User Guide
RangerIO current public beta release · Reviewed August 4, 2026
Chapter 01 · Start
Welcome to RangerIO
RangerIO current public beta release. Last reviewed August 4, 2026. This guide includes only behavior verified in the current product.
RangerIO is a desktop data-intelligence and sanitization tool for working with files that may contain sensitive information. It imports supported files, builds a local structured profile called a dossier, scans for potential PII, provides review and correction tools, supports local analytical questions, and prepares sanitized or tokenized context for explicitly enabled AI workflows.
In everyday terms, RangerIO helps you open a work file, understand what is in it, check it for sensitive information, ask questions about it, and prepare an output for review or sharing.
What do you need to do?
| I need to… | Start here | Workflow |
|---|---|---|
| Bring in a spreadsheet, document, or group of files | Data | Import one or more files |
| Check whether a file contains personal or sensitive identifiers | Data → select the file → Privacy | Review a structured source or review a document |
| Correct something RangerIO marked incorrectly | Privacy | Dismiss, confirm, reclassify, or mark a value, then re-scan |
| Create a copy with detected sensitive values hidden | Document preview or Export | Export a masked document or standard data export |
| Ask for a total, list, comparison, or summary | Assistant or Data → Use in Chat | Start a data question |
| Turn one or more files into a draft report | Export → AI Assisted | Generate an AI-assisted report |
| Use a separately running local AI or a cloud AI service | Models | Configure an AI engine |
| Use RangerIO from Claude Desktop | Settings → Connectors | Configure Claude Desktop |
| Repeat a review for a new client, month, or reporting period | Data → Actions | Repeated engagement workflow |
A good first workflow
you want to learn the product with one representative file before importing an entire engagement.
choose a supported file that you are authorized to use. If possible, begin with a copy rather than your only copy of the file.
- 1Open Data.
- 2Choose Actions → New Project and create a clearly named project.
- 3Choose Import → Files.
- 4Add one file.
- 5Review the detected structure and selected columns.
- 6Choose the project and select Start Import.
- 7Wait for the import task to finish.
- 8Select the imported file on Data.
- 9Open its preview and then Privacy.
- 10Review the scan state and any marked values.
- 11Correct findings if needed and choose Re-scan now.
- 12After the file is ready for the intended task, choose Use in Chat or continue to Export.
the file appears in the correct project, its detail view is available, and you understand both its readiness state and its privacy-scan state.
open the task panel, read the failed or interrupted task, and use the recovery procedure in “During import.” Do not keep importing duplicate copies while an earlier task is still active.
RangerIO is not only a chat interface. The data engine operates before a model is involved:
- 1A source is imported.
- 2RangerIO examines its structure.
- 3Local profiling and indexing build reusable intelligence.
- 4PII scanning records findings and coverage.
- 5The user reviews the source and scan state.
- 6The user can query, report, mask, or export the source.
- 7A local, cloud, or MCP model path is used only when the selected task requires it and that path is available.
RangerIO and RangerIO Plus
| Capability | RangerIO | RangerIO Plus |
|---|---|---|
| --- | --- | --- |
| Import, profile, PII scan, sanitize, quality analysis, and export | Included | Included |
| Dossier, local analytics, question routing, reports, and privacy review | Included | Included |
| Connect a configured external local provider | Included | Included |
| Connect a configured cloud provider | Included; opt in | Included; opt in |
| Local MCP server and connector controls | Included; opt in | Included; opt in |
| Bundled local llama.cpp/GGUF runtime | Not included | Included |
| RangerIO-managed local-model setup and selection | Not included | Included |
In one sentence: RangerIO provides the complete data engine and lets you connect an AI provider. RangerIO Plus adds RangerIO's bundled local-model runtime. Unless a section says otherwise, the data, privacy, dossier, report, and export workflows apply to both products.
RangerIO Enterprise
RangerIO Enterprise is a licensing tier, not a separate product. It runs the same data engine, privacy workflows, and export paths described in this guide, and adds two things for organizations: centralized management for multi-seat deployments, and fully supported database and REST API data sources alongside file imports.
- Centralized management for deployment, configuration, and policy across many workstations.
- SQL database sources as a supported, fully backed import path.
- REST API sources as a supported, fully backed import path.
- Full support for the organizations running these connected sources.
Enterprise licensing is expected to begin shipping in early 2027 and is available on request today. Database and REST API sources are not usable in the current public beta of the desktop product. For more information on our Enterprise version, please contact info@rangerio.com.
What you can do in both products
- Create projects and project groups.
- Import individual files, multiple files, or selected files from a directory.
- Inspect import tasks and recover an interrupted import.
- View source structure, preview data, and inspect dossier intelligence.
- Review PII findings in tables and documents.
- Mark missed sensitive values, dismiss false positives, reclassify findings, and re-scan.
- Ask questions against one or more ready sources.
- Review grounding, confidence, coverage, and data-quality caveats when supplied with an answer.
- Export data, reports, and supported masked document copies.
- Enable the local MCP server and configure the current Claude Desktop connector.
Where the products differ
RangerIO requires a configured external local or cloud model for model-assisted work. Local dossier lookups and local analytical routes can still operate without a bundled LLM.
RangerIO Plus includes RangerIO's local llama.cpp/GGUF runtime and RangerIO-managed model setup. Selecting that local runtime keeps model inference on the workstation. Cloud and MCP paths remain optional in RangerIO Plus.
Before relying on an output
A completed import, a “Ready” status, a PII scan, a masked export, or an AI answer is not a certification. Review consequential outputs against the source material and your organization's policy.
Terms you will see
| Product term | Plain-language meaning |
|---|---|
| **Project** | A workspace that groups the files for one client, matter, review, or period. It is not the same as a folder on your computer. |
| **Source** | RangerIO's working record for a file or workbook sheet you imported. |
| **Dossier** | The reusable file profile RangerIO builds: structure, statistics, quality signals, sensitive-data findings, and other available context. |
| **PII** | Personally identifiable information: values that may identify or relate to a person. The legal definition depends on the jurisdiction and context. |
| **Severity** | How risky the findings that were detected may be. |
| **Coverage** | Whether the privacy scan finished sufficiently. It does not mean the file is clean. |
| **Ready** | The inputs needed for a particular action are available. It is not a guarantee that the source or result is correct. |
| **AI provider** | The local server or cloud service used for tasks that need a generative AI model. |
| **MCP connector** | The optional connection that lets Claude Desktop request approved RangerIO tools. |
Chapter 02 · Start
Why RangerIO Exists
Professional work often starts with files that should not be pasted directly into a general-purpose AI chat: contracts, employee files, accounting workbooks, research exports, operational records, and other client material.
RangerIO separates preparing and understanding the source from choosing an AI engine.
The practical problem
Without a preparation layer, a user has to decide between:
- doing the work manually;
- sharing more source content than intended;
- manually removing identifiers;
- rebuilding the same context in every new AI conversation; or
- using an AI answer without a reusable, inspectable source profile.
RangerIO addresses this by building reusable local intelligence first.
The operating model
Local preparation
The data engine imports, profiles, indexes, scans, and stores working intelligence locally.
Explicit model choice
The user can use:
- local dossier lookup or analytics;
- a configured external local provider in RangerIO or RangerIO Plus;
- the bundled local runtime in RangerIO Plus;
- an explicitly configured in-app cloud provider; or
- an explicitly enabled MCP connector.
Review before disclosure
The user reviews scan coverage, findings, masking, and the organizational rules that apply to the data.
The product boundary
RangerIO reduces preparation work and provides safety controls. It does not make an otherwise prohibited disclosure permitted, replace legal review, or guarantee that every sensitive value will be detected.
Chapter 03 · Start
How RangerIO Works
End-to-end workflow
- 1Select a source
- 2Inspect structure
- 3Import, profile, and build the dossier
- 4Complete and review privacy coverage
- 5Analyze, report, or mask
- 6Export locally or explicitly use an external AI path
Step 1 — Select and inspect
For file imports, RangerIO performs a light structure scan before the full import:
- tabular files can show detected columns and an initial row count;
- documents can show extracted document structure;
- files that cannot be inspected show an error before the import proceeds;
- the user can remove a file or inspect its preview;
- for supported tabular files, the user can choose which columns to retain.
This structure scan is not the final PII scan.
Step 2 — Import, profile, and build the dossier
The import pipeline creates the working source and builds available intelligence such as:
- source identity and format;
- schema and inferred types;
- row, column, or document-structure information;
- column statistics;
- searchable chunks and embeddings where applicable;
- data-quality signals;
- entities and domain intelligence where available; and
- task and readiness state.
The interface remains responsive while longer work runs in the task system.
The dossier is built from this profiling work. Privacy processing can continue as a separate pipeline stage, so do not present these as one indivisible completion state.
Step 3 — Privacy coverage
Import completion and PII-scan completion are separate states. A source may be imported while its Privacy Scan is still pending, incomplete, or degraded.
Step 4 — Review readiness and correct findings
Open the source detail and privacy views after processing. Review structure, data-quality signals, PII coverage, and findings. Correct false positives or missed values and re-scan when required. A refresh can rebuild the source's current profile; a privacy re-scan refreshes detection and coverage.
Step 5 — Route the task
| Task | Local data engine | Model needed? |
|---|---|---|
| Read schema or row count | Yes | Usually no |
| Run a local analytical query | Yes | Not always |
| Produce an interpretive answer | Yes, for context | Yes |
| Review or correct PII | Yes | Scan components may use models, but user review remains required |
| Export data | Yes | No for standard data export |
| Generate an AI-assisted report | Yes, for source context | Yes |
| Use an MCP host | Local connector plus host | Yes, in the external host |
Local and external model paths
| Path | RangerIO | RangerIO Plus | Data-handling note |
|---|---|---|---|
| Bundled local model | Not included | Included | Model inference stays on the workstation |
| External local provider | When configured | When configured | Provider must be reachable from the workstation |
| In-app cloud provider | When configured | When configured | Outbound masking and validation apply |
| External MCP host | When enabled | When enabled | Tool results return through the host and stay sanitized/tokenized |
Important distinction: in-app cloud vs. MCP
For an in-app cloud call, RangerIO can mask outbound values and rehydrate supported response values locally.
For an external MCP host, public rehydration is blocked because an MCP tool result is sent back through that host's conversation context.
Chapter 04 · Start
System Requirements & Installation
Current desktop builds
- macOS: Apple Silicon, arm64
- Windows: x64
Startup requirements
| Component | RangerIO | RangerIO Plus |
|---|---|---|
| RAM | 8 GB minimum | 16 GB minimum |
| Free storage | 5 GB minimum | 5 GB minimum, plus space for local models |
| CPU | 4 cores minimum | 4 cores minimum |
| Disk | SSD required | SSD required |
Actual working capacity depends on source size, file complexity, selected models, and other applications using memory.
Install on Windows
- 1Download the current Windows x64 installer for the correct product.
- 2Run the installer.
- 3Complete the installer prompts.
- 4Start RangerIO.
- 5Complete the in-app setup.
Install on macOS
- 1Download the current Apple Silicon installer for the correct product.
- 2Open the disk image or packaged installer supplied by RangerIO.
- 3Move RangerIO to Applications when prompted.
- 4Start RangerIO.
- 5Complete any macOS security prompt and the in-app setup.
First launch
Both products initialize the local data engine and inspect available resources.
RangerIO
- The data engine is available without the bundled llama.cpp runtime.
- Configure an external local provider or cloud provider when model-assisted work is required.
- Provider configuration is separate from file import.
RangerIO Plus
- Includes the bundled local runtime.
- RangerIO-managed local-model setup is available.
- Model readiness is separate from data-engine readiness.
If a model is unavailable, users can still work with the data engine where the selected function does not require that model.
Configure an AI engine
Import, profiling, privacy review, local analytical queries, and standard exports do not all require a generative model. Chat interpretation and AI-assisted reports do require an active engine. Configure engines from Models, not from the Connectors area.
#### Which model option fits your situation?
| Your situation | Use | What to know |
|---|---|---|
| You only need to import, inspect, review privacy findings, run supported local analysis, or export standard data | Continue without configuring a generative model | A later feature may tell you when a model is required |
| Your organization already runs Ollama, LM Studio, vLLM, or another compatible local server | **Local LLM Server** in either product | The separate server must be running and reachable from the workstation |
| You have RangerIO Plus and want RangerIO to manage a downloaded local GGUF model | **Download Model** | This lane is available only in RangerIO Plus |
| Your organization permits an external AI service and you have its credentials | **Cloud / API** | Model context is sent to the configured provider under that provider's terms; review the trust disclosure |
Lead with where model processing occurs and who operates that AI service.
The Models page has three lanes:
| Lane | RangerIO | RangerIO Plus | Purpose |
|---|---|---|---|
| **Download Model** | Not available as a bundled-runtime workflow | Available | Download and run a GGUF model with RangerIO's bundled runtime |
| **Local LLM Server** | Available | Available | Connect a separately running local server such as Ollama, LM Studio, or vLLM |
| **Cloud/API** | Available | Available | Configure an explicitly chosen remote provider |
#### Connect a detected local LLM server
- 1Start the local LLM server and load at least one model in that server.
- 2Open Models.
- 3Choose Local LLM Server.
- 4Review Local LLM servers for detected endpoints.
- 5Choose Connect beside the running server.
- 6Confirm that the provider appears in Saved Configurations or as the active model.
If no server is detected, choose Configure beside a known server or enter a custom endpoint, then choose Test & Connect. The local server is a separate application or service; RangerIO does not install or manage it.
#### Connect a cloud/API provider
- 1Open Models.
- 2Choose Cloud/API.
- 3Select the provider type offered by the interface.
- 4Enter the endpoint when the provider requires a custom endpoint.
- 5Enter the API key.
- 6Wait for the provider's live model list, then select a model. If the provider cannot return a list, enter only a model identifier confirmed by that provider.
- 7Enter a configuration name.
- 8Choose Test Connection.
- 9Choose Save & Connect after the test succeeds.
- 10Confirm the new entry is Active under Saved Configurations.
Provider credentials, charges, retention, and contractual terms belong to that provider.
#### Switch, edit, or remove a saved configuration
- 1Open Models.
- 2Find Saved Configurations.
- 3Choose Activate to switch to a different saved configuration.
- 4Use the edit control to change its endpoint, model, name, or key, then choose Save Changes.
- 5Use the delete control only when the configuration is no longer required.
Deleting a provider configuration does not delete imported sources.
#### Use the bundled local runtime in RangerIO Plus
- 1Open Models.
- 2Choose Download Model.
- 3Select a model offered by RangerIO or provide a supported download URL when that control is available.
- 4Choose Download.
- 5Follow download progress in the task interface.
- 6After the model is present, select or activate it from the model list.
- 7Confirm that the active-model strip reports the intended local model before starting model-assisted work.
Working-data location
RangerIO uses a local data directory under the signed-in user's home directory. The current engine uses RangerIO_local as its local working directory. Imported working data, indexes, metadata, registries, logs, and audit information can be present there.
Updates
The packaged desktop app checks for updates. Automatic download is disabled, so the user is asked before a package is downloaded.
Troubleshooting startup
If RangerIO cannot start a required component:
- 1Read the displayed readiness or backend message.
- 2Close memory-heavy applications if the system is low on RAM.
- 3Retry the action.
- 4In RangerIO Plus, verify that the selected local model is available.
- 5In RangerIO, verify that the configured external provider is reachable when a model is required.
- 6Open Support from the application header if the issue persists.
- 7Choose Generate Report.
- 8Review the diagnostic report, choose Copy Report, and send it to RangerIO support only after checking what it contains.
Chapter 05 · Work with data
Bringing Data In
This chapter must be a full in-product workflow, not a format list.
Projects and project groups
A project organizes related sources for an engagement or analysis. A project group organizes multiple projects.
#### Create a project
- 1Open Data.
- 2Open Actions.
- 3Choose New Project.
- 4Enter a project name.
- 5Choose Create.
#### Create a project group
- 1Open Data.
- 2Open Actions.
- 3Choose New Project Group.
- 4Enter the group details.
- 5Save the group.
- 6Move related projects into it when needed.
Verified import formats in the current release
Tabular and structured
- CSV
- TSV
- XLS
- XLSX
- XLSM
- JSON
- JSONL
- Parquet
Documents and text
- DOCX
- PPTX
- HTML
- TXT
legacy .doc and .rtf. Convert them to a verified format first.
Import one or more files
- 1Open Data.
- 2Choose Import.
- 3Select Files.
- 4Add files with the file picker or drag files into the import area.
- 5Wait for the light structure scan.
- 6Review every file's status.
- 7Remove files that should not be imported.
- 8Open a file preview when structure needs confirmation.
- 9For a supported table, confirm the selected columns.
- 10Choose a project or create a project from the import flow when available.
- 11Leave Domain on Auto-detect or choose the correct domain.
- 12Choose a Reporting Profile when a relevant profile is available.
- 13Add Key Notes when the future analysis needs context. Example: “Q4 audit data; focus on vendor transactions above $10,000.”
- 14Choose Start Import.
- 15Follow progress in the task panel.
The Domain, Reporting Profile, and Key Notes fields guide later intelligence and reporting. They do not change the source data.
Drag files directly onto Data
The Data page accepts file drag-and-drop. Dropped files open the import workflow with those files staged. The user must still review the staged files and start the import.
Import selected files from a directory
This is a selectable directory import, not continuous directory watching.
- 1Open Data.
- 2Choose Import.
- 3Select Directory.
- 4Choose the directory path.
- 5Select the file types to discover.
- 6Choose whether to include subdirectories.
- 7Set the maximum directory depth when shown.
- 8Choose Scan Directory.
- 9Review the discovered files.
- 10Filter the list by file type when useful.
- 11Use Select All, Deselect All, or select individual files.
- 12Choose Continue with N files.
- 13Follow the resulting import tasks.
Database and API cards
The current import interface may show SQL Database and REST API source cards, but their public import action is not wired as a complete workflow and displays Coming Soon.
Database and REST API import are not documented as working public workflows in the current release of the desktop product. They are part of RangerIO Enterprise licensing.
Database and REST API sources are delivered through RangerIO Enterprise licensing, together with centralized management and full support for connected sources. Enterprise licensing is expected to begin shipping in early 2027 and is available on request today.
For more information on our Enterprise version, including database and API data sources and centralized management, please contact info@rangerio.com.
During import
The task system reports current work and can show partial, interrupted, paused, failed, or completed states.
If an import is interrupted after a restart:
- 1Open the banner on Data or the task panel.
- 2Choose Resume to continue when resources permit.
- 3In the Data banner, choose Dismiss to remove the banner without resuming. In the task panel, use Cancel Task when the interrupted task should not continue.
- 4If Resume is refused because memory is low, close other applications and retry.
What appears after import
A source row and detail pane can show:
- source name and format;
- project placement;
- row or document information;
- indexing or dossier readiness;
- privacy severity;
- privacy coverage;
- data-quality and structure warnings;
- PII count or unscanned state;
- refresh, chat, export, move, and delete actions when available.
The Data toolbar also supports:
- search;
- status/type/severity filters;
- selecting one or more sources;
- Use in Chat for selected ready sources;
- refresh and move actions; and
- deletion.
Source status
Use these concepts carefully:
- Ready: the inputs required by that feature are available.
- Needs attention: a warning, incomplete process, or uncertain structure requires review.
- Failed: the relevant process did not complete.
- Unscanned: the PII scan has not completed.
- Degraded / Unverified: PII findings may be real, but scan coverage is incomplete.
A source can be analytically ready while its privacy coverage still needs attention.
Excel workbooks
A supported workbook can produce related sheet sources and a workbook-level relationship. Users should:
- 1Open the workbook or relevant sheet in Data.
- 2Review sheet-level row, schema, quality, and PII information.
- 3Use the specific sheet when a question or export must be sheet-scoped.
- 4Use the workbook context only when cross-sheet aggregation is appropriate.
- 5Verify source attribution in answers and reports.
Refresh a source
- 1Open Data.
- 2Select the source.
- 3Use its refresh action, or select sources and use Refresh selected.
- 4Follow the task state.
- 5Re-open the source detail.
- 6Review structure, intelligence, and PII coverage again.
A refresh re-imports and re-profiles the source.
Delete a source
- 1Select the source.
- 2Choose Delete or Delete Selected.
- 3Confirm the exact source or sources.
- 4Verify that the correct project remains.
Deletion removes RangerIO's working records for the selected source. It does not delete the original external file.
Chapter 06 · Work with data
The Dossier
What a dossier is
The dossier is RangerIO's reusable structured understanding of a source. It is built from import and profiling work and used by source details, questions, reports, and connector tools.
A dossier is not a second copy of the original document for human reading. It is a structured intelligence layer.
What can appear in a dossier
Depending on the source and completed processing:
- source name, format, size, and timestamps;
- row, column, page, paragraph, or document-structure information;
- schema and inferred types;
- per-column statistics such as missingness, uniqueness, common values, and numeric summaries where applicable;
- data-quality and parsing-confidence signals;
- detected entities;
- PII findings and scan coverage;
- searchable chunks and retrieval metadata;
- domain and reporting-profile context;
- readiness, degraded, or blocked state;
- workbook/sheet attribution; and
- provenance used by questions and reports.
Not every field is available for every format.
Open a dossier/source detail
- 1Open Data.
- 2Search or filter for the source.
- 3Select the source row.
- 4Review the detail pane.
- 5Open the data or document preview for row-level or text-level context.
- 6Open the privacy view when PII findings require review.
- 7Use Use in Chat or the chat action only after the source is ready for the intended workflow.
Readiness contract
| State | Meaning | User action |
|---|---|---|
| Ready | Required inputs for the current feature are available | Continue, but still review the output |
| Degraded | Some inputs are incomplete or uncertain | Read warnings and decide whether to refresh or re-scan |
| Blocked | Required inputs are unavailable | Complete the missing import, scan, model, or configuration step |
| Unscanned | Privacy coverage is unknown | Run the Privacy Scan before treating the source as reviewed |
A Ready status does not certify the underlying data, the completeness of PII detection, or an AI answer.
When the dossier changes
The dossier can change when:
- a source is imported;
- a source is refreshed;
- structure or intelligence is rebuilt;
- PII findings or overrides change;
- a PII re-scan completes; or
- a source is processed with updated product components.
After any material change, re-open the warnings and readiness indicators before exporting.
Data-quality signals
RangerIO can surface structure confidence, missingness, anomalous values, normalization issues, and other data-quality context depending on the source and operation.
For analytical answers, caveats can be operation-aware. For example, a total over a materially incomplete column can carry a missingness warning.
A missing warning is not proof that the data is clean.
Chapter 07 · Work with data
Privacy Scan
This chapter should contain separate workflows for structured tables and documents.
What the Privacy Scan does
RangerIO scans supported structured and document content for potential sensitive values. Detection can combine machine-validatable patterns, model-detected entities, prior user marks, and stored corrections.
The public review experience uses these labels:
| Label | Meaning |
|---|---|
| **Verified** | Matched by a machine-validatable rule |
| **AI-detected — needs review** | Detected by the model and awaiting human judgment |
| **Marked by you** | Added by a user |
Coverage and severity are different
- Severity describes the risk level of findings that exist.
- Coverage describes whether scanning completed sufficiently.
- Unscanned is not a severity.
- Degraded · Unverified means findings may exist but the scan is incomplete.
Never present zero findings from an unscanned source as “No PII.”
Review a structured source
- 1Open Data.
- 2Select the source.
- 3Open its preview.
- 4Choose Privacy to open the findings view.
- 5Review flagged columns and the displayed type/severity.
- 6Click a PII-marked column header to inspect its current classification.
- 7
- 8Mark a value or column as PII, dismiss a false positive, or reclassify the type when the interface offers that action.
- 9Re-scan after material corrections.
- 10Recheck the source's coverage state before cloud use or masked export.
Review a document
- 1Open the document preview from Data.
- 2Choose Privacy.
- 3Read the document with scan-backed underlines.
- 4Use the class chips to focus on:
- Needs your review - Marked by you - Verified
- 1Use the previous/next occurrence controls to step through every occurrence of a finding.
- 2Click a marked value to open its correction actions.
- 3Use:
- Not PII — this value to dismiss a detected value; - Reclassify when the PII type is wrong; - Confirm as [type] for an AI-detected value; - Unmark for a value previously marked by the user.
- 1Select unmarked text in the document and choose Mark as PII when the scan missed it.
- 2Use Reading mode when you want the marks reduced to quieter gutter indicators.
- 3Finish all corrections before running one final re-scan.
Correction scope
A document correction applies to every matching occurrence represented by that correction. The correction view shows the occurrence count. Review the count before applying the action.
Re-scan and export gate
Corrections appear in the preview immediately, but masked document export uses the last complete scan.
After a correction:
- 1Read the banner explaining that corrections were applied.
- 2Choose Re-scan now when review is complete.
- 3Leave the preview open if desired; it remains usable while scanning.
- 4If re-scan fails, the corrections remain saved but detection has not refreshed.
- 5Retry the re-scan.
- 6Wait for Scanned [time] · export ready before using the one-click masked export.
When the scan is stale, the header shows Masked export paused until re-scan.
If the scan found nothing
A completed scan with no findings is not a guarantee. Review the document and use text selection to mark anything missed.
What automated detection cannot promise
- complete recall for every locale and identifier;
- perfect distinction between real and template data;
- correct classification of every organization, date, account reference, or short name;
- a legal conclusion about whether a value is personal information; or
- permission to disclose the resulting file.
Human review remains required.
Chapter 08 · Connect and share
Safe Handoff
Purpose
Safe Handoff is the set of controls used when an explicitly configured cloud or connector workflow receives RangerIO context.
In-app cloud-provider flow
- 1Read privacy state
RangerIO checks the selected source's PII coverage and current registry.
- 1Build task context
Only the context required for the question or report is assembled.
- 1Mask or tokenize detected values
Registered values are replaced with stable stand-ins where the workflow supports it.
- 1Validate outbound content
RangerIO applies its pre-egress checks. If acceptable sanitization cannot be established, the cloud call is blocked.
- 1Send to the configured provider
The user has explicitly configured this provider and is responsible for its account and terms.
- 1Receive the response
The in-app workflow can restore supported tokens locally.
- 1Show lineage and warnings
The response can include protection markings, grounding, caveats, and audit metadata.
Stable stand-ins
Stable stand-ins let repeated values remain linkable during an engagement. This can preserve relationships such as repeated counterparties without sending the original detected value.
The mapping is maintained in a local registry scoped to the engagement/project workflow.
Fail-closed behavior
If RangerIO cannot validate a cloud-bound context, the expected outcome is a blocked cloud request with an explanation—not a silent downgrade.
The user can then:
- re-scan the source;
- correct findings;
- select fewer or different sources;
- use a local provider; or
- use RangerIO Plus's bundled local runtime when available.
External MCP flow
An external MCP host is different:
- 1The host asks RangerIO to run a tool.
- 2RangerIO authorizes the tool and builds a response.
- 3PII-aware scrubbing and egress controls apply.
- 4The tool result returns to the external host.
- 5That result becomes part of the host's conversation context.
Because of step 5, RangerIO's public MCP surface blocks rehydration. The external host receives sanitized or tokenized content.
What MCP tools may return
Depending on the tool and scope:
- project and source metadata;
- dossier summaries;
- schema and quality information;
- PII summaries;
- sanitized row previews;
- sanitized analytical query results; and
- tokenized exports when the user explicitly enables that permission.
Review requirement
Masked context can still expose structure, categories, counts, excerpts, or undetected values. The user must decide whether the task and external provider are permitted.
Chapter 09 · Connect and share
Asking Questions
Start a data question
- 1Open Assistant.
- 2Choose Select a data source.
- 3Search for and select one or more ready sources.
- 4Preview the selected source when needed.
- 5Enter the question.
- 6Use
@to reference available fields where useful. - 7Send the question.
- 8Follow progress and use Cancel if the query should stop.
- 9Review the answer and its evidence signals.
Users can also select sources on Data and choose Use in Chat.
How RangerIO routes a question
RangerIO uses multiple answer paths:
- 1Direct dossier lookup
Schema, counts, known fields, and precomputed source facts can be returned without a generative model.
- 1Local analytical query / Smart SQL
Questions that map to a safe analytical query can run against the local analytics engine.
- 1Grounded model-assisted answer
Interpretive questions use a configured model with source context.
The user does not need to choose the internal route.
Example direct questions
- “How many rows are in this source?”
- “Which columns are present?”
- “Which selected sources are still unscanned?”
- “What is the inferred type of Invoice Date?”
Example analytical questions
- “Show the top 10 vendors by total amount.”
- “Count transactions by status.”
- “List records over $10,000.”
- “Compare missingness in Q3 and Q4.”
Example interpretive questions
- “Summarize the main patterns in this source.”
- “What should I review first?”
- “Explain the largest differences between these two files.”
- “Draft a cautious summary that includes the data-quality caveats.”
Multiple sources
When selecting multiple sources:
- confirm that each source is ready;
- ask a question that identifies the desired comparison or join;
- review source attribution;
- reduce the number of sources if coverage or model limits become an issue; and
- do not assume all cross-source relationships are valid without checking keys and source structure.
Evidence and honesty signals
An answer can display:
- source names;
- confidence;
- processing strategy;
- data coverage;
- a grounding badge for checked numeric claims;
- caveats for missing or anomalous data;
- a clarification request when confidence is too low;
- a warning when a response was shortened; and
- a protection label when values were masked and restored in an in-app cloud workflow.
Teach users to read these signals.
If a cloud request is blocked for privacy
- 1Read the privacy error.
- 2Select the blocked source.
- 3Use Re-scan now when offered.
- 4Review the scan and corrections.
- 5Retry only after coverage is current.
- 6Alternatively use an available local model path.
If an answer is incomplete
- ask a narrower question;
- select fewer sources;
- name the exact field or operation;
- review missingness and caveats;
- refresh or re-scan the source;
- add a related source only when it is genuinely needed; or
- calculate consequential numbers independently.
Limits of external-client answers
RangerIO can validate and sanitize its tool output. It cannot control or validate new prose that an external AI host generates after receiving that tool output.
Chapter 10 · Connect and share
Connecting to Your AI Tools
What the connector is
RangerIO includes a local MCP server that lets an MCP-compatible host request approved RangerIO tools. The server is off by default.
The current guided setup is for Claude Desktop. The protocol may interoperate with other MCP hosts, but this guide must not claim end-to-end support for another host.
Enable the MCP server
- 1Open Settings.
- 2Open Connectors.
- 3Turn on MCP server.
- 4Wait for the local connector service to start.
- 5Choose Add Connector.
Configure Claude Desktop
The wizard performs a preflight and configuration flow:
- 1Ensure Claude Desktop is installed.
- 2Close Claude Desktop if RangerIO says it is running.
- 3Review RangerIO's configuration preview.
- 4Approve the connector installation.
- 5Let RangerIO write the managed connector configuration.
- 6Relaunch Claude Desktop.
- 7Return to RangerIO.
- 8Confirm the connector status changes to Connected after activity.
The in-product wizard owns the guided setup.
Connector status
- Not configured: the connector has not been installed.
- Pending: configured and waiting for the first connection.
- Connected: RangerIO has observed connector activity.
- Idle: configured without current activity.
- Error: the sidecar or configuration needs attention.
Use Re-test to check the connector and Disconnect to remove the configured connection.
Trust settings
The MCP connector is conservative by default.
Allow tokenized export from stdio agents is off by default. When off, an agent cannot request a tokenized project bundle outside RangerIO's data directory.
When enabled:
- a trusted agent can request that export;
- detected PII is replaced with tokenized/synthetic equivalents;
- the resulting bundle still leaves RangerIO's data directory; and
- the setting should be disabled when it is no longer needed.
Disable the server
Turning the MCP server off stops the local connector service and unregisters the managed desktop connection. Use this when connector access is not required.
Chapter 11 · Connect and share
Reports & Exports
Separate standard data exports, AI-assisted reports, and masked document exports.
A. Export standard data
- 1Open Export.
- 2Select a source.
- 3Leave AI Assisted off.
- 4Review the preview.
- 5Choose one of the formats offered for that source.
- 6Configure available PII/masking options.
- 7Start the export.
- 8Follow the real progress state.
- 9Review the completion path and saved/downloaded file.
- 10Inspect the exported content before sharing it.
Format availability varies by source. The current export system supports structured formats and document/report outputs; the interface is the source of truth for the selected source.
| Selected source/workflow | Formats currently offered |
|---|---|
| Structured data export | CSV, Excel (`.xlsx`), JSON, Parquet |
| Document/text export | TXT, DOCX |
| AI-assisted report | DOCX, PDF, Excel (`.xlsx`) |
The format picker can narrow the choices further for a particular source.
B. Generate an AI-assisted report
- 1Open Export.
- 2Select one or more eligible sources.
- 3Turn on AI Assisted.
- 4Review the cloud/local model disclosure shown by the interface.
- 5Select a report template when available, or choose the report format.
- 6Add or select relevant discoveries when offered.
- 7Choose Generate Report.
- 8Let the report run in the background.
- 9Review the generated sections and any available content variants.
- 10Read missing-section, degraded, or source-unavailable warnings.
- 11Choose Download for the complete draft or Export Report for the selected variants.
Current report formats shown by the product include DOCX, PDF, and Excel where supported.
A generated report must still be reviewed for factual and professional accuracy.
Report readiness
| State | Meaning |
|---|---|
| Ready | Required source inputs for the report are present |
| Degraded | Some inputs or sections are incomplete |
| Blocked | Required inputs are missing and the report cannot proceed safely |
C. Export a masked document from the preview
- 1Open the document preview.
- 2Complete the Privacy review.
- 3Apply corrections.
- 4Run Re-scan now.
- 5Wait for export ready.
- 6Choose Export masked.
- 7Follow progress.
- 8Open the exported copy and inspect every sensitive section before disclosure.
D. Export from the PII dashboard
For supported sources:
- 1Open the PII report/dashboard.
- 2Choose the source.
- 3Review findings by type.
- 4Select the PII types to mask.
- 5Select the masking style offered by the interface.
- 6Choose Export Masked.
- 7Review the resulting copy.
Masking strategies
The standard Export screen currently offers these labels when the selected source supports them:
- None — export as-is: does not mask detected PII. This must never be described as the safe default for a sensitive source.
- **Partial (J\*\*\*n):** keeps limited edge characters and masks the rest.
- **Full (\*\*\*\*\*):** replaces all visible characters in the detected value.
- Redact: removes the detected PII from the visible output.
- Tokenize: replaces registered values with deterministic PII tokens so selected relationships can remain linkable.
Availability and behavior depend on the source and export path.
Audit trail
RangerIO records local audit information for protected operations, including connector and export activity where supported. Audit records are technical evidence of what RangerIO recorded; they are not a regulatory certification.
Chapter 12 · Examples and reference
Use-Case Workflows
Organize this chapter first by the job to be done, then by profession. A reader should not have to identify with an industry label to find a useful procedure.
Check a document and create a masked review copy
you have a PDF or DOCX file that may contain names, contact details, account information, or other identifiers, and you need a copy with reviewed findings hidden.
confirm that the document is a supported format and that you are authorized to process it.
- 1Create or select the correct project in Data.
- 2Import the document.
- 3Select the document and open its preview.
- 4Choose Privacy.
- 5Review AI-detected — needs review findings first.
- 6Use the previous and next controls to inspect every occurrence.
- 7Choose Not PII — this value, Reclassify, Confirm as [type], or Unmark where appropriate.
- 8Select any missed sensitive text and choose Mark as PII.
- 9Choose Re-scan now after the corrections are complete.
- 10Wait for Scanned [time] · export ready.
- 11Choose Export masked.
- 12Open the exported copy and compare sensitive passages with the original.
the exported copy opens successfully and you have manually checked the areas that contain or could contain sensitive information.
if the header says Masked export paused until re-scan, complete the re-scan. If re-scan fails, keep the saved corrections, retry, and do not use an older masked export as if it included the new corrections.
Ask a spreadsheet question and verify the answer
you need a total, count, ranked list, exception list, or period breakdown from a spreadsheet without writing a formula or query.
identify the sheet, fields, filters, and time period that should be included. A precise business question produces a result that is easier to verify.
- 1Import the workbook.
- 2Open the workbook or sheet details in Data.
- 3Review detected headers, types, missingness, and warnings.
- 4Select the sheet that contains the required records.
- 5Choose Use in Chat.
- 6Ask one precise question, such as “Show the top 10 vendors by total Amount for Invoice Date in Q4.”
- 7Use
@to select a field when the field name could be ambiguous. - 8Review the source name, grounding, coverage, and caveats shown with the answer.
- 9Compare material totals or example rows with the original workbook.
- 10Ask a narrower follow-up if the answer mixed periods, sheets, or fields.
the question names the intended scope, RangerIO attributes the result to the correct source, and consequential figures have been checked against the file.
choose the specific sheet instead of the workbook, name the exact column, reduce the number of requested operations, and read any missingness or structure warnings.
Compare two files or reporting periods
you want to compare last month with this month, an original file with a revised file, or two related source exports.
confirm that the files represent comparable populations and that their key fields have the same meaning. RangerIO cannot decide that two similarly named columns are business-equivalent.
- 1Put both files in the same project when they belong to the same engagement.
- 2Import both files.
- 3Review each file's structure and readiness separately.
- 4Select both ready sources in Data.
- 5Choose Use in Chat.
- 6Ask for a named comparison, for example: “Compare total Amount and record count by Status between March and April.”
- 7Review which source each number came from.
- 8Read missingness and data-quality caveats for both files.
- 9Verify the largest differences against the underlying records.
the answer identifies both sources, uses the intended fields, and the significant differences have been checked.
compare one measure at a time, state which source represents which period, and avoid asking for a join until you have confirmed a reliable matching key.
Prepare a draft report for professional review
you need a structured first draft based on one or more imported sources.
finish source review, confirm privacy coverage, and activate the permitted local or cloud AI engine. A report is model-assisted and must be reviewed.
- 1Open Export.
- 2Select the eligible sources.
- 3Turn on AI Assisted.
- 4Read whether the active engine is local or cloud.
- 5Select the report template and sections that fit the assignment.
- 6Enter a clear report title.
- 7Choose DOCX, PDF, or Excel as offered by the selected report workflow.
- 8Choose Generate Report.
- 9Continue other work while the report runs in the background.
- 10Open the completed report preview.
- 11Read every section and any missing-input or degraded warnings.
- 12Choose the required content variants.
- 13Choose Download or Export Report.
- 14Check material facts, calculations, names, and conclusions before circulation.
the report file opens, its source scope is correct, its warnings have been addressed, and a qualified person has reviewed the draft.
confirm the sources are ready, confirm an AI engine is active, reduce the source set, or remove a report section whose required inputs are unavailable.
Review a folder of engagement files without enabling folder watching
a client or colleague gave you a folder containing several supported files and you want to choose which ones belong in RangerIO.
remove known backups or irrelevant files from consideration, or plan to deselect them after the scan. This workflow discovers files once; it does not monitor the folder for future changes.
- 1Open Data.
- 2Create or select the engagement project.
- 3Choose Import → Directory.
- 4Choose the folder.
- 5Select the file types to discover.
- 6Decide whether to include subdirectories and set the depth shown by the interface.
- 7Choose Scan Directory.
- 8Review the discovered files.
- 9Deselect backups, duplicates, irrelevant files, and unsupported material.
- 10Choose Continue with N files.
- 11Follow the grouped import tasks.
- 12Review failed or interrupted files separately rather than assuming the entire group succeeded.
the intended files appear in the correct project and each file's task state is accounted for.
narrow the file types or directory depth, import a problem file individually, and use Resume or Cancel Task for interrupted tasks.
Use RangerIO from Claude Desktop
you prefer to ask questions in Claude Desktop and want Claude to request approved RangerIO information without manually attaching the original source file.
import and review the source in RangerIO, enable the MCP server, and complete the guided Claude Desktop connector setup. Your organization must permit the external host.
- 1Confirm the source is ready in RangerIO.
- 2Review its privacy state.
- 3Confirm the connector is Connected in Settings → Connectors.
- 4Open Claude Desktop.
- 5Ask a question that clearly identifies the RangerIO project or source needed.
- 6Review any tool request shown by the host.
- 7Review the returned answer knowing that RangerIO sanitizes its tool output but does not control Claude Desktop's final prose or retention behavior.
Claude Desktop used the intended RangerIO source and the returned result contains only information you are permitted to place in that external conversation.
return to RangerIO, choose Re-test, confirm the MCP server is on, and relaunch Claude Desktop if the connector wizard instructs you to do so.
Individual professional workflow
- 1Create a project for the engagement.
- 2Import supported files.
- 3Review structure warnings.
- 4Complete the Privacy Scan.
- 5Correct findings and re-scan.
- 6Ask local or model-assisted questions.
- 7Verify important answers.
- 8Export the dossier, report, or masked copy appropriate to the task.
- 9Retain or delete the local project according to organizational policy.
Accounting and audit workflow
- 1Create a project for the client and period.
- 2Import ledgers, workbooks, and supporting documents in verified formats.
- 3Review sheet structure and header confidence.
- 4Inspect missingness, unusual values, and parsing warnings.
- 5Review PII across the sources.
- 6Ask precise questions such as totals, counts, status breakdowns, and exceptions.
- 7Read grounding and data-quality caveats.
- 8Verify material totals against the underlying rows.
- 9Export data or a report for professional review.
Legal and HR workflow
- 1Create a project for the matter or HR review.
- 2Import supported DOCX, PDF, spreadsheet, or text sources.
- 3Open document previews.
- 4Review AI-detected — needs review values first.
- 5Step through each occurrence.
- 6Dismiss, reclassify, confirm, or mark values.
- 7Re-scan after corrections.
- 8Use the bundled local model in RangerIO Plus or a permitted configured provider for analysis.
- 9Export a masked copy only after reviewing the export itself.
Healthcare and research workflow
- 1Create a project for the authorized dataset or study workflow.
- 2Import supported tabular exports and documents.
- 3Review the source's structure and scan coverage.
- 4Inspect names, dates, identifiers, locations, and other potential re-identification fields.
- 5Manually mark specialized identifiers that the scan missed.
- 6Re-scan.
- 7Use local analysis where policy requires it.
- 8If an external provider is permitted, review sanitized context and organizational rules first.
- 9Verify all analytical results against the source.
Repeated engagement workflow
- 1Start a new project for the new period or client.
- 2Import the current files.
- 3Confirm that source structure has not changed unexpectedly.
- 4Review new scan findings rather than assuming prior classifications apply.
- 5Ask repeatable questions using the same field names and operations.
- 6Export the current output and record the review.
Chapter 13 · Examples and reference
What RangerIO Doesn't Do
It is not a regulatory certification
RangerIO and RangerIO Plus provide technical controls and review tools. They do not make an organization HIPAA-compliant, SOC 2-certified, PCI DSS-compliant, or legally authorized to disclose data.
It is not DLP or endpoint security
The products do not monitor all filesystem, email, browser, or network activity and do not enforce organization-wide data-loss policy.
It is not a cloud warehouse
The current desktop products are workstation-oriented. They are not a centralized multi-user warehouse or enterprise identity/access-control plane.
It is not a real-time streaming pipeline
The verified public workflow imports supported files and selected directory contents. It does not provide a documented continuous event-stream workflow.
Database and REST API import are not complete public workflows
Cards may appear in the import interface, but the current release does not document them as complete, usable import paths. Database and REST API sources are part of RangerIO Enterprise licensing, with full support and centralized management, and are expected to begin shipping in early 2027. For more information on our Enterprise version, please contact info@rangerio.com.
It does not certify a source as free of PII
A complete scan can miss values or produce false positives. A user must review the source and output.
It does not guarantee correct AI output
Models can be incorrect, incomplete, or misleading. Grounding and caveat controls reduce risk but do not eliminate it.
It does not control an external AI host
RangerIO controls its own tool response and egress checks. The host's final prose, retention, account settings, and provider behavior remain outside RangerIO.
RangerIO is not RangerIO Plus
RangerIO does not include the bundled llama.cpp/GGUF runtime.
Chapter 14 · Examples and reference
Technical FAQ
Which release does this guide cover?
Current public beta release, reviewed August 4, 2026. Unverified and roadmap features are omitted.
What is the architecture?
RangerIO is an Electron desktop application with a local backend. The backend handles ingestion, profiling, PII processing, analytics, retrieval, exports, connector tools, and model orchestration.
Current technical components include:
- FastAPI for the local backend;
- DuckDB for staging and analytical queries;
- SQLite for application metadata and registries;
- LanceDB for vector retrieval;
- fastembed through ONNX for embeddings;
- GLiNER2 through ONNX for entity extraction; and
- llama.cpp/GGUF local inference in RangerIO Plus.
Ports and internal process topology are implementation details and should not be presented as stable user configuration.
What is the exact difference between RangerIO and RangerIO Plus?
Both contain the complete data engine. RangerIO does not bundle the llama.cpp/GGUF runtime and uses a configured external local or cloud provider for model-assisted work. RangerIO Plus bundles that local runtime and exposes RangerIO-managed local-model setup.
Can RangerIO use a local model?
RangerIO can connect to a configured external local provider such as Ollama, LM Studio, or vLLM. Direct use of RangerIO's bundled llama.cpp/GGUF runtime is a RangerIO Plus capability.
What runs locally?
In both products:
- file and directory import;
- structure analysis;
- profiling and dossier storage;
- DuckDB analytical queries;
- PII review data and corrections;
- indexing and retrieval;
- standard exports; and
- local connector service.
RangerIO Plus also includes the bundled local-model inference runtime.
Configured cloud-provider calls and external MCP-host conversations are external paths.
Where is working data stored?
The desktop engine uses a local RangerIO data directory under the signed-in user's home directory. The current working directory is named RangerIO_local. It can contain imported working data, metadata, indexes, registries, logs, and audit data.
Which formats are verified for import?
CSV, TSV, XLS, XLSX, XLSM, JSON, JSONL, Parquet, PDF, DOCX, PPTX, HTML, and TXT.
Legacy .doc and .rtf are not supported in the current release.
Why can import be complete while PII says Unscanned?
Import and PII scanning are separate pipeline stages. A source can exist and be profiled while privacy processing is still pending, interrupted, or degraded.
What does Degraded · Unverified mean?
The displayed findings may be valid, but the scan did not establish complete coverage. Treat the source as requiring a re-scan and review.
Do corrections survive a re-scan?
User corrections are stored and the preview applies them immediately. A re-scan refreshes detection and the export gate using the current corrections.
Why does masked export pause after a correction?
The preview can show the correction immediately, but the masked exporter relies on the last complete scan and registry. Re-scanning reconciles the complete document and unlocks export.
Is a masked export guaranteed safe?
No. Registry-first masking and backstop checks reduce risk, but the user must inspect the exported file.
How are questions answered?
RangerIO routes questions through direct dossier lookup, local analytical query paths, and configured model-assisted paths. The chosen path depends on the question and available engines.
What do grounding and caveats mean?
Grounding shows that supported claims—especially numeric claims—were checked against source/query facts. Caveats describe relevant data limitations such as missingness or anomaly coverage.
Neither is a guarantee that the entire answer is correct.
Can an in-app cloud answer restore masked values?
The in-app cloud workflow can restore supported tokens locally after the provider response returns. Protection markings can appear with the answer.
Can an external MCP client receive restored sensitive values?
RangerIO's public MCP surface blocks rehydration because tool results return through the external host.
Does MCP expose raw rows?
MCP tools can return sanitized previews and sanitized analytical results. PII-aware scrubbing and outbound controls apply, but the result still requires review.
Is the MCP server always running?
No. It is off by default and starts when the user enables it in Settings.
Does RangerIO send telemetry?
MCP telemetry is off by default. When explicitly enabled, it writes to a local rotating log. Update checks and any external provider or connector enabled by the user create network traffic for those functions.
Does RangerIO require the internet?
Local ingestion and local analysis can operate without a cloud provider. Downloads, updates, configured cloud providers, and external connector hosts require connectivity.
Does RangerIO check for updates?
Yes. The packaged app checks for updates and asks before downloading because automatic download is disabled.
What happens when an import is interrupted?
The task panel and Data banner can offer Resume and Cancel/Dismiss. Resume is user-driven and can be refused when the system lacks sufficient memory.
Does deleting a source delete the original file?
No. It deletes RangerIO's working records for that source, not the original external file.
Are database, API, or SharePoint imports supported?
Not in the current public beta of the desktop product. SQL database and REST API sources are part of RangerIO Enterprise licensing, with full support, and are expected to begin shipping in early 2027. SharePoint is not a documented source. For more information on our Enterprise version, please contact info@rangerio.com.
Is there an enterprise or centrally managed version?
Yes. RangerIO Enterprise is a licensing tier over the same data engine. It adds centralized management for multi-seat deployments and fully supported database and REST API data sources in addition to file imports. Enterprise licensing is expected to begin shipping in early 2027 and is available on request today.
For more information on our Enterprise version, please contact info@rangerio.com.
Is RangerIO a compliance program?
No. It is one technical component in a broader organizational process.