Roll out the Cloud Proxy
This guide is for IT. You’ll deliver three things to each Mac through your device management tool — a configuration profile, the Flowstate agent, and a network extension profile — first to a pilot group, then to everyone. Nobody using the Macs has to click anything.
Before you begin
- You need access to manage AI telemetry keys — ask your Flowstate admin.
- Your security and compliance teams have approved what is recorded, and people have been told. See Security and privacy.
- Your network lets Macs reach
proxy.flowstate.inc. See Allow the Cloud Proxy through your network. - Every Mac in scope runs macOS 13 or later, is enrolled in your device management tool, and has an assigned user whose email matches their work email in Flowstate.
1. Get the files from Flowstate
Ask your Flowstate contact for:
- The Flowstate agent installer,
FlowstateAgent.pkg. - Your network extension profile,
flowstate-<your company>-network-extension.mobileconfig.
2. Generate your profile
- In Flowstate, open Settings → AI → Cloud Proxy.
- Under MDM / managed fleet, select Generate MDM profile.
- A file named
flowstate-<your company>.mobileconfigdownloads. If it doesn’t, select Download .mobileconfig.
The page also shows your Org API token once. You don’t need to copy it — it’s already inside the profile.
3. Set the email variable
The profile identifies each Mac by its assigned user’s email. It uses the placeholder $EMAIL, which you replace with your device management tool’s own variable for the assigned user’s email.
- Open
flowstate-<your company>.mobileconfigin a text editor. - Replace every
$EMAILwith your tool’s variable from the table below. It appears twice. - Save the file.
| Device management tool | Replace $EMAIL with |
|---|---|
| Jamf Pro | $EMAIL — no change needed |
| Kandji | $EMAIL — no change needed |
| Mosyle | %Email% |
| Microsoft Intune | {{userprincipalname}}, or {{mail}} if people’s email differs from their sign-in name |
4. Deliver to a pilot group, in order
Pick a small pilot group, then deliver the three files to it in this order.
- Upload
flowstate-<your company>.mobileconfigas a custom configuration profile, and scope it to the pilot group. - Upload
FlowstateAgent.pkgas a package or custom app, and scope it to the same group. - Once the agent has installed, upload
flowstate-<your company>-network-extension.mobileconfigas a custom configuration profile, scoped to the same group.
5. Check the pilot
On one pilot Mac:
- Open System Settings → General → Device Management. You should see Flowstate AI Proxy —
<your company>and Flowstate AI Proxy — Network Extension (<your company>). - Check the Flowstate icon is in the menu bar.
- Use Claude or ChatGPT in a browser.
Then in Flowstate:
- Open Insights → Agent insights → Agent sessions.
- Set the period to today and find the session under that person’s name.
- Its project shows Pending… at first, then a project or No project.
If nothing shows up, see Troubleshooting.
6. Roll out to everyone
When the pilot looks right, widen the scope of both profiles and the package to every Mac in scope. Keep the same order for Macs that don’t have the agent yet.
7. Plan the token replacement
The token inside your profile lasts one year from when you generated it. Put a reminder in your calendar a few weeks before, then follow Replace the Cloud Proxy token.
What the profiles do
- The first profile gives the agent your company’s Flowstate details, the Mac’s user email and the token. It approves the agent’s network extension and background items so nobody is asked, and it makes the Mac trust your organisation’s own certificate, Flowstate Tenant CA, which the Cloud Proxy needs to read covered AI conversations.
- The network extension profile switches on the agent’s network extension without asking the person using the Mac. It shows in the Mac’s network settings as Flowstate AI Capture.
Remove the agent from a Mac
- In your device management tool, remove the Mac from the scope of both profiles and the package.
- If the app stays on the Mac, delete FlowstateAgent from the Applications folder.
Once the first profile is removed, the Mac no longer trusts your organisation’s certificate and AI tools connect directly again.