Sealo user guide · v0.3

From download to
Verified.

One complete path for team owners, participants, and receivers. Follow it top to bottom or search for the exact screen you are on.

01 · Before you start

Two parts, two jobs.

The desktop app proves what a sender transmits. The browser extension checks that proof for a receiver. For a real test, use two people or two browser profiles.

SenderDesktop appSealo Camera
signed video →
ReceiverChrome extensionVerified badge
Do not install both and expect your own app to certify itself. A sender cannot prove to themselves what a remote receiver received.

02 · Identity

Create once, reuse everywhere.

1

Use your invitation

If an admin invited you, accept the email using the exact same address you will use in Sealo. You join their existing organization—do not create another.

2

Or create the first organization

The first person from a company signs into the Sealo portal, enters the company name, and becomes its owner.

3

Invite the team

Owners use Portal → Users. WorkOS-backed memberships then follow the account into the Mac app, Windows app, and verifier extension.

Sealo organization onboarding page with a company-name field
Actual productThe organization onboarding screen. Users with an existing membership skip this page.
Already managed by an identity provider?

If WorkOS finds an active membership, Sealo skips organization creation. Google or Microsoft login identifies the person; it does not automatically prove which company should own their Sealo tenant unless a WorkOS organization membership or directory connection establishes that relationship.

03 · Sender · macOS

Install and approve Sealo Camera.

Install Sealo
SA

Drag Sealo into Applications

Login Items & ExtensionsCamera Extensions
Sealo CameraOn

Only you can approve a camera extension.

1

Install the application

Download Sealo.dmg, open it, and drag Sealo into Applications. Eject the disk image and launch the copy inside Applications.

2

Approve the camera extension

Click Activate. If macOS says approval is pending, go to System Settings → General → Login Items & Extensions → Camera Extensions and enable Sealo Camera. Apple requires this manual consent.

3

Sign in and enroll

Choose your physical camera, sign in with your organization account, and enroll. The Secure Enclave creates a key that cannot be exported.

SSealoActive
Physical input
MacBook Pro Camera⌄
Account
alex@northstar.example
Enrollment
Enrolled

Publishing MacBook Pro Camera to Sealo Camera

04 · Sender · Windows

Install and enroll with the TPM.

1

Run the installer

Download Sealo-Setup.exe. This development build is unsigned: choose More info → Run anyway only if it came from sealo.tech, then approve administrator access.

2

Sign in

The browser returns to Sealo using sealo-windows://auth/callback. Use an account in your organization.

3

Choose and enroll

Select the physical camera and enroll. Windows creates the signing key inside TPM 2.0 and starts Sealo Camera.

Windows status

The installer and protocol pass Windows CI. Physical Windows 11 TPM/camera acceptance is still required before calling this production-ready.

05 · Every call

Select the virtual camera.

1

Keep Sealo running

The desktop app must say Publishing [physical camera] to Sealo Camera.

2

Open call settings

In Meet, Teams, Zoom, or another calling app, open its camera picker.

3

Choose Sealo Camera

Do not choose MacBook Pro Camera, Logitech, or another physical camera. Those bypass the signed path and correctly produce Cannot verify.

SSealoActive
Physical input
MacBook Pro Camera⌄
Account
alex@northstar.example
Enrollment
Enrolled

Publishing MacBook Pro Camera to Sealo Camera

06 · Receiver · Chrome

Install the verifier once.

1

Load the extension

Download and unzip sealo-verifier.zip into a folder you will keep. Open chrome://extensions, enable Developer mode, choose Load unpacked, and select that folder.

2

Sign into the extension

Open Sealo from Chrome’s toolbar and sign in. It reuses your existing organization membership. There is no second organization setup.

3

Reload existing meeting tabs

Chrome cannot inject a newly installed extension into pages already open. Reload the meeting once after install or update.

chrome://extensions
S
Sealo Verifier

Verify signed participants in live calls

On

07 · The result

Read the badge, not the face.

Participant in a video call✓ Verified · Alex MorganAlex Morgan
✓ Verified

Identity, device, signature, freshness, watermark, and video binding passed.

? Cannot verify

A check could not be completed. Open details for the exact reason. This is not an accusation.

× Not verified

A concrete security rule failed. The details identify the rule.

Your own preview says “Sealo Active.” That confirms you selected the virtual camera. Only another receiver can say your transmitted video is Verified.

08 · Troubleshooting

Start with what you see.

Sealo Camera is missing on Mac

Enable it in System Settings → General → Login Items & Extensions → Camera Extensions, then fully quit and reopen the calling app.

The camera is selected but video is blank

Keep Sealo open and confirm it says Publishing. Switch to the physical camera and back once. If needed, restart the calling app.

No badge appears

Open the verifier extension, sign in, confirm it is enabled for the meeting site, and reload the meeting tab.

“Cannot verify — no watermark”

First confirm the sender chose Sealo Camera—not the physical camera. Then open badge details and allow a few frames for watermark recovery.

Enrollment returns 403

The account is not an active member of an approved organization. Accept the invitation or finish organization setup, then retry.

Enrollment returns 409

The hardware is already enrolled to another identity. An organization admin must revoke or reassign that device.

AI agent handoff

Make the setup copyable.

Use Copy guide for an AI agent at the top. It copies a clean Markdown version with exact URLs, menu paths, expected states, and troubleshooting branches.

Never share secrets

Do not paste passwords, WorkOS API keys, refresh tokens, device private keys, or invitation links into an AI agent.