# How do we install firm os?

> Name the firm and its people, press Allow on a Cloudflare page for one account, and firm os is installed there in about two minutes.

Give the firm's name and who is in, then press Allow on a Cloudflare page for one account. About two minutes later firm os answers at that account's workers.dev address, behind sign-in with email codes.

## What you need

- A Cloudflare account on **Workers Paid**, $5 a month, paid to Cloudflare. The install checks this first and stops if the account isn't on it.
- A person signed in to that account who can press Allow.
- Sign-in through Cloudflare Access, free for up to 50 people. Everyone who signs in counts, including people let in by the firm's email domain.

## The steps

1. Give the firm's name and who is in: each person's email and role. At least one of them is an admin, who runs the settings.
2. Press Allow on the Cloudflare page, and tick **one** account. If the Allow covers several, the installer asks which one.
3. Watch the install's own page for about two minutes. If a step stops, the page says why and offers **Try again** until an hour after the Allow.

## What it makes

Everything is named after the firm: `acme capital` becomes `acme-capital`.

| Kind | Name | Role |
| --- | --- | --- |
| Worker | `acme-capital` | The router: what people open, with the web app at `/firm/` |
| Worker | `acme-capital-workshop` | Cloudflare OS's Workshop, which runs the workspaces |
| Worker | `acme-capital-context` | The context store |
| Worker | `acme-capital-scheduler` | The scheduler |
| Worker | `acme-capital-desk` | Each person's private desk |
| Worker | `acme-capital-jev` | Jev, which labels records |
| Worker | `acme-capital-partners` | The data partners: people and company facts with the firm's own key |
| Worker | `acme-capital-custom` | An example gatekeeper, turned off when the first admin signs in |
| Worker | `acme-capital-errors` | The error reporter |
| Key-value stores | `acme-capital-blueprints`, `acme-capital-avatars`, `acme-capital-context` | Blocks, avatars, context collections |
| R2 bucket | `acme-capital-blueprint-content` | The blocks' files |
| Access app | `acme capital firm os` | Guards the address. Its rule lets in everyone at the firm's email domains and each named person outside them |

If the account already has one of these names, the install stops before making any of them, so nothing the account already had is taken over or later removed.

## What it adds only if missing

These are the account's own setup, which other things may use, so removing firm os keeps them.

- A workers.dev name, registered after the firm.
- A Zero Trust team, named after the firm. An existing team is never renamed.
- Sign-in with email codes.
- An AI Gateway named `default`, which chat uses. One the installer makes has its logs on.

## First sign-in

When the install is done, the install's own page links to the firm's address. Open it, give your email, and type the code Cloudflare sends; a sign-in lasts 24 hours. The first admin to sign in sees firm os set itself up for the firm.

Keep the install's own page: it is where you [remove firm os](https://firmos.railblocks.com/docs/remove). The installer installs its current release and hands its key back, so it never changes the install afterwards.

Updated 2026-10-02.
