The Settings panel
Settings is split into seven views, listed down the left of the panel.
The rest of this page covers the Settings view itself.
Identity — Your access
The first card reports the scope of your own access, for example “Covers the whole tenant · 232 endpoints.”This card is informational. It describes your intended scope — it is not a filter on the data shown elsewhere in the console.
Fleet — Endpoint Configuration
Agent settings pushed to every endpoint in the tenant. Changes apply on the next agent heartbeat, so you never need to touch individual machines.OTLP collector port
Set this if your endpoints already run a corporate OTel collector — Datadog, Alloy, Dynatrace — on 4318. The card shows a Last saved timestamp, and Discard / Save buttons. Changes are not pushed until you save.Additional fleet configuration is available with the AI Visibility feature. If your tenant doesn’t have it, the options above are the full set exposed in this card.
Integrations — Anthropic Compliance API key
Lets Origin pull your organization’sclaude.ai and Claude Desktop chats through Anthropic’s Compliance API, so they appear alongside proxy-captured prompts.
Paste a Compliance Access Key — it begins with sk-ant-api01- and is created in claude.ai under Compliance Access Keys. The key is stored encrypted and never shown again after saving. Once configured, the card reads Configured — connected and offers Remove and Replace key.
For the full setup walkthrough, including the Claude-side steps and the scopes Origin needs, see Claude Enterprise.
Integrations — Microsoft 365 Copilot capture
Pulls Microsoft 365 Copilot prompts and responses (Word, Excel, Outlook, Teams, Copilot Chat) into AI activity, attributed to each person. Copilot capture is enabled per connected Microsoft Entra ID directory — each appears as its own card — and needs no extra credentials beyond the directory integration’s admin consent. Each card carries a Capture Copilot activity toggle, a delivery mode, and a Readiness section with a Check readiness / Re-check button that makes live Microsoft API calls.Turning the toggle on is not sufficient on its own. Capture stays blocked until the Microsoft-side prerequisites pass, so run the readiness check after enabling.
Account — Change Password
Set a new password from the Current password, New password, and Confirm new password fields. New passwords must be at least 8 characters.This only applies to local password accounts. Users who sign in via SSO / WorkOS manage credentials at their identity provider.
Local storage — Clear local data
Wipes locally-cached data from the browser you’re using, without signing you out. This affects that browser only; server-side state is unchanged.Installers
The Installers view lists the agent packages available for download. It shows the three latest builds by default, with a Show all versions toggle and a search box.
Both an MSI and an EXE are published for Windows. The MSI is the right choice for MDM and software-distribution tooling; the EXE installs the Visual C++ redistributable automatically and suits ad-hoc installs. See Windows Install for the difference.
Installers are downloaded here, but the provisioning token an agent needs to register is generated under Provisioning Tokens — a separate view. See Provisioning Tokens.
Next steps
Invite your team
Add users and assign one of Origin’s eight built-in roles.
Generate a provisioning token
Create the token each agent needs to register with your tenant.
Connect AI providers
See which AI tools Origin captures and set up the API-based integrations.
Deploy the agent
Install on macOS and Windows, manually or via MDM.