Skip to main content
After Application Server installation, Management Tool installation, and Client deployment, this is the checklist of tasks that gets the platform from “installed” to “operational.” Work through it in roughly this order — the early items are prerequisites for the later ones. For SaaS deployments, complete Getting Started with a SaaS deployment first, then continue here. For updating an existing Syteca deployment, see the separate upgrade procedure.

The 16 tasks

1

Assign endpoint licenses to Clients

Available licenses are automatically assigned to Clients on their first connection to the Application Server. If a license wasn’t assigned, assign it manually.
2

Assign PAM seat licenses to PAM users

PAM seat licenses need to be assigned to specific users (on the Users page) before they can use any PAM functionality — Password Management page, Account Discovery page, Syteca Desktop Connection Manager, and Syteca Web Connection Manager.
3

Add Client groups

Client groups let you grant access to multiple Clients at once and apply shared configuration — without needing to grant access to every Client individually.
4

Add users / user groups and define their permissions

5

Define Client and Client group configuration

Configure recording, monitoring, USB rules, and other settings on individual Clients or — more efficiently — on Client groups so settings propagate to all members.
6

Configure Password Management (PAM)

Walk through Getting Started with Password Management to configure secrets, Syteca Connection Manager (desktop or web), and the access-request workflow.
7

Configure Account Discovery

Account Discovery scans the network for privileged accounts and onboards them into PAM secrets — letting you bring existing accounts into management without manual entry.
8

Manage alerts

Alerts notify investigators of potentially harmful or forbidden activity. Create new alerts, assign them, and use import / export for backup or migration between deployments. The platform also ships with a library of default alerts for fraud, data leakage, illicit websites, and non-work activity.
9

Create USB monitoring rules

USB monitoring rules detect (and optionally block) USB devices plugged into Windows Clients — with notifications, alerts, and per-device-class controls.
10

View monitoring results in the Management Tool

Monitored data from Clients flows to the Session Viewer — accessed via the Sessions list on the Activity Monitoring page.
11

Export sessions for forensic use

Use Forensic Export to produce encrypted session files that can be played in the standalone Syteca Forensic Player — useful for legal evidence, HR investigations, and third-party audit handovers.
12

Configure alert notifications

Configure how alert events reach investigators — email and tray notifications, on-screen warnings, automatic blocking. Notifications can also flow through the Syteca Tray Notifications application in the Windows notification area.
13

Generate reports

Reports turn months of activity data into auditor-ready evidence — scheduled for recurring deliveries or ad-hoc for one-time investigations.
14

Set up dashboards

User Activity Dashboards visualize productivity, threat detection, and other monitoring data. System Health dashboards show real-time platform health.
15

Configure database management

Configure database cleanup and archiving to keep the live database manageable as your data volume grows. Old data can be archived to long-term storage and accessed later via Archived Sessions. Also remove uninstalled Clients from the database.
16

Enable Multi-Tenant mode (if needed)

Multi-Tenant mode lets a single Syteca deployment serve multiple isolated tenants — useful for MSSPs, large organizations with strict business-unit segregation, or service providers.

What’s next

After completing the checklist, the platform is fully operational. From here:

SaaS deployment

First-hour onboarding for SaaS customers — mandatory password change, mandatory 2FA, serial key viewing, Client install.

Update Syteca

Upgrade procedure with Isolation Mode, data migration, .NET prereqs, and Client update strategy.

Getting started with PAM

Configure Password Management — Connection Managers, secrets, third-party apps required.

Management Tool basics

Sign-in patterns, navigation, brute-force lockout, language and tray notifications.