Cloud Proxy troubleshooting
Find what you’re seeing, then follow the fix. Sessions show under Insights → Agent insights → Agent sessions — set the period to cover when the person used the AI tool.
No sessions arrive
From any Mac
- On a pilot Mac, open System Settings → General → Device Management. Check both Flowstate profiles are listed: Flowstate AI Proxy and Flowstate AI Proxy — Network Extension.
- Check the Flowstate icon is in the menu bar. If it isn’t, the agent package hasn’t installed.
- Check the Mac can reach
proxy.flowstate.incon port 443. See Allow the Cloud Proxy through your network. - Use Claude or ChatGPT on that Mac, wait a few minutes, then look for the person in Agent sessions.
From one Mac
Check that Mac is in scope for both profiles and the package in your device management tool, then follow the four steps above on it.
From every Mac, all at once, after months of working
The Cloud Proxy token in your profile has expired. It lasts one year from when the profile was generated. Replace the token.
From some Macs, after you replaced the token
Those Macs still have the old profile. Check your device management tool delivered the new profile to them.
From one AI tool
That tool isn’t covered. GitHub Copilot and Windsurf, for example, aren’t covered — connect their billing instead: see Connect AI providers. If it’s your own private endpoint, add it as a custom hostname.
Sessions show the wrong person, or nobody
Sessions show $EMAIL or no person
The email placeholder in the profile wasn’t replaced with your device management tool’s own variable, or the Mac has no assigned user.
- Replace
$EMAILin the profile with your tool’s variable. See Set the email variable. - Give every Mac in scope an assigned user.
- Redeploy the profile.
Sessions show an email address instead of a name
The email your device management tool holds for that user doesn’t match anyone’s work email in Flowstate. Correct it in one place or the other so they match.
Sessions show someone else
Sessions go against the Mac’s assigned user in your device management tool, not whoever is signed in to the Mac. Update the assigned user and redeploy the profile.
Certificate errors
AI tools show “connection not private” or certificate errors
The profile that makes the Mac trust your organisation’s certificate, Flowstate Tenant CA, hasn’t landed. Check System Settings → General → Device Management for the Flowstate AI Proxy profile, and redeliver it.
Browsers work, but a command-line tool shows certificate errors
Some command-line tools keep their own list of trusted certificates instead of using the Mac’s. Ask the tool’s owner to add Flowstate Tenant CA from the Mac’s System keychain to that tool’s trusted certificates.
Installing the profiles
The profile fails to install with a VPN service error
The network extension profile reached the Mac before the agent package. Remove it from that Mac, check the package has installed, then deliver the network extension profile again.
People are asked to allow Flowstate to add proxy configurations
The network extension profile hasn’t reached the Mac. Deliver it after the package. Ask people not to click through the prompt.
People are asked to allow a system extension or background items
The first profile hasn’t reached the Mac. Deliver it before the package.
Corporate networks
AI tools work at home but not in the office
Your office network blocks or inspects proxy.flowstate.inc. Allow it on port 443 and exclude it from inspection.
Macs can only reach the internet through a corporate proxy
The agent needs to reach proxy.flowstate.inc directly. Allow it through, or talk to your Flowstate contact before rollout.
An AI provider rejects requests after rollout
The provider account only accepts your own IP addresses. Allow Flowstate at your AI providers.
Private AI endpoints
A hostname you added doesn’t show sessions yet
Changes reach your Macs within 5 minutes. Wait, then use the endpoint again.
“Enter a valid hostname (e.g. ai.acme.com) — no scheme, port, or path.”
Enter only the hostname, like ai.example.com: no https://, port, path or *.
An endpoint stopped working after you added it
It may only accept connections from your own network or IP addresses. Remove the hostname to restore the direct connection, then see Private AI endpoints.
Settings page
”Could not generate the MDM profile.”
You need access to manage AI telemetry keys — ask your Flowstate admin. If you already have it, contact Flowstate support.
You can see custom hostnames but can’t change them
You need access to update integrations — ask your Flowstate admin.
Still stuck
Contact Flowstate support with your device management tool, whether both profiles and the package show as installed on an affected Mac, and what Agent sessions shows for the affected person. Never send the profile or the token.