Skip to content

Roll out the Cloud Proxy

The Cloud Proxy records the AI sessions people have on your company Macs: who had each one, with which tool and model, and what it cost. Adoption, Agent sessions, AI spend by project and AI impact are all built on those sessions, so the checklists that need them link here.

It records what people send to AI services. Your security and compliance teams approve it before anything is installed, and IT puts it on your Macs through your device management tool. Nobody using a Mac has to click anything.

An engineering or IT lead owns this foundation, with security and compliance, HR, IT and a Flowstate admin.

Before you start

  • Load your people and teams. Everyone's work email in Flowstate must match the email your device management tool holds for them.
  • A device management tool for your Macs, such as Jamf Pro, Kandji, Microsoft Intune or Mosyle.

Not available yet: Windows and Linux

The Cloud Proxy runs on Macs with macOS 13 or later. AI use on Windows and Linux computers shows only through your AI providers' billing. See Connect your AI providers.

1. Switch on AI attribution

What: Ask for AI attribution. Who: Implementation lead. Where: Your Flowstate contact. Done when: Insights → Agent insights shows an Agent sessions tab.

2. Get approval for what is recorded

What: Review what the Cloud Proxy records, where it's kept, for how long and who can see it. Agree how people will be told. Who: Security lead and compliance, with HR where employee notice or works councils apply. Where: Cloud Proxy security and privacyDone when: You have written approval, and an employee notice ready to send before the pilot.

The Cloud Proxy records full prompts and responses. Nobody using a Mac is asked to consent, so telling people is up to you.

3. Decide who can see sessions

What: Decide who may see everyone's sessions. Give everyone else the AI Viewer role, so they only see their own AI use. Who: Flowstate admin, with the security lead. Where: Settings → Users & Access → UsersDone when: A test account with the AI Viewer role sees only My AI, and everyone who shouldn't see all sessions has that role.

4. Pick a pilot group of Macs

What: Choose a small group of Macs enrolled in device management, each with an assigned user whose email matches their work email in Flowstate. Who: IT. Where: Your device management tool. Done when: You have a named pilot group, every Mac on macOS 13 or later with an assigned user. Shared Macs are left out.

5. Open your network

What: Let Macs reach the Cloud Proxy, and let Flowstate reach any AI provider account you've limited to certain IP addresses. Who: Network or security team, with each provider's admin. Where: Allow the Cloud Proxy through your networkDone when: Macs can reach proxy.flowstate.inc on port 443, and every IP-restricted provider account allows Flowstate's addresses.

6. Optional: add private AI endpoints

What: Add any private AI address your company uses, such as your own Azure OpenAI endpoint, so the Cloud Proxy covers it. Who: IT, with an engineering lead. Where: Settings → AI → Cloud Proxy → Custom AI-service hostnames. See Add a private AI endpoint. Done when: Each private hostname is listed under its service.

7. Pilot the Cloud Proxy

What: Send the employee notice, then deliver the profile, the agent and the network extension profile to the pilot group. Who: IT. Where: IT's step-by-step guide, Roll out the Cloud Proxy on your Macs. Done when: Sessions from pilot users appear in Insights → Agent insights → Agent sessions under the right names.

8. Roll out to everyone

What: Widen the rollout to every Mac in scope. Who: IT. Where: Roll out to everyoneDone when: Your device management tool shows both Flowstate profiles and the agent installed on every Mac in scope, and Spend accounted for on the Agent insights Dashboard has risen.

Put the token's replacement in the calendar for a year after you generated the profile. See Replace the Cloud Proxy token.

You're set up when

  • Sessions from people on every Mac in scope appear under Agent sessions, against the right names.
  • Spend accounted for on the Dashboard has risen since the pilot.
  • The token's replacement date is in someone's calendar.

If something's not right

Someone's sessions don't appear. Their Mac has no assigned user, or that email doesn't match anyone in Flowstate. Correct the email in Flowstate or in your device management tool. See Tying sessions to people.

A session shows the person as Unknown. They were signed in to the AI tool with an account Flowstate doesn't recognise, such as a personal account.

People are asked to allow Flowstate to add proxy configurations. The network extension profile didn't arrive, or arrived before the agent was installed. See Deliver to a pilot group, in order.

For anything else, see Cloud Proxy troubleshooting.

For your technical team

Flowstate Documentation