Cloud Proxy
The Cloud Proxy shows you what people use AI for on your company Macs. It records their conversations with AI services and turns them into sessions in Flowstate: who had the conversation, with which tool and model, which project it was for and what it cost.
Provider bills tell you how much you spent on AI. Sessions tell you what it was spent on. See How AI data arrives in Flowstate.
How it works
- Your IT team puts the Flowstate agent on your company Macs through device management. It sits in the menu bar.
- When someone uses a covered AI service, the agent sends the conversation through the Flowstate Cloud Proxy. Everything else on the Mac goes out as normal.
- The Cloud Proxy records the conversation and passes it on to the AI provider. The AI tool keeps working as usual.
- Flowstate groups what’s recorded into sessions under the Mac’s assigned user, works out the cost and ties each session to a project where it can.
Sessions appear in Insights → Agent insights → Agent sessions, and each person sees their own under My AI → My sessions.
Which AI services are covered
| Service | Covered |
|---|---|
| Anthropic | The API, the Console and claude.ai |
| OpenAI | The API and ChatGPT |
| Amazon Bedrock | In every AWS region |
| Microsoft Azure | Azure OpenAI and Azure AI services |
| Vertex AI, the Gemini API, Gemini Code Assist and Jules | |
| Cursor | The Cursor app and its agent |
| Your own endpoints | Any private hostname you add — see below |
GitHub Copilot, Windsurf and the Gemini web app aren’t covered. Their use shows only through their billing, where you’ve connected it. See Connect AI providers.
The agent runs on Macs with macOS 13 or later. AI use on Windows and Linux computers shows only through provider billing.
What you manage in Flowstate
Everything is on Settings → AI → Cloud Proxy:
- MDM / managed fleet — generate the profile your IT team deploys. See Roll out the Cloud Proxy.
- Custom AI-service hostnames — add private AI endpoints for the Cloud Proxy to cover.
Install the agent through your device management tool, even for a single Mac.
Add a private AI endpoint
Use this if your company calls AI through its own address, such as an Azure OpenAI endpoint on your own domain.
- Open Settings → AI → Cloud Proxy.
- Under Custom AI-service hostnames, find the service the endpoint belongs to: Azure or Bedrock.
- Type just the hostname, such as
ai.example.com— nohttps://, port or path. - Select Add host. It saves straight away.
Your Macs pick up the change within 5 minutes. To take a hostname off, select the bin icon next to it.
You need access to update integrations to change this list — ask your Flowstate admin.
Roll out in this order
- Get approval. Security and compliance approve what’s recorded, and HR agrees how people are told. Security and privacy
- Switch on AI attribution. Your Flowstate contact does this. Roll out the Cloud Proxy
- Check people’s emails. Everyone’s work email in Flowstate matches the email your device management tool holds for them. People and teams
- Open your network. Allow the Cloud Proxy through your network
- Add private endpoints, if you have any. Add a private AI endpoint
- Pilot. Deploy to a small group and check their sessions arrive. Roll out the Cloud Proxy
- Roll out to everyone. Roll out to everyone
- Plan the token replacement for a year’s time. Replace the Cloud Proxy token