> ## Documentation Index
> Fetch the complete documentation index at: https://docs.screenpipe.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Teams — share configs with end-to-end encryption

> Push scheduled task configurations and content filters to your team. Everything is encrypted client-side — the server only sees encrypted blobs.

Teams let admins push scheduled task configurations and recording filters to all members. Everything is end-to-end encrypted using AES-256-GCM — the Screenpipe server never sees your configs in plaintext.

## What you can share

<CardGroup cols={3}>
  <Card title="Scheduled tasks" icon="zap">
    Share scheduled AI agents (pipe.md configs) with your team so everyone runs the same automations
  </Card>

  <Card title="Window filters" icon="app-window">
    Push ignored/included window lists so the whole team has consistent privacy rules
  </Card>

  <Card title="URL filters" icon="globe">
    Share ignored URL patterns (e.g. Banking sites) to enforce org-wide recording policies
  </Card>

  <Card title="Managed AI presets" icon="sliders-horizontal">
    Publish approved model presets, lock the default, and control whether employees can add custom presets
  </Card>
</CardGroup>

## How security works

Teams use **AES-256-GCM** encryption. The encryption key is generated on the admin's device and never sent to our server. Members receive the key through the invite link (shared out-of-band via a secure channel like Slack DM or signal).

<Steps>
  <Step title="Admin creates a team">
    A 256-bit AES-GCM key is generated locally using the Web Crypto API. This key is stored in the Tauri secure store (`~/.screenpipe/store.bin`) — not in localStorage or anywhere web-accessible.
  </Step>

  <Step title="Admin shares invite link">
    The invite link contains the team ID and the base64-encoded encryption key: `screenpipe://join-team?team_id=...&key=...`. This is the only time the key is transmitted — via the link itself, not through our server.
  </Step>

  <Step title="Members join and store the key">
    When a member opens the invite link, the key is imported and stored in their local Tauri secure store. Our server only records the membership — it never sees the key.
  </Step>

  <Step title="Configs are encrypted before upload">
    When an admin pushes a scheduled task or filter config, it's encrypted locally with AES-256-GCM using a random 12-byte nonce. Only the encrypted blob and nonce are sent to the server.
  </Step>

  <Step title="Members decrypt locally">
    Team members download the encrypted configs and decrypt them on-device using the shared key. Decrypted configs are applied to local settings automatically.
  </Step>
</Steps>

## What the server stores vs what it can see

| Data | Stored on server | Readable by server |
| - | :-: | :-: |
| Team name & member list | Yes | Yes |
| Encrypted config blobs | Yes | **No** |
| Encryption nonces | Yes | Yes (but useless without key) |
| Encryption key | **No** | **No** |
| Decrypted scheduled task configs | **No** | **No** |
| Decrypted filter lists | **No** | **No** |
| Managed preset policy | Yes | Depends on policy metadata; model secrets stay local |

## Managed AI presets

Admins can standardize which AI models employees use for chat and scheduled tasks.

Common policies:

| Policy | When to use it |
| - | - |
| Locked default | Every employee should use the same approved model |
| Allowed custom presets | Power users can add providers while the team default stays managed |
| No custom presets | Regulated teams need approved models only |
| budget-aware presets | Expensive models are reserved for specific workflows |

Managed presets are especially useful when paired with [privacy data flow](/privacy-data-flow): document which models can receive screen context, which integrations are approved, and whether cloud media analysis is allowed.

## Getting started

### Create a team (admin)

1. Go to **settings > team**
2. Enter a team name and click **create team**
3. Copy the invite link and share it with your team via a secure channel

<Warning>
  The invite link contains your encryption key. Share it only through a secure channel (e.g. Signal, Slack DM, in-person). Anyone with this link can join and decrypt your team's configs.
</Warning>

### Join a team (member)

1. Open the invite link — Screenpipe will handle it automatically via deep link
2. Alternatively, go to **settings > team** and paste the invite link manually

### Push filters to team (admin)

1. Go to **settings > recording** and scroll to **filtering**
2. Set up your ignored windows, included windows, or ignored URLs
3. Click the **push to team** button on any filter card

Pushed filters appear under the **team** tab and are automatically synced to all members.

### Share a scheduled task to team (admin)

1. Go to **settings > scheduled tasks**
2. Click the **share** button next to any scheduled task
3. The scheduled task config (including its prompt and schedule) is encrypted and pushed to the team

<Info>
  If you update a scheduled task locally and share it again, the team copy is overwritten with your latest version. The model is last-push-wins — there's no merge.
</Info>

### How filters sync for members

When a member visits the team tab, shared filters are automatically merged into their local recording settings:

* **Team filters are additive** — they're combined with the member's own filters, not replaced
* **Team-sourced entries show a badge** in the recording settings so members know which filters come from the team
* **Members can't remove team filters** from their local settings while they're in the team — leaving the team clears them

## Roles

| Action | Admin | Member |
| - | :-: | :-: |
| create/delete team | Yes | No |
| Invite members | Yes | No |
| Remove members | Yes | No |
| Push configs (scheduled tasks, filters) | Yes | No |
| Delete shared configs | Yes | No |
| Receive shared configs | Yes | Yes |
| Leave team | Yes | Yes |

## Requirements

* Screenpipe account (sign in at **settings > team**)
* Screenpipe desktop app (teams use the Tauri secure store for key storage)

## Technical details

* **Encryption**: AES-256-GCM via the [Web Crypto API](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto)
* **Key storage**: Tauri plugin-store (`~/.screenpipe/store.bin`), not localStorage
* **Nonce**: 12-byte random per encryption operation (crypto.getRandomValues)
* **Config types**: `pipe`, `window_filter`, `url_filter` (extensible)
* **Sync**: automatic when the team tab loads; filter configs merge into local settings via the `useTeamSync` hook

<Card title="View source code" icon="code" href="https://github.com/screenpipe/screenpipe/tree/main/apps/screenpipe-app-tauri/lib/team-crypto.ts">
  Audit the AES-256-GCM encryption implementation
</Card>

## FAQ

**What happens if i lose the invite link?**
The admin can always copy it again from **settings > team**. The encryption key is stored locally on the admin's device.

**Can the Screenpipe team read my configs?**
No. The server only stores encrypted blobs. The encryption key is never transmitted to our server.

**What if two admins push the same scheduled task name?**
Last push wins. The newer version overwrites the older one. There's no merge or conflict resolution — the scheduled task is treated as a single document.

**What happens when i leave a team?**
All team-sourced filters are removed from your local settings. Your personal filters remain unchanged.

**Is the encryption key rotated?**
Not currently. If you suspect the key is compromised, delete the team and create a new one with a fresh key.

**What if a member receives a server-emailed invite without the key?**
Server emails cannot include the client-side encryption key. The admin must share the full invite link from the desktop app through a trusted channel.

Questions? [join our Discord](https://discord.gg/screenpipe).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.