Documentation Get help

Cloud Proxy troubleshooting

Find what you’re seeing, then follow the fix. Sessions show under Insights → Agent insights → Agent sessions — set the period to cover when the person used the AI tool.

No sessions arrive

From any Mac

  1. On a pilot Mac, open System Settings → General → Device Management. Check both Flowstate profiles are listed: Flowstate AI Proxy and Flowstate AI Proxy — Network Extension.
  2. Check the Flowstate icon is in the menu bar. If it isn’t, the agent package hasn’t installed.
  3. Check the Mac can reach proxy.flowstate.inc on port 443. See Allow the Cloud Proxy through your network.
  4. Use Claude or ChatGPT on that Mac, wait a few minutes, then look for the person in Agent sessions.

From one Mac

Check that Mac is in scope for both profiles and the package in your device management tool, then follow the four steps above on it.

From every Mac, all at once, after months of working

The Cloud Proxy token in your profile has expired. It lasts one year from when the profile was generated. Replace the token.

From some Macs, after you replaced the token

Those Macs still have the old profile. Check your device management tool delivered the new profile to them.

From one AI tool

That tool isn’t covered. GitHub Copilot and Windsurf, for example, aren’t covered — connect their billing instead: see Connect AI providers. If it’s your own private endpoint, add it as a custom hostname.

Sessions show the wrong person, or nobody

Sessions show $EMAIL or no person

The email placeholder in the profile wasn’t replaced with your device management tool’s own variable, or the Mac has no assigned user.

  1. Replace $EMAIL in the profile with your tool’s variable. See Set the email variable.
  2. Give every Mac in scope an assigned user.
  3. Redeploy the profile.

Sessions show an email address instead of a name

The email your device management tool holds for that user doesn’t match anyone’s work email in Flowstate. Correct it in one place or the other so they match.

Sessions show someone else

Sessions go against the Mac’s assigned user in your device management tool, not whoever is signed in to the Mac. Update the assigned user and redeploy the profile.

Certificate errors

AI tools show “connection not private” or certificate errors

The profile that makes the Mac trust your organisation’s certificate, Flowstate Tenant CA, hasn’t landed. Check System Settings → General → Device Management for the Flowstate AI Proxy profile, and redeliver it.

Browsers work, but a command-line tool shows certificate errors

Some command-line tools keep their own list of trusted certificates instead of using the Mac’s. Ask the tool’s owner to add Flowstate Tenant CA from the Mac’s System keychain to that tool’s trusted certificates.

Installing the profiles

The profile fails to install with a VPN service error

The network extension profile reached the Mac before the agent package. Remove it from that Mac, check the package has installed, then deliver the network extension profile again.

People are asked to allow Flowstate to add proxy configurations

The network extension profile hasn’t reached the Mac. Deliver it after the package. Ask people not to click through the prompt.

People are asked to allow a system extension or background items

The first profile hasn’t reached the Mac. Deliver it before the package.

Corporate networks

AI tools work at home but not in the office

Your office network blocks or inspects proxy.flowstate.inc. Allow it on port 443 and exclude it from inspection.

Macs can only reach the internet through a corporate proxy

The agent needs to reach proxy.flowstate.inc directly. Allow it through, or talk to your Flowstate contact before rollout.

An AI provider rejects requests after rollout

The provider account only accepts your own IP addresses. Allow Flowstate at your AI providers.

Private AI endpoints

A hostname you added doesn’t show sessions yet

Changes reach your Macs within 5 minutes. Wait, then use the endpoint again.

“Enter a valid hostname (e.g. ai.acme.com) — no scheme, port, or path.”

Enter only the hostname, like ai.example.com: no https://, port, path or *.

An endpoint stopped working after you added it

It may only accept connections from your own network or IP addresses. Remove the hostname to restore the direct connection, then see Private AI endpoints.

Settings page

”Could not generate the MDM profile.”

You need access to manage AI telemetry keys — ask your Flowstate admin. If you already have it, contact Flowstate support.

You can see custom hostnames but can’t change them

You need access to update integrations — ask your Flowstate admin.

Still stuck

Contact Flowstate support with your device management tool, whether both profiles and the package show as installed on an affected Mac, and what Agent sessions shows for the affected person. Never send the profile or the token.