProgrammeAgentic Way of WorkingE-learningLeadMake

Company

About UsResourcesContactCareersPodcast ↗

© 2026 WAIMAKERS. All rights reserved.

Privacy PolicyCookie Policy