Documentation Get help

Roll out the Cloud Proxy

This guide is for IT. You’ll deliver three things to each Mac through your device management tool — a configuration profile, the Flowstate agent, and a network extension profile — first to a pilot group, then to everyone. Nobody using the Macs has to click anything.

Before you begin

  • You need access to manage AI telemetry keys — ask your Flowstate admin.
  • Your security and compliance teams have approved what is recorded, and people have been told. See Security and privacy.
  • Your network lets Macs reach proxy.flowstate.inc. See Allow the Cloud Proxy through your network.
  • Every Mac in scope runs macOS 13 or later, is enrolled in your device management tool, and has an assigned user whose email matches their work email in Flowstate.

1. Get the files from Flowstate

Ask your Flowstate contact for:

  • The Flowstate agent installer, FlowstateAgent.pkg.
  • Your network extension profile, flowstate-<your company>-network-extension.mobileconfig.

2. Generate your profile

  1. In Flowstate, open Settings → AI → Cloud Proxy.
  2. Under MDM / managed fleet, select Generate MDM profile.
  3. A file named flowstate-<your company>.mobileconfig downloads. If it doesn’t, select Download .mobileconfig.

The page also shows your Org API token once. You don’t need to copy it — it’s already inside the profile.

3. Set the email variable

The profile identifies each Mac by its assigned user’s email. It uses the placeholder $EMAIL, which you replace with your device management tool’s own variable for the assigned user’s email.

  1. Open flowstate-<your company>.mobileconfig in a text editor.
  2. Replace every $EMAIL with your tool’s variable from the table below. It appears twice.
  3. Save the file.
Device management toolReplace $EMAIL with
Jamf Pro$EMAIL — no change needed
Kandji$EMAIL — no change needed
Mosyle%Email%
Microsoft Intune{{userprincipalname}}, or {{mail}} if people’s email differs from their sign-in name

4. Deliver to a pilot group, in order

Pick a small pilot group, then deliver the three files to it in this order.

  1. Upload flowstate-<your company>.mobileconfig as a custom configuration profile, and scope it to the pilot group.
  2. Upload FlowstateAgent.pkg as a package or custom app, and scope it to the same group.
  3. Once the agent has installed, upload flowstate-<your company>-network-extension.mobileconfig as a custom configuration profile, scoped to the same group.

5. Check the pilot

On one pilot Mac:

  1. Open System Settings → General → Device Management. You should see Flowstate AI Proxy — <your company> and Flowstate AI Proxy — Network Extension (<your company>).
  2. Check the Flowstate icon is in the menu bar.
  3. Use Claude or ChatGPT in a browser.

Then in Flowstate:

  1. Open Insights → Agent insights → Agent sessions.
  2. Set the period to today and find the session under that person’s name.
  3. Its project shows Pending… at first, then a project or No project.

If nothing shows up, see Troubleshooting.

6. Roll out to everyone

When the pilot looks right, widen the scope of both profiles and the package to every Mac in scope. Keep the same order for Macs that don’t have the agent yet.

7. Plan the token replacement

The token inside your profile lasts one year from when you generated it. Put a reminder in your calendar a few weeks before, then follow Replace the Cloud Proxy token.

What the profiles do

  • The first profile gives the agent your company’s Flowstate details, the Mac’s user email and the token. It approves the agent’s network extension and background items so nobody is asked, and it makes the Mac trust your organisation’s own certificate, Flowstate Tenant CA, which the Cloud Proxy needs to read covered AI conversations.
  • The network extension profile switches on the agent’s network extension without asking the person using the Mac. It shows in the Mac’s network settings as Flowstate AI Capture.

Remove the agent from a Mac

  1. In your device management tool, remove the Mac from the scope of both profiles and the package.
  2. If the app stays on the Mac, delete FlowstateAgent from the Applications folder.

Once the first profile is removed, the Mac no longer trusts your organisation’s certificate and AI tools connect directly again.