# chrome-flow-capture — Employee operator package

> This directory is the installed Employee GUI package. Start the GUI launcher, enter the one-time invitation issued by IT, choose or create a local profile, and use the isolated Chrome window. No source code or repository checkout is required for normal Employee operation.

This is the runtime guide for an installed package. It intentionally contains no credentials, invitation codes, capture IDs, or captured data. The Employee package does not contain IT CLI commands and cannot issue invitations or retrieve remote captures.

## Before operating

- Use only a machine and internal web app you are authorized to operate.
- Never use the user's real Chrome profile. The application opens a dedicated isolated Chrome profile.
- Treat invitation codes, local captures, HAR files, cookies, and tokens as sensitive. Never paste captured content into agent logs, chat, tickets, or source files.
- Obtain the invitation from authorized IT. Do not ask for the IT admin credential or try to create an invitation locally.

## Start the Employee GUI

- macOS: open the adjacent `Chrome Flow Capture.app` bundle.
- Windows: start the installed Employee GUI shortcut or the adjacent Employee GUI launcher.
- The Employee package is GUI-only; there is no supported `chrome-flow-capture it ...` command here.

## First activation

1. Open the Employee GUI.
2. Paste the one-time code from IT into `Mã kích hoạt`.
3. Select `Kích hoạt`.
4. Choose or create the local profile.

The Employee does not enter or select a department. The server derives the device department from the invitation.

## Capture workflow

1. Select the intended profile.
2. Start the managed Chrome window.
3. Log in and use only the authorized internal web app.
4. Close the managed Chrome window to finalize the capture.
5. Leave automatic sending enabled unless IT instructs otherwise.

Every finalized capture remains locally encrypted. Automatic sending uploads it through the authenticated Worker path; disabling automatic sending leaves the encrypted bundle local for later supported sending from the GUI.

## Included references

- [Bundled application README](./app/README.md): Product purpose and capture sensitivity.
