Skip to main content

Installing SigmaShake Desktop

SigmaShake Desktop is a tray/menu-bar app that supervises ssg daemon + ssg serve in the background and hosts the SigmaShake governance dashboard in a native window. No terminal. No .rules files to hand-write. Install, click through a short wizard, the shield turns green.

Desktop ships as three separate native apps, one per operating system — not one cross-platform bundle. They run the identical ssg engine and the identical dashboard + wizard web UI; only the window shell differs:

PlatformShellWhere to get it
macOSNative Swift/AppKit menu-bar app (WKWebView)Mac App Store
WindowsNative C# / .NET 8 WinForms + WebView2Microsoft Store or winget install SigmaShake.Desktop
LinuxNative Wails v2/Go app (system WebKitGTK WebView)Flatpak, one-line installer, or manual tarball

Free to download and install; a $5/month subscription unlocks every value surface — subscribe at sigmashake.com/pricing. You activate your account inside the first-run wizard, so it's fine to install first and subscribe when the wizard asks.

If you bought a SigmaShake plan and you're not a developer, this is the version you want. Prefer to have your AI coding agent do the clicking for you? See Tutorial: install SigmaShake with your AI agent.


SigmaShake Desktop for Windows is a native C# / .NET 8 WinForms + WebView2 application. It ships a per-user installer — you do not need administrator rights, and the app installs to your own user folder. Two ways to install.

Option 1 — Download the installer (no terminal)​

  1. Go to sigmashake.com/desktop
  2. Click Download SigmaShake Desktop for Windows — your browser downloads SigmaShakeDesktop-Setup.exe directly (no zip to extract).
  3. Double-click SigmaShakeDesktop-Setup.exe in your Downloads folder.
  4. If Microsoft Defender SmartScreen appears ("Windows protected your PC"):
    • Click More info.
    • Click Run anyway.
    • This can appear the first time you run a newly-released installer before Windows reputation scoring catches up. The installer is Authenticode-signed; you can verify by right-clicking the .exe → Properties → Digital Signatures and checking the SigmaShake signature.
  5. The installer runs silently — there is no admin prompt because it installs to your own user folder.
  6. The SigmaShake shield appears in your system tray (bottom-right of the taskbar, next to the clock). If you don't see it, click the small ^ ("Show hidden icons") arrow to reveal it.

Option 2 — winget (one command) or the Microsoft Store​

If you have a terminal open already, this is the fastest path:

winget install SigmaShake.Desktop

winget is Microsoft's official package manager and ships with Windows 11 and modern Windows 10. It handles the SmartScreen check for you. You can also install from the Microsoft Store listing directly, which auto-updates through the Store.

First time using winget? Press Win + X on your keyboard, then click Terminal. Paste the command above and press Enter.


First-run wizard (same flow on every shell)​

The first time SigmaShake Desktop opens on any platform, the same welcome wizard walks you through nine steps — macOS, Windows, and Linux each embed their own copy of the setup/wizard web UI, but the flow and the steps below are identical. (Source of the flow verified against sigmashake-desktop-linux/frontend/wizard/index.html.)

1 — Choose your protection profile​

Pick the profile that matches how you use AI agents:

ProfileFor
I'm new to AI (recommended)New to AI agents. Sets the safest defaults and explains what each guardrail does as you go.
PersonalSolo Claude Code / Cursor / Windsurf use. Blocks destructive shell commands, asks before network writes.
ProfessionalKnowledge workers handling customer data. Adds secrets scanning, email guardrails, audit logging.
EnterpriseSOC 2-ready. Tamper protection, SIEM forwarding, fleet enrollment. Requires organization admin.
Agent DevIDE for vibecoders. Spawn agents, enforce guardrails, monitor everything. Unlocks the Agent Developer Environment.

Click your profile — you can change it later in Settings. There's also a Quick Setup button on this screen that skips agent, feature, and rule customization and finishes setup immediately with recommended defaults.

2 — Pick your AI coding agent​

Choose the AI agent you use most (Claude Code, Cursor, Copilot, Codex, Gemini CLI, etc.) so SigmaShake can wire itself into it. You can connect more agents later from Settings, or click "I'll set this up later" to skip.

3 — Configure features​

Every hook and MCP-server integration for your chosen agent is on by default. Turn off anything you don't need, or click "Use recommended defaults" to keep everything on and move ahead.

4 — Add rules from the Hub (optional)​

SigmaShake starts with zero rules — nothing is blocked until you say so. Search and pick any governance rulesets you want from the Hub now, or continue with none and add them later from the dashboard's Hub page.

5 — Choose your workspace​

Pick the project folder SigmaShake should govern. A .sigmashake/ folder is created there and your agent is wired up — nothing else on disk is touched.

6 — Accept the Terms​

Read and accept the SigmaShake Terms of Service to continue.

7 — Review and install​

A plain-language list of every change the installer is about to make, plus how to undo each one later. A "keep AI agents from uninstalling SigmaShake" self-protection toggle is on by default here. Click Install now.

8 — Activate your account​

This is where you connect SigmaShake Desktop to the SigmaShake account you bought your plan with. Two ways (or skip and activate later):

Sign in with browser​

  1. Click Sign in with browser.
  2. Your default browser opens to accounts.sigmashake.com.
  3. Sign in with your SigmaShake account (or via SSO if your company is on Enterprise).
  4. The browser confirms, and SigmaShake Desktop automatically advances.

When you bought your plan, we emailed you a welcome link. Open that email, copy the link, then in the wizard:

  1. Click "Have an activation link from email?".
  2. Paste the link into the box that appears.
  3. Click Activate.

Lost the email? On the welcome page (the URL inside the email), click "Send me a fresh link" and we'll email you a new activation link to the same address.

Click "I'll authenticate later" to explore locally first — cloud audit, private rulesets, and your eval quota need an activated account, but local governance works immediately.

9 — Done​

The wizard closes. Click Open dashboard to see the live governance dashboard, or "Show me what AI can and can't do" for a quick guardrail simulator. Any AI agent on your computer is now governed by the rules in your profile.

To open the dashboard again later: on Windows, click the tray icon and select Open Dashboard, or press Win + S and type SigmaShake Desktop. On macOS and Linux, click the menu-bar/tray icon and choose Open Dashboard. From a terminal on any platform: ssg serve.


Linux​

SigmaShake Desktop for Linux is a native Wails v2/Go application (system WebKitGTK WebView) — the Linux successor to the retired cross-platform Electrobun wrapper. It supervises ssg daemon + ssg serve and opens a WebKitGTK window pointed at the same dashboard those serve on every other platform. Free to download and install; a $5/month subscription unlocks every value surface — subscribe at sigmashake.com/pricing. Three install paths below. Flatpak is the most modern (sandboxed, delta auto-updates, works on every Flatpak-capable distro). The one-line installer is the simplest for a single user without Flatpak.

Our signed Flatpak channel at flatpak.sigmashake.com ships SigmaShake Desktop, sandboxed by default, with delta auto-updates via flatpak update. The Desktop bundle includes the governed ssg engine it needs at runtime. One-time remote add:

flatpak remote-add --if-not-exists sigmashake \
https://flatpak.sigmashake.com/sigmashake.flatpakrepo

Install the app:

flatpak install sigmashake com.sigmashake.Desktop

Launch from your application menu, or:

flatpak run com.sigmashake.Desktop

Updates: flatpak update picks up every release automatically; the in-app updater inside the Desktop bundle is a no-op under Flatpak (the runtime is content-addressed and read-only).

First-time Flatpak setup? Most distros ship Flatpak preinstalled. If flatpak: command not found, your distro's docs cover it — see flatpak.org/setup.

Paste this in a terminal and SigmaShake Desktop installs, registers itself in your application menu, and launches:

curl -fsSL sigmashake.com/desktop/install.sh | sh

The installer:

  • Downloads the stable Linux Wails/Go bundle from download.sigmashake.com/desktop/wails/.
  • Extracts the bundle to ~/.local/share/SigmaShakeDesktop (no sudo, per-user only).
  • Verifies the published .sha256 sidecar and confirms the bundled ssg engine is a Linux ELF before replacing the installed app.
  • Writes a real Freedesktop menu entry to ~/.local/share/applications/sigmashake-desktop.desktop with absolute paths and a proper icon, so SigmaShake Desktop appears in your launcher and runs with a single click — same UX as an AppImage.
  • Refreshes the desktop database when your distro provides the helper.
  • Launches the app for you when a graphical session is available. Set SIGMASHAKE_NO_LAUNCH=1 to install only.

After install, future starts are one click from your application menu (GNOME Activities, KDE Krunner, COSMIC launcher, Pop!_OS Activities, etc.). The first-run wizard is the same flow as every other platform — see First-run wizard above.

Read the script before running it​

curl -fsSL sigmashake.com/desktop/install.sh | less

Customise the install​

Env varEffect
SIGMASHAKE_DESKTOP_DIR=$HOME/Apps/SigmaShakeDesktopInstall somewhere under your home directory other than ~/.local/share/SigmaShakeDesktop.
SIGMASHAKE_DESKTOP_BIN_DIR=$HOME/.local/binPut the sigmashake-desktop launcher symlink somewhere else under your user account.
SIGMASHAKE_NO_LAUNCH=1Install only — don't open the app at the end.

Manual extract (if you don't want to run a script)​

  1. Download stable-linux-x64-SigmaShakeDesktop.tar.gz from sigmashake.com/desktop (CDN: download.sigmashake.com/desktop/wails/).
  2. Extract: tar -xzf stable-linux-x64-SigmaShakeDesktop.tar.gz.
  3. Run: cd SigmaShakeDesktop && ./SigmaShakeDesktop (use chmod +x SigmaShakeDesktop first if your shell says "permission denied").

This is a plain tarball, not a package — there's nothing for a package manager to install. It needs libwebkit2gtk-4.1 + libgtk-3 already on your system, which ship by default on Ubuntu, Pop!_OS, and Steam Deck's Desktop Mode.

Fedora: Fedora Workstation doesn't ship webkit2gtk4.1 by default. Install it first: sudo dnf install webkit2gtk4.1 gtk3. (An AppImage build that bundles its own WebKitGTK — no dnf install step needed — is also referenced on the download page, but is not currently published; use the tarball + dnf install above, or Flatpak, instead.)

The bundled SigmaShakeDesktop.desktop file is portable package metadata and is not a one-click menu entry on its own — that's why the install script writes a corrected one with absolute paths. If you skip the script, keep launching from ./SigmaShakeDesktop.

Long-form Linux notes (manual install + uninstall): Linux desktop (Wails/Go).

Legacy .deb packages​

Older .deb packages may still exist on disk from before the current Wails-era distribution. New downloads use Flatpak or the one-line installer above. If you're migrating from a legacy .deb, remove it with your distribution's package manager (sudo apt remove sigmashake-desktop), then run the one-liner.


macOS​

SigmaShake Desktop for macOS is a native Swift/AppKit menu-bar application. It hosts the same dashboard in a WKWebView window instead of re-implementing the UI natively — only the shell is Swift.

Install from the Mac App Store. This build is sandboxed and updates automatically through the Store — no separate updater, no notarisation prompts.

Option 2 — Direct download (.dmg)​

If your organization can't install from the Mac App Store, download the signed, notarized .dmg from sigmashake.com/desktop. This build uses Sparkle for in-app updates instead of the Store. On first launch, right-click the app → Open may be required until Gatekeeper's notarisation check catches up — the App Store build above doesn't need this.

For CLI-only installs on macOS (no Desktop app), see Install on macOS.


Uninstalling SigmaShake Desktop​

macOS​

Mac App Store install: open Launchpad, click and hold SigmaShake Desktop until it jiggles, then click the ✕ — or drag it from Applications to the Trash. macOS handles the rest; there's no separate uninstaller.

Direct .dmg install: quit the app from the menu bar, then drag SigmaShake Desktop.app from Applications to the Trash.

Optional full settings wipe (either install method): delete ~/.sigmashake/ with Finder, or run ssg uninstall from a terminal where ssg is on PATH.

Windows​

  1. Open Settings → Apps → Installed apps.
  2. Find SigmaShake Desktop in the list.
  3. Click the ⋯ (three dots) → Uninstall.
  4. Confirm.

This removes the application but leaves your settings (%USERPROFILE%\.sigmashake\ and %LOCALAPPDATA%\SigmaShake\). To remove those too:

# Run in PowerShell as your normal user (not Administrator):
Remove-Item -Recurse -Force "$env:USERPROFILE\.sigmashake"
Remove-Item -Recurse -Force "$env:LOCALAPPDATA\SigmaShake"

Linux​

One-line installer (recommended): quit the app from the tray, then delete these three paths in your file manager (or with your shell):

  • ~/.local/share/SigmaShakeDesktop — the bundle
  • ~/.local/share/applications/sigmashake-desktop.desktop — the menu entry
  • ~/.local/share/icons/hicolor/256x256/apps/sigmashake-desktop.png — the icon

After removing the menu entry, run update-desktop-database ~/.local/share/applications so it disappears from your launcher immediately (otherwise it goes away on next login).

Manual extract elsewhere: quit the app and delete whatever SigmaShakeDesktop folder you extracted.

Optional full settings wipe: delete ~/.sigmashake/ with your file manager — or run ssg uninstall from a shell where ssg is on PATH.

Legacy .deb: remove the sigmashake-desktop package with your distribution's package manager.

Legacy AppImage: delete the .AppImage file from wherever you stored it.

Flatpak install: flatpak uninstall com.sigmashake.Desktop. Add --delete-data to also drop the sandboxed per-user state under ~/.var/app/com.sigmashake.Desktop/. The ~/.sigmashake/ state lives on the host filesystem (via the --filesystem=home portal) — remove it with ssg uninstall for a full wipe, or delete that directory in your file manager.


Troubleshooting​

Tray icon never appears​

On Windows: click the ^ ("Show hidden icons") arrow next to the system clock — your tray icon may be hidden. Drag it onto the visible part of the taskbar to keep it there.

On Linux Wayland: the tray icon needs an indicator extension. On GNOME, install the AppIndicator and KStatusNotifierItem Support extension.

"Sign in failed" after the browser flow​

  1. Make sure you're signing in with the same email you used to buy your plan.
  2. If you're signed in to multiple SigmaShake accounts in your browser, sign all of them out and try again.
  3. As a fallback, click "I'll authenticate later" in the wizard, then use the activation link from your welcome email.

SmartScreen still blocks the install after "Run anyway"​

This means the installer file was modified or downloaded from a non-official source. Re-download from sigmashake.com/desktop — Microsoft's tamper detection is strict but reliable.

Agent isn't being blocked even though I set up SigmaShake Desktop​

SigmaShake Desktop governs AI agents that run on your computer. If your agent runs in the cloud (e.g., GitHub Codespaces, a remote SSH host, a containerized devbox), you need to install ssg directly on that machine. See Getting Started for the CLI install path.


What's next?​