Cloudflare has introduced a built-in, multi-AI-agent security operations harness designed to handle large volumes of security alerts at Cloudflare scale. The system accelerates data gathering, detection aggregation, and accounting for missing sources as new alerts arrive, while relying on model-backed analysis for deeper context.
WHAT CHANGED FROM THE SINGLE-AGENT PROTOTYPE TO THE NEW HARNESS
The company notes that an initial, single-shot AI agent could provide useful analysis but sometimes produced results not supported by evidence. Three recurring problems were identified: context could become authoritative beyond the evidence, scope could drift beyond the correct account or time range, and lookups could time out or fail without clear "not found" signals. TechStaged has also covered Cloudflare AI Gateway Observability and Cost Controls.
HOW THE NEW HARNESS WORKS ON CLOUDFLARE MANAGED DEFENSE
Before model inference, deterministic code runs fixed reconnaissance workflows with versioned API calls to collect identity, detection history, traffic baseline, enforcement outcomes, and network observations. This reconciles inputs and makes evaluation reproducible across runs.
- Front half is free of AI agents and performs data collection and boundary enforcement
- Evidence packages are versioned and stored with source, version, and timestamp
SPECIALIST AI AGENTS AND THE SYNTHESIS STEP
For alerts needing deeper review, a coordinator AI agent runs four specialist AI agents in parallel: traffic analysis, customer context, global telemetry, and threat intelligence. A synthesis AI agent then combines their findings into an advisory using an approved vocabulary; the advisory can’t fetch new evidence or extend the allowed scope.
- Traffic analysis checks request behavior and enforcement
- Customer context references earlier alerts and analyst decisions
- Global telemetry uses anonymized, aggregate signals
- Threat intelligence checks existing indicators within the case
GLOBAL CONTEXT WITH PRIVACY SAFEGUARDS
The system compares alerts to patterns seen across Cloudflare’s global network but uses only aggregates to preserve customer privacy. This global context helps differentiate per-customer events from broader trends without exposing identity information.
EVIDENCE HANDLING AND VALIDATION
An evidence dossier records the alert’s track record, including previous dispositions, and the investigation cites specific items from that package. Application code on Cloudflare Workers admits evidence and validates results, ensuring that findings stay within the investigation’s scope and that invalid findings are corrected or noted as limitations.
- Versioned evidence packages
- Citations validated by application code
- Durable Objects and state management for case context
ADVISORY GENERATION AND ANALYST WORKFLOW
An LLM-powered advisory report uses terminology familiar to Managed Defense Analysts, including affected surface, enforcement outcome, relevant controls, and next steps. Analysts can inspect evidence, revise recommendations, or group alerts into a case, while the system fixes the customer scope before any model results are presented publicly. The analyst remains responsible for final decisions and mitigations.
- Evidence behind AI recommendations is visible to analysts
- Analysts retain control over judgment and interventions
SCALE, BETA STATUS, AND FUTURE PLANS
The early beta is available in Cloudflare Managed Defense for eligible application-security alerts and cases. The company plans to add a Custom Managed level with more organization-specific flexibility and to explore continuous AI agents that monitor traffic for patterns beyond fixed rules and thresholds.
- Beta availability for eligible customers
- Future plans include Custom Managed level and continuous AI agents
WHAT THIS MEANS FOR USERS AND SECURITY TEAMS
Cloudflare’s Managed Defense customers with WAF, DDoS, Magic Transit, or related products could access the beta, potentially accelerating investigation and remediation by correlating evidence across alerts and cases. Analysts maintain final decision authority, while AI handles repetitive collection, context synthesis, and advisory generation.
RELATED COVERAGE
- Cloudflare AI Gateway Observability and Cost Controls
- Cloudflare Workers AI Agents for Edge Applications
- Cloudflare opens second non-profit cohort to accelerate AI-powered civil-society tools
- GitHub Copilot adds general availability for local sandboxing across CLI, app, and VS Code
- Developer Tools articles
SOURCES
- Cloudflare Blog: Building an evidence-grounded agentic security operations harness on Cloudflare Published · Primary source






