Onboarding your team: what your employees do in My Uproot
Everyone your identity provider syncs into UprootSecurity gets My Uproot, the employee side of the platform. Each person does three things there: accept your published policies, complete Security Training, and install the Uproot Agent on their machine. That's the whole job.
What your team sees
My Uproot has four areas — Dashboard, Training, Policies and My Device. My Profile sits in the account menu. That's the whole portal; nothing in the admin console is reachable from it.
Getting in is one email. Each new person receives a mail to set up their account and choose a password, and from then on they sign in with their email and that password.
The three things every employee does
1. Accept your policies
Every employee sees every published policy. There's no per-person or per-team assignment — don't promise your team a tailored list, because they'll get the full set. They open each policy, read it, and accept it. Anything they haven't accepted yet sorts to the top of their list, so nobody has to hunt.
Acceptance has two states: accepted or not. There's no un-accepting.
If acknowledgement looks stuck, check the policy is actually published. A policy still in draft doesn't appear in My Uproot at all, and the check behind it sits at Pending rather than failing — so nothing looks broken while nothing is happening.
2. Complete Security Training
There is one course, Security Training: ten multiple-choice questions plus a video resource. Each answer is checked as they go, so a wrong answer won't let them move on — they just try again, as many times as they need. They finish the course only by answering every question correctly. Once it's complete, they can't retake it. That one course is the whole of training today.
3. Install the Uproot Agent
My Device walks each person through three steps: download, install, connect. There are builds for Windows, macOS and Linux (Ubuntu and Debian).
The connect step waits about two minutes for the agent to check in, and the page updates itself when it does. Tell people to leave that page open rather than refreshing or closing it.
Once connected, the agent runs seven checks on the machine and reports the verdicts back periodically: disk encryption, security updates, malware protection, screen lock timeout, logging, password policy and firewall. A failed check comes with step-by-step instructions to fix it, and the employee fixes it themselves — that's the design, and it's why you don't need to touch every laptop.
What the agent can and can't see is the question your team will actually ask — send them What UprootSecurity can see rather than paraphrasing it.
What an employee can't do
Admins assume several of these, then wait for something that isn't coming:
- Change their own email address, or change their password from inside the portal.
- Un-accept a policy, or download a policy as a file.
- Retake completed training.
- See their own due dates or renewal dates. Employees have no deadline view.
- Rename, remove or excuse a device, or mark a failing check as not applicable. Those are admin actions in the console.
- See anything in the admin console at all.
Why a skipped step costs the whole organization
Say this part out loud to your team — the blast radius is bigger than anyone expects.
- Unaccepted policies fail the policy-acknowledgement checks. They're measured across everyone in scope for your audit, so one person who hasn't accepted fails the check for the entire organization.
- Incomplete training fails the security-training checks exactly the same way — one straggler, one failed check for everybody.
- If nobody has installed the agent, the device checks sit at Pending, not Failed. That's the easy one to miss, because nothing looks broken. Once at least one device reports in, the checks start returning real verdicts — and then a single failing check on a single machine fails that check for the organization.
Chase the last three people. It's not tidiness; it's the difference between a check that passes and one that doesn't.
