Desken is a program that runs on your own machine. You build the workflow on a canvas — from material to finished text, with documentation checks and a human approval along the way. This page can be read front to back as an introduction, or looked up when something gives you trouble. Reading time front to back: about 25 minutes.
The app has its own short manual: ⋯ MORE → ❓ Manual and help. The keyboard shortcuts sit behind ?.
Desken is a workstation for communications work where claims have to stand up to scrutiny. You gather your material, let an AI model write a draft from that material, have every claim checked against it, and approve the text as a human before it goes out.
Desken is not an AI service. We run no server and have no model of our own. You connect the AI providers you want to use with your own keys, and the calls go straight from your machine to the provider. That also means you pay the provider for what you use — and that you decide who gets to see your material.
The app is available at desken.dk/hent. Desken is in closed beta, so downloading requires an access code from whoever invited you.
The Mac build is signed and notarised with Apple, so it opens without warnings. Drag Desken into Applications and start it from there.
The Windows build is still in development and is not signed yet. Windows therefore warns about an “unknown publisher”: click More info → Run anyway. With Smart App Control switched on in Windows 11, the file is blocked outright. During the beta we recommend the Mac build.
The app keeps itself up to date. It looks for a new version when it starts and every six hours after that, downloads it in the background and then asks whether you want to restart now or later. The update is installed when the app closes. Your projects are not affected.
The first time you open Desken, you create a user with a name and an email address. There is no password and no PIN in the desktop app — your computer's own login is the access control.
The name and email are sent to the publisher and used for one thing: the list of who is using the beta, so you can be told about new versions. Nothing from your projects goes with them. You are not creating an account with us, and there is nothing to log in to. The details are on the privacy page.
The name is used in one place inside the program as well: it appears on the approvals you make, so it can be seen who signed off on a text.
Without at least one API key, the AI nodes cannot run. The fields are under ⚙ Settings → API KEY.
Desken can use:
Press 🔌 Test connection after entering a key, so you know it works before you build anything on top of it.
Keys are encrypted with your computer's own keychain — Keychain on Mac, DPAPI on Windows — and stay on the machine. They are never sent to us. If the app's signature changes (which happens with a larger update), keys encrypted with the old one can no longer be read and have to be entered again. That is the keychain refusing, not the app.
Every new project starts in the New task guide. It has three steps:
The guide also has a tick box, Also check claims against the web, which is ticked by default. Desken then adds an external check alongside the check against your material (see section 11). If the text is under embargo, untick it. The box cannot be ticked without a Gemini key, or when data protection is set to Offline.
You then choose the name and location of the project folder, and an AI model builds the workflow on the canvas from your description. With a local model this can take a couple of minutes.
If you would rather start from the fixed workflow, choose Use the standard workflow instead. And ⬜ TEMPLATE opens a gallery of ready-made workflows — the full flow and smaller templates for things like a PDF, an interview or social media. Your own canvas can be saved there as a template too.
The colour follows the status of the data, so you can see trustworthiness flow through the workflow:
| Blue | raw source — unprocessed text or data |
| Yellow | AI-generated and not yet verified |
| Green | verified, or approved by a human |
| Red | flagged — an error, or a check found problems |
| Purple | media: image, audio or video |
| Grey | no data yet |
▶ RUN NODE in the right-hand panel runs the selected node on its own. ▶ RUN FLOW at the top (⌘↩) runs every connected node in the right order, shows progress and turns into a red ■ STOP if you want to interrupt it. If a node is out of date — because the material, the prompt or the model has changed since it last ran — ↻ OUT OF DATE runs just those and everything downstream.
When you select a node, the right-hand panel shows What does this one do?: what the node is for, and what it is missing before it can run — for instance that a check has no material to hold the text up against, that a web search has no Gemini key, or that an export has no approval in front of it. The panel opens by itself when something is wrong, so you see it before you pay for a run. It uses no AI and fixes nothing on its own. If the workspace has renamed the node, its name in the node catalogue is shown too, so you can look it up in the manual.
The 💬 ASK ABOUT THE CANVAS button in the bottom right-hand corner opens a chat about your workflow. It is also under ⋯ MORE and on ⌘K. Ask about whatever is giving you trouble: why a node can't run, what is missing before export, or which node to use for a task.
If the canvas is empty, the chat points you to the New task guide, which can build the workflow for you. The chat can be made larger with the handle in its top left-hand corner; double-click it for the default size.
With 🎙 next to ASK you can speak instead of typing. It needs a Groq or OpenAI key for the transcription. The answer is read aloud in a natural voice from ElevenLabs if you have an ElevenLabs key (the voice is chosen in Settings), otherwise from OpenAI, and otherwise by your computer's own voice. You can ask questions, ask it to run, open or export something, and say “yes” or “no” to a suggestion.
{{input}} in a text value — for example {"field": "{{input}}"}, where “field” is the name the server uses (see them with SHOW AVAILABLE TOOLS/RESOURCES) — it is replaced with the text from the nodes connected into the MCP node; an AI node can then write the search terms and the MCP node searches for them. With no input, the node stops with an error.http:// address, Desken asks first and offers https instead. Over http, anyone between your machine and the server can both read and alter the material on the way, leaving no trace in the text. Your approval covers that exact address — edit the path and you are asked again.
A workspace is the frame every node in the project works within. Desken ships one ready-made: 📣 Communications. It names the nodes the way a communications department does (Press release, Documentation check, External check, Approval, Spokesperson, Channel pack) and puts fixed rules into every production and output node.
The rules in the communications workspace include:
[NO EVIDENCE: what needs to be obtained] rather than phrasing it anyway.The workspace has four empty fields for you to fill in: About us – boilerplate, Key messages, Banned words and phrases and Tone of voice – excerpt. They are added to every text as standing guidance. They ship empty on purpose: a workspace must never put invented house material into a sender's mouth. An empty field affects nothing.
The workspace also holds ready-made layouts — press release, briefing note and Q&A, customer story, newsletter — with the structure a communications department already uses, and ready-made prompts, among them Risk check: five critical readers at once (the journalist, the competitor, the specialist, the citizen and the employee).
A workspace is a file. You can edit it, save your own and share it with a colleague.
The draft is written by the model you chose on the node — from the material the node is connected to, and the rules the workspace puts in. When you pick a model per node, there is no hidden shared model behind it: if the node says Claude, Claude is what ran.
Where the material doesn't reach, a visible gap is left — [NO EVIDENCE] — rather than a guess. Those gaps are meant to stay there until you have obtained the evidence.
The Documentation check (called Fact-checker in the journalism workspace) reads the text against the material it is connected to and marks every claim:
| Documented | the claim is in the material — with a reference to where |
| No evidence | the material neither confirms nor contradicts it |
| Contradicted | the material says something else |
The External check goes to the web instead: one search per claim and a verbatim quote from the source. It requires a Gemini key, and it sends a short search string per claim — not the text and not the material. That is why web search is approved separately under Data protection: a department with a data processing agreement covering its text model should be able to say yes to search without saying yes to everything.
Put several checks on the same text, each with its own model. Where they agree, you are on firm ground. Where they disagree is where you should look. The ⚖ Consensus matrix (under ⋯ MORE) shows every check side by side, claim by claim. Rows where the models disagree are highlighted. Expand a row to see each model's exact verdict.
Approval (Human review in the standard workspace) is the fixed control point. Double-click the node: every point raised by the checks appears as a checklist on the left, and the final text is on the right, where you edit it. Each point is marked ✓ Handled or ✗ Rejected — including when it is the model that got it wrong.
Every time you press SAVE in the text editor or in Approval, a version is saved on the node itself. The HISTORY tab lists the versions with the time, the word count, who saved it and whether the text was approved. Select a version to see what has changed since.
RESTORE puts an older text back in the editor. It isn't saved until you press SAVE — and then it becomes a new version, so nothing is lost. The history lives in the project file and moves with the folder. Each node keeps its latest 30 versions; the history does not follow a node when it is duplicated or saved as a template.
A finished flow can be shown as a small tool: a couple of fields, a Run button and a result — with no canvas. It is for the colleague who needs to use the workflow but not build it.
In the app, you fill in the fields and press ▶ Run. The result can be copied or saved as Markdown, and the check's verdicts are one click away. If anything is missing before the flow can run — a key, a search query, an MCP address — the app says so before you press Run. Edit on the canvas switches back. If you want the project to open straight into the app, tick Open the project directly in the app.
Under ⚙ Settings → DATA PROTECTION you decide where your material may be sent when AI nodes run. The current mode is always shown in the top bar, so you can see it without opening settings.
| Mode | What may run |
|---|---|
| 🌐 Open | All the providers you have set up with your own keys. |
| 🔐 Approved providers only | Only the providers you have ticked — for instance the ones you have a data processing agreement with. Web search is ticked separately. |
| 🛡 Offline | No content leaves the machine. Only local Ollama models may run; cloud AI, web search and the external check are blocked. |
URL import, API import and the MCP connector bring data in and are not affected by the mode. If a node tries to use a provider that isn't permitted, it stops with a message explaining why — it does not run half-way. The same goes for the canvas chat.
Under ⚙ Settings → BETA & FEEDBACK there are two options, both switched off until you switch them on yourself:
Behind a firewall, on a train or in Offline mode, the following works as normal:
The following needs a connection:
A project is a folder on your own disk, in a location you choose. The folder holds the project file together with kilder/ (sources) and eksport/ (exports). The paths are relative, so the whole folder can be moved, archived or handed to a colleague.
Large files are not copied needlessly: a big video is added in an instant and does not take up space twice when the disk allows it.
Press ? in the app for the full list. On Windows, ⌘ is Ctrl.
| Key | Does |
|---|---|
| ⌘K | Command palette / add node |
| ⌘F | Search in nodes and output |
| ⌘↩ | Run flow |
| ⌘S | Save project |
| ⌘Z / ⌘⇧Z | Undo / redo (on Windows Ctrl+Z / Ctrl+Y) |
| ⌘A | Select all nodes |
| ⌘C / ⌘V / ⌘D | Copy / paste / duplicate selection |
| Delete | Delete selection, connection or zone |
| Esc | Clear selection, close panels |
| ← ↑ → ↓ | Move the selection to a neighbouring node |
| Enter / double-click | Open the node's editor |
| Drag a file in | Create a PDF or image node |
| Drop a node on a connection | Splice it in between two nodes |
| ? | This list |
There is no key for the provider the node uses. Enter it under Settings and press Test connection.
The node is missing something before it can run: a Gemini key, a search query, an MCP address or a chosen tool. Look under What does this one do? on the node — or, in the app view, at the list of what is missing before the flow can run.
If the material is connected directly to the check, it is checked against itself. Remove the connection and connect only the text; the check finds the material by itself further up the flow. See section 11.
Data protection is set to Approved providers only or Offline. Approve the provider, change the mode, or pick a model that is allowed to run.
If the app's signature changes, your computer's keychain can no longer read what was saved with the old one. Enter the keys again. This does not happen with ordinary updates.
Check three things: that the file is under 25 MB, that OpenAI or Groq is permitted under Data protection, and that you are not in Offline mode.
The project was saved with a newer Desken than yours. Update the app — the file has not been touched in the meantime.
The chat uses the model shown at the top of it. If there is no key for that model, add one under Settings or pick another model. In Offline mode only a local model answers.
It reads the answers from the check nodes. If you have edited a check's prompt so that it no longer answers in the form the matrix reads, there is nothing to show. Put the prompt back, or run the check again.
The material, the prompt or the model has changed since the node last ran. This is not an error — it is a reminder that the result no longer matches what is above it. ↻ OUT OF DATE runs just those nodes and everything downstream.
The Windows build isn't signed yet. More info → Run anyway. With Smart App Control switched on in Windows 11 it cannot be run at all; use the Mac build during the beta.
Send a report with ⋯ MORE → 💬 Send beta feedback. It opens an email with the version and operating system filled in — write what you tried, what happened and what you expected.
Write to hej@grumpyproductions.dk. It is the same address for bugs, questions, requests and for being taken off the list again.
It saves a round trip if the email contains:
Desken is in closed beta and is built by one person. We therefore promise no particular response time yet — and we would rather say so plainly than publish a number that won't survive a week of teaching. Urgent problems — the app won't start, or a project won't open — go first. A response time will be published when sales open, along with a data processing agreement.
This page describes Desken as the program actually works — not as it is planned to work. If you find something here that doesn't match, that is a mistake on the page, and we would like to hear about it.