Skip to main content
Studio is a signed desktop application with a bundled local helper. The desktop must reach both Altostrat’s cloud services and the hosts, APIs, browsers, or local applications you want Studio to operate.

Supported desktop platforms

Install the build matching the workstation architecture. Keep automatic updates enabled unless your organization distributes pinned releases through its own software-management process.

Cloud and local network access

Studio needs:
  • HTTPS access for sign-in, organization sync, Bedrock and supported AWS services, updates, billing, Studio Remote relay, and configured cloud integrations.
  • Direct or routed reachability from the workstation to managed hosts.
  • A VPN or jump host when the management network is not directly reachable.
  • Protocol ports required by the configured host, such as SSH, Telnet, RDP, HTTPS, VNC, serial, SNMP, or vendor-specific services.
  • Access to connector and MCP server URLs, including OAuth authorization and callback endpoints.
Studio does not provide a network path the workstation lacks. Test a target from the same workstation and network context before diagnosing it as a Studio failure.

Local helper

The bundled helper provides terminals, network diagnostics, file transfer, browser runtime coordination, Computer Use, firmware staging, and other local operations. It starts with Studio and listens on local application paths rather than as a separately administered server. Endpoint controls must allow the signed Studio app and its bundled helper binaries to run. If a local tool disappears after an EDR or antivirus policy change, inspect the security product before reinstalling Studio.

OS permissions

Grant only the features your operators use. After granting a macOS privacy permission, use Settings → Computer Use/Audio Use → Re-check. Restart Studio if macOS retains the previous state.

Computer Use availability

The documented Computer Use permission and secondary-cursor workflow is for the macOS desktop app. Prefer a structured terminal, connector, MCP, or browser tool when possible; Computer Use is for native graphical surfaces with no safer structured route.

Browser runtime

Studio packages the browser assets required by headless browser sessions. Endpoint security must preserve the application bundle’s browser files and symlinks. Browser sessions also need outbound access to the target site and its authentication endpoints.

Firmware staging

The TFTP firmware server binds to a private RFC 1918 address and serves a selected local root directory.
  • Windows defaults to UDP 69.
  • macOS/Linux-like helper environments default to UDP 6969 because privileged ports normally require elevation.
  • The target device must reach the displayed workstation address and port.
  • Host firewall rules must allow the selected UDP port.
TFTP has no authentication. Use a dedicated directory, place only the required firmware file inside it, and stop the server after transfer.

Studio Remote

Studio Remote requires:
  • The current production Studio desktop app running in Electron.
  • A signed-in desktop with the remote relay enabled for the release.
  • Altostrat Remote on iPhone. Android is currently shown as coming soon.
  • Network access from both devices to the relay services.
The phone does not replace local reachability. The desktop must stay awake, signed in, and connected to target networks for local tools to run.

Calls and media

Allow WebRTC and the required media paths through proxies and firewalls. Select the correct microphone, camera, and speaker in the call preview or device settings. Audio Use and call transcription also require available usage allowance and no applicable hard limit.

Resource planning

Long chats, multiple live browser or RDP sessions, large terminal buffers, dashboards, local embeddings, media calls, and packet capture all consume workstation resources. Close unused live surfaces and keep enough disk space for updates, files, recordings, and cached application assets. For large rollouts, validate one representative managed workstation with the organization’s VPN, proxy, EDR, firewall, OAuth, and device protocol policies before broad deployment.

Install and sign in

Install the signed desktop build and select the correct organization.

Troubleshooting

Work from scope, helper, permissions, policy, credentials, and external reachability.