Troubleshooting
Resolve setup, coverage, policy, and networking problems.
Record the app status, failed interaction, app version, operating system, AI client, and approximate time before changing settings.
| Symptom | First check | Follow-up |
|---|---|---|
| Protection cannot start | Finish the setup or repair action shown in the app | Installation |
| AI works but no trace appears | Confirm protection is active and test one new request | Inspection limits |
| CLI reports a certificate error | Open a new terminal and check its CA settings | Runtime CA support |
| Container traffic is missing | Check container routing and certificate trust | Runtime CA support |
| Protection degrades with a VPN | Start the VPN before protection and inspect the upstream proxy | VPN support |
| A local allow still results in a block | Inspect the matched policy and organization rules | Findings and policies |
| MCP shows drift or monitor pending | Review the source configuration and protection state | Agents and MCP |
| Organization inventory is empty | Confirm enrollment, device activity, and the selected organization | Discovery quickstart |
Retry a controlled example
Section titled “Retry a controlled example”After a repair or configuration change, repeat the quickstart test and verify a new trace. Old evidence cannot confirm the current network path.
If the problem persists, include the visible error, version, platform, reproduction steps, and relevant trace identifiers in your support request. Review any attached logs for credentials or private content.
Recover after removal
Section titled “Recover after removal”Use the packaged uninstaller first. Manual cleanup covers interrupted removal and leftover certificate or proxy settings.