# Endpoint Suite problems

## SmartScreen warns on Windows

Expected today: the Windows build is not yet Authenticode-signed. **More info → Run
anyway**. We will remove this step when the certificate is in place.

## The app cannot create a device identity

On macOS, this is nearly always **running it from the disk image**. Drag the app into
Applications and open it from there — macOS otherwise runs it from a temporary read-only
location where it cannot use the Keychain.

On Windows, it means Credential Manager refused. Signing out of Windows and back in
usually clears it; if not, send us a log bundle.

## "Can't reach {host}"

The banner names the host. Give that name to your network team — it is normally a VPN that
has not come up yet or an egress rule that has not been widened. The app keeps retrying and
recovers by itself once the host is reachable.

## Buttons are missing

If your organization deploys a managed configuration, it can prevent signing out,
disconnecting a tool, or ungoverning MCP servers. The card says the setting is managed by
your organization. This is your own policy, not a fault.

## Signing out did not ungovern my tools

Deliberate. Tools stay pointed at the Gateway and fail closed. Silently returning a machine
to ungoverned direct access because someone signed out would be the worst possible failure
for a governance product. An admin removes the device from the console.

## Sending us logs

**Account → Export logs**, or ask your admin to request them from **Diagnostics**. Event
logs only — no prompt content, no secrets, 14-day retention.