Skip to main content

Install on Windows

SigmaShake works on Windows 10 (Build 17063+) and Windows 11, x64 only. ARM64 native support is on the roadmap; for now ARM64 devices can run the x64 build under Windows on Arm emulation.

Pro subscription required. Sign up at sigmashake.com/pricing, then run ssg auth login to activate your license.

Quick install​

Step 1 — Subscribe​

A Pro or Enterprise subscription is required. Subscribe at sigmashake.com/pricing before installing.

Step 2 — Install the CLI​

PowerShell one-liner (recommended):

iwr -useb https://install.sigmashake.com/install.ps1 | iex

Pass -Yes / -y for non-interactive ToS consent (fail-closed without it in non-TTY runs). This script:

  1. Downloads the ssg CLI binary for Windows x64.
  2. Verifies the tarball against a pinned SHA-256.
  3. Extracts to %LOCALAPPDATA%\Programs\ssg\ (default).
  4. Adds that directory to your User Path environment variable.
  5. Optionally runs ssg setup (skip with -NoSetup). Open a fresh terminal after the install so PATH picks up the new directory.

Step 3 — Activate your license​

ssg auth login

The browser opens to accounts.sigmashake.com. Click Authorize ssg CLI and the license JWT writes to disk automatically.

Verify the install​

ssg --version # should print: 0.29.85 (or newer)
ssg --help

If ssg isn't found after a fresh PowerShell installer run, open a new terminal. PATH changes don't propagate into the shell that ran the installer.

First-run setup — ssg init​

cd C:\path\to\your-project
ssg init

This does four things on Windows:

  1. Writes .sigmashake/ (governance rules + presets) into your project.
  2. Auto-detects every AI agent on the machine (Claude Code, Cursor, Copilot, Codex, Gemini CLI, Antigravity, etc.) and wires C:\…\ssg-hookw.exe hook eval into each adapter's settings file.
  3. Patches .vscode/mcp.json to register the ssg-governance MCP server for GitHub Copilot.
  4. Registers a Windows Task Scheduler entry so ssg daemon starts at user login and restarts on crash.

Then it prints a status report you can verify with ssg status.

Why ssg-hookw.exe? It is the windowless twin of ssg.exe, built against the Windows GUI subsystem so Claude Code's PreToolUse hook doesn't briefly flash a console window every time you fire a tool call. Functionally identical to ssg hook <subcommand>.

What got installed​

ssg init writes these files into your project (all reversible):

PathPurpose
.sigmashake/config.tomlDashboard port, eval timeout, per-agent toggles
.sigmashake/rules/security.rulesStarter security rules (destructive shell, .env reads)
.sigmashake/presets/minimal.rulesBare-minimum starter preset
.sigmashake/presets/strict.rulesStricter preset with deploy approval gates
.gitignore (modify)Appends .sigmashake/rules/autopilot.rules
.claude/settings.jsonAdds 8 hook entries (PreToolUse, UserPromptSubmit, …)
.vscode/mcp.jsonRegisters the ssg-governance MCP server
.gemini/policies/ssg-governance.tomlGemini CLI policy file (if Gemini installed)

Useful flags​

FlagWhat it does
--client=<name>Install one adapter only (claude-code, copilot, cursor, codex, gemini, antigravity, pi)
--smartDetect your project's tech stack and pull matching Hub rulesets
--globalWrite hook config to %USERPROFILE%\.claude\settings.json so it covers every project
--no-autostartSkip the Task Scheduler entry (set SSG_NO_AUTOSTART=1 to make it the default)

Daemon control​

ssg autostart status # is the Task Scheduler entry present and running?
ssg autostart disable # stop + remove the scheduled task
ssg autostart enable # install + start the scheduled task (idempotent)

The autostart entry runs as your user — no elevated permissions, no system service.

Restart VS Code after init​

If the Copilot adapter was installed, VS Code needs a restart to load the new MCP server registration from .vscode/mcp.json. Close every window and re-open the workspace.

Activate your Pro subscription​

ssg requires an active Pro or Enterprise subscription. After installing, run:

ssg auth login # opens accounts.sigmashake.com in your browser

The license JWT is issued automatically after payment. No license key to copy or paste.

Subscribe at sigmashake.com/pricing. Pro is $5/month. Enterprise pricing on request.

Once activated, ssg provides:

  • Unlimited evaluations
  • All adapters (Claude Code, Cursor, Copilot, Gemini, Codex, etc.)
  • All built-in rules (security, destructive-ops, secrets, etc.)
  • Local audit log at %USERPROFILE%\.sigmashake\audit.db
  • Cloud audit sync across machines

Check your status anytime:

ssg status
ssg flight # last 24h dashboard

SigmaShake Desktop — the desktop app (optional)​

SigmaShake Desktop is a native C#/.NET WinForms + WebView2 app that wraps ssg for non-CLI users. It runs the governance daemon, surfaces approvals as native Windows toasts, and opens the dashboard in a WebView2 window.

Download​

Live channel metadata (canonical): desktop/windows/latest.json — currently 1.0.20 SigmaShakeDesktop-Setup.exe.

BuildDownload
Always-latest (from windows/latest.json)SigmaShakeDesktop-Setup.exe
Microsoft Store (sandboxed, auto-updates)SigmaShake Desktop on the Microsoft Store
Windows x64 Setup.exeSigmaShakeDesktop-Setup-1.0.20.exe

The Setup .exe is an NSIS installer. The app checks for updates on launch. First-run license/ToS is a GUI gate and stays fail-closed — never skip it.

Microsoft Store. Free to download; a $5/month subscription unlocks value surfaces. Purchase from the Store listing or subscribe at sigmashake.com/pricing.

Install​

  1. Run the downloaded .exe.
  2. SmartScreen will warn "Windows protected your PC" on first launch — the binary is Azure Code Signed but Microsoft's reputation cache lags behind every new release. Click More info → Run anyway.
  3. The app drops into your system tray (no taskbar entry).

What it does​

  • Lives in the system tray — right-click for Open Dashboard, Settings, Diagnostics, Quit.
  • Health probe every 5 s — tray icon turns red if the governance daemon stops.
  • Native Windows toasts when an agent's tool call hits an ask-mode rule.
  • Auto-launches ssg daemon + ssg serve on startup; manages port hunting in the 5599–5603 range.
  • Bundles its own copy of ssg.exe — installing the desktop app also installs the CLI under %LOCALAPPDATA%\Programs\SigmaShakeDesktop\resources\ssg.exe. If you installed the CLI separately via winget or PowerShell, the standalone CLI takes precedence on PATH.

First-run wizard​

The desktop app opens a one-time wizard asking which profile to apply:

  • Personal — relaxed defaults, single-user, no audit sync
  • Professional — strict defaults, structured logging, team-sync ready
  • Enterprise — fail-closed mode, license required, MDM-ready

For solo developers: pick Personal. Change later in Settings.

Combined CLI + Desktop install​

The fastest path for a brand-new Windows machine (subscribe first at sigmashake.com/pricing):

# 1. CLI
iwr -useb https://install.sigmashake.com/install.ps1 | iex

# 2. Activate license
ssg auth login

# 3. Desktop app (run the NSIS installer)
# https://download.sigmashake.com/desktop/windows/latest/SigmaShakeDesktop.exe

# 4. Wire your project
cd C:\path\to\your-project
ssg init
ssg status # verify daemon, dashboard, hooks

If you're a Claude Code user, you can ask Claude to do this for you with /init-windows — the skill resolves the ssg.exe path, runs ssg init in the project, and reports a single-page status. See the skill source at shared/agent-config/skills/init-windows/SKILL.md.

Update​

The CLI auto-updates inside its version range. To pull the latest:

iwr -useb https://install.sigmashake.com/install.ps1 | iex # PowerShell installer is idempotent
ssg update # all install methods

SigmaShake Desktop checks for updates on launch and prompts when a new version is available.

Uninstall​

ssg uninstall --yes # remove ssg + %USERPROFILE%\.sigmashake\
# or remove %LOCALAPPDATA%\Programs\ssg\ manually for the PowerShell installer

# Desktop app:
# Settings → Apps → SigmaShake Desktop → Uninstall

ssg uninstall cleans up:

  • %USERPROFILE%\.sigmashake\ (audit log, license, daemon socket)
  • All .claude/settings.json files in your home tree (strips ssg hook entries)
  • Any %USERPROFILE%\.gemini\, %USERPROFILE%\.codex\ adapter configs
  • The Task Scheduler entry registered by ssg autostart enable

It does not touch winget's own metadata or installed node_modules.

Permissions you'll be asked for​

PermissionWhyWhen asked
SmartScreen pass-throughReputation cache for newly-signed buildsFirst launch of SigmaShake Desktop
NotificationsNative Windows toasts for ask-mode rulesFirst time SigmaShake Desktop fires a toast
NetworkOnly used for ssg auth login and Hub ruleset pullsFirst Pro upgrade or first --smart init

ssg (CLI) does NOT request: microphone, camera, location, or any elevated/admin permission. Every governance evaluation is local.

Troubleshooting​

Do I need Administrator to install ssg?​

No. Nothing in the official ssg CLI or SigmaShake Desktop installers requires elevated permissions, ever:

ArtifactInstalls toScope
ssg CLI%LOCALAPPDATA%\Programs\ssg\Per-user
SigmaShake Desktop%LOCALAPPDATA%\Programs\SigmaShakeDesktop\Per-user
PATH entryAdded by the installerUser scope only, never Machine
Autostart entryTask Scheduler / HKCURuns as your user, no system service

If you ever felt forced into an elevated PowerShell to get ssg installed, that's a symptom of one of the two issues below — not a real requirement. See docs/ops/windows/INSTALL_PERMISSIONS.md for the deeper agent/operator runbook on this.

"running scripts is disabled on this system" / "is not digitally signed"​

This is not a permissions problem with ssg, and you do not need to run as Administrator. You'll see one of these when running the installer:

File C:\...\install.ps1 cannot be loaded because running scripts is disabled on this system.
File C:\...\install.ps1 is not digitally signed. You cannot run this script on the current system.

What's actually happening: PowerShell blocks script files that were downloaded from the internet (they carry a hidden Zone.Identifier tag). This only bites you if you saved install.ps1 to disk first — the recommended one-liner pipes the script straight into iex and never touches disk, so it isn't affected:

# Preferred — immune to this issue entirely
iwr -useb https://install.sigmashake.com/install.ps1 | iex

If you already downloaded the file, fix it without elevation using either of these — no admin required:

# Option A — allow scripts for your user only (no admin needed)
Set-ExecutionPolicy -Scope CurrentUser RemoteSigned
# Option B — strip the "downloaded from the internet" tag from this one file
Unblock-File .\install.ps1

Do not follow generic internet advice to run Set-ExecutionPolicy RemoteSigned in an elevated shell. That changes the policy for every user on the machine and needs admin only because it defaults to LocalMachine scope. -Scope CurrentUser does the same job for your account alone, with no elevation.

"Access to the path ... is denied" during install​

Two distinct causes, neither requires admin to fix:

Cause A — ssg is currently running. ssg.exe, ssg-hookw.exe, or SigmaShake Desktop is holding the binary open. Close SigmaShake Desktop (right-click the tray icon → Quit) and stop any running daemon:

ssg daemon --stop

Then re-run the installer.

Cause B — a prior elevated install left a restrictive ACL. If someone previously "fixed" an install issue by running the installer as Administrator, that run can leave %LOCALAPPDATA%\Programs\ssg\ owned by an elevated identity, which then blocks every future non-elevated install or update. This is the trap that bad "run as admin" advice leads to. Fix it by removing the folder and reinstalling normally — still no admin required:

Remove-Item -Recurse -Force "$env:LOCALAPPDATA\Programs\ssg"
iwr -useb https://install.sigmashake.com/install.ps1 | iex

ssg: command not found after PowerShell install​

You're in the same terminal that ran the installer. Open a new PowerShell window — PATH only updates for new shells. Or run:

$env:Path += ";$env:LOCALAPPDATA\Programs\ssg"

…to patch the current session.

ssg init says "ssg" not found on PATH even though I just installed it​

This is the same shell-vs-environment issue. From the binary's install directory:

& "$env:LOCALAPPDATA\Programs\ssg\ssg.exe" install

ssg install is the official PATH-fix command — it writes the install directory to your user Path env var. Open a new terminal afterwards.

Hooks fire but Claude Code doesn't see decisions​

Restart Claude Code. Hooks are read once at process start.

Brief black console flash on every tool call in Claude Code​

This is an upstream Claude Code Windows bug, not an SSG bug. When Claude Code fires a hook on Windows, it wraps the configured command string in bash.exe -c "..." and spawns Git Bash without setting the windowsHide flag. Git Bash is a CONSOLE-subsystem PE, so Windows allocates a fresh conhost.exe window for it — the visible flash you see on every tool call.

SSG ships ssg-hookw.exe as a GUI-subsystem (windowless) binary so the loader never allocates a console for it directly. That fix works only when Claude Code spawns the binary itself; once Anthropic's CLI wraps the command in bash.exe -c, the bash process is the one allocating the console, and SSG can't override it from outside.

What we've done to reduce the noise (v0.29.90+):

  • Removed the wasted Windows daemon-respawn fork that fired on every hook eval (the Unix-socket existence check is meaningless on Windows — the Task-Scheduler-managed daemon is already running).
  • Verified every remaining child spawn in the eval path passes windowsHide:true to Bun so any console subsystem child is hidden.

Workarounds while waiting on Anthropic:

  1. Use SigmaShake Desktop — it bundles the dashboard in a native window and surfaces approvals as Windows toasts, so you can run Claude Code in --no-hook mode (or skip the CLI entirely for approval workflows).
  2. Run Claude Code from a fully detached terminal session (e.g. WezTerm or Windows Terminal pinned to a workspace) so the flashes are confined to that workspace and don't steal foreground focus.

Track the upstream fix: if you see this and want to push for a Claude Code fix, file an issue at github.com/anthropics/claude-code with a reproducer pointing at this section.

Daemon won't start at login​

ssg autostart status
schtasks /Query /TN "SigmaShake-Daemon" /V /FO LIST

Re-register with ssg autostart enable. If the task is in a failed state, manually delete it via Task Scheduler and re-enable.

Dashboard port 5599 is busy​

Edit .sigmashake/config.toml and change dashboard_port. Restart with ssg daemon --stop && ssg daemon. Port hunting (5599→5603) is automatic when SigmaShake Desktop starts the daemon, but a CLI-launched daemon honors your config exactly.

package/bin/ssg.exe SHA256 mismatch during PowerShell install​

The installer pins a SHA-256 per release. If you see this, wait an hour and retry the PowerShell installer. If the issue persists, contact support at sigmashake.com/support.

SigmaShake Desktop won't launch​

  1. Run from PowerShell to surface the actual error:
    & "$env:LOCALAPPDATA\Programs\SigmaShakeDesktop\SigmaShakeDesktop.exe"
  2. Check %USERPROFILE%\.sigmashake\desktop.<date>.log.
  3. File a bug at github.com/sigmashakeinc/sigmashake-mono/issues.

Other SigmaShake products on Windows​

ProductStatus on WindowsWhat it does
ssg CLI✅ ProductionThe governance engine. Pro subscription required. Install via the PowerShell one-liner above.
SigmaShake Desktop✅ ProductionSystem-tray app. Download from sigmashake.com/desktop or the .exe link earlier on this page.
SigmaShake Voice🟡 RoadmapWhisper-powered voice-to-text. macOS + Linux today; Windows on the v1 roadmap.
SigmaShake Gaze❌ Linux-only (v0)Webcam eye-tracking. Windows support on the v1 roadmap.

What's next​