Security alerts rarely arrive one at a time. A single alert can trigger a cascade across an enterprise environment, forcing human analysts to decipher which notifications are genuinely related and what they ultimately signify. When multiple alerts flood in simultaneously, they can quickly overwhelm even the most seasoned security professionals. This recurring dilemma is widely known in the industry as the alert paradox. To help combat this growing strain, Cloudflare has introduced a built-in, multi-AI-agent security operations harness designed to shoulder heavier workloads at Cloudflare scale.
The company’s Cloudflare Managed Defense AI agent harness is engineered to dramatically accelerate the process of gathering raw data, connecting and aggregating diverse detections, and accounting for missing sources—all while fresh streams of alerts continuously roll in. To achieve deeper model-backed analysis and evaluate complex contexts, Cloudflare leverages the OpenAI Daybreak Defense Network and a strategic partnership with Anthropic. The platform utilizes approved models from these partners, including GPT-5.6 Cyber and Mythos, while initial analysis and scoring are powered by Clef, Cloudflare’s open-source decision model.
Collecting the necessary evidence to understand the precise meaning of every individual alert has historically demanded significant time and effort. Even within highly sophisticated Security Information and Event Management (SIEM) systems, far too much heavy lifting is left to human reviewers. Human analysts must continuously manually gather data, piece together and aggregate disparate detections, and account for missing information sources while incoming alerts pile up.
Consider the countless mental calculations a human analyst faces during every review cycle: Which alerts should be silenced? What immediate action should be taken? Which notification should be ignored entirely? Which should be resolved as false positives, and which require classification as true positives? Which specific warning should trigger the incident response team? Cloudflare addresses this operational predicament directly through its advanced AI agent strategy. This approach drastically cuts down the time required to evaluate alerts and provides Managed Defense Analysts with a quick, consolidated view that delivers immediate insight into related alerts, admitted evidence, visible gaps, and recommended next steps. The ultimate result is a substantial reduction in analysis time paired with a hyper-focus on actually resolving security alerts and deploying effective mitigations.
Why a Single Agent Fails
Early prototyping by Cloudflare engineers clearly exposed the limitations of relying on a single, general-purpose AI agent. When the team fed an entire investigation into a solitary agent, it produced some useful insights, but it also suffered from hallucinations—making claims that the underlying evidence simply could not support. Critical telemetry, detector descriptions, security policies, and threat intelligence were flattened together into one massive prompt, causing their distinct functional roles to blur and merge.
To overcome these hurdles, the engineering team shifted evidence collection and scope enforcement directly into application code, ensuring these safeguards execute before any model-based analysis begins.
Recon First, Inference Second
While it might be tempting to deploy an AI agent at every single stage of an investigation, Cloudflare’s harness employs no AI during the initial phase. Before any inference calls are made, deterministic code executes a fixed set of reconnaissance workflows powered by versioned API calls. This process systematically collects customer identity data, detection history, traffic baselines, enforcement outcomes, and network observations. Each piece of information is meticulously stored alongside its specific source, version, and timestamp.
Because Cloudflare observes both incoming requests and the exact actions applied to them, investigations can seamlessly connect the specific behavior that triggered an alert with both the security control that fired and its ultimate outcome. This fixed reconnaissance snapshot also ensures that evaluations remain entirely reproducible. If AI agents were allowed to fetch their own data dynamically, two separate runs might produce conflicting conclusions simply because their underlying inputs shifted mid-stream. With a fixed snapshot, the exact same data can be replayed, ensuring that any differences in specialist AI agent findings stem from nuanced interpretation rather than retrieval discrepancies.
Filter Noise Early
The vast majority of security alerts are not actual incidents. The exact same rule often fires repeatedly in response to a known, benign traffic pattern, and paging Managed Defense Analysts every single time only increases the risk that a genuine security incident will be overlooked.
To solve this, Cloudflare integrated a lightweight triage model designed to compare each incoming alert against its corresponding reconnaissance data: Has this event previously been detected for this customer? What decisions did Managed Defense Analysts make in past instances? Does the traffic pattern align with normal human behavior? Alerts that are scored with a high likelihood of being false positives are routed around the specialist AI agents entirely.
Clef, running on Workers AI, proved to be an ideal fit for this type of rapid agentic reasoning. Known high-volume noise is deterministically classified as passive the moment it arrives. While it remains accessible as background context, it does not clutter the active investigation queue.
Specialist AI Agents Handle the Investigation
For alerts that demand a deeper, more rigorous review, a coordinator AI agent orchestrates four specialist AI agents running simultaneously in parallel. A dedicated synthesis AI agent then combines their typed findings into a single, cohesive advisory. Crucially, the synthesis agent lacks the ability to fetch new evidence or choose classifications outside of an approved vocabulary. Keeping each operational task strictly bounded makes it far easier to catch unsupported claims and ensures that recommendations remain fully auditable.
Global Context Without Customer Data
While an ordinary security tool understands events unfolding strictly within its own isolated environment, it typically remains blind to the broader threat landscape outside. Cloudflare overcomes this limitation by evaluating alerts against patterns observed across its vast global network.
For instance, an incoming IP address might be targeting a single site, scanning thousands of different locations simultaneously, or appearing across the network for the very first time. Each of these patterns carries a distinct weight in a security assessment. To safeguard customer privacy, the global telemetry specialist works exclusively with aggregated data, never receiving another customer’s individual records or personal identities.

This comprehensive view integrates features from Cloudflare’s CDN, WAF, DDoS protection, Turnstile, Rate Limiting, and Cloudforce One threat intelligence services. The synthesis AI agent carefully weighs both global reputation data and customer-specific history. This balance ensures that a globally common traffic pattern can be accurately interpreted on a per-customer basis without incorrectly assuming that every widespread pattern represents a coordinated campaign targeting all users.
History is Evidence
Every evaluation performed by the system retains a deep awareness of preceding events, including past alerts, historical patterns, and specific customer context. The reconnaissance dossier records an alert’s track record—including how many times a particular service alert has fired, how frequently those occurrences were dismissed as false positives, and what conclusions Managed Defense Analysts ultimately reached. An attack pattern that has consistently proved benign during past reviews is treated very differently from the first sighting of an entirely novel threat, and the specialist AI agents are explicitly briefed on this distinction. Approved background context is automatically pulled from previous alerts and cases, allowing yesterday’s conclusions to inform today’s decisions rather than forcing analysts to rebuild context from scratch.
Furthermore, the system automatically aggregates related alerts into a consolidated case. Within each case, it stores all gathered evidence, analytical findings, and recommendations. While the system deterministically joins and correlates this data, final confirmation of the actual scope is left to human Managed Defense Analysts. Over time, a single case can successfully tie together network, application, and Zero Trust evidence while meticulously tracking the origin of every piece of data for future reference.
From Evidence to Decision
Prior to conducting any analysis, the system compiles a versioned evidence package containing the subject, operational scope, time anchor, admitted evidence, policy versions, data sources, and any coverage gaps. Specialist agents are strictly required to cite items included in this package. Underlying application code verifies that every citation actually exists, belongs to the specific investigation, and genuinely supports the attached claim. Any invalid findings are promptly corrected or formally recorded as operational limitations.
Clef is utilized a second time to score the assembled evidence: Is the collected data sufficient to reach a confident decision? Does any piece of evidence contradict another? Based on these evaluations, Clef selects from a deterministically reduced list of attack classifications and dispositions.
Cloudflare’s developer platform powers this entire workflow infrastructure. Application code running on Workers admits evidence and validates results, while Workflows coordinates each sequential stage and saves completed work before subsequent phases begin. If a stage fails, the system reuses previously validated evidence rather than starting over from scratch. Investigation and advisory states are maintained via D1, bounded contexts and evidence artifacts are stored in R2, and case-chat states persist in Durable Objects using Flue, enriched further by AI Search.
Ultimately, an LLM-powered agent generates an advisory report using familiar terminology that Managed Defense Analysts use every day: affected surfaces, enforcement outcomes, relevant controls, and recommended next steps. Analysts retain full visibility to inspect evidence, dig deeper, revise recommendations, or group alerts into broader cases. Crucially, application code establishes strict tenant boundaries before any model processes the data, ensuring the AI never receives the authority to cross tenant lines or act independently of human oversight.
Handling Incomplete Evidence
Operating at network scale means occasional data source failures are inevitable. A comparison lookup may time out, critical metadata might be missing, or a threat intelligence query could return no matches at all. When these hiccups occur, the system preserves all successfully gathered evidence while formally documenting the operational gap.
The resulting advisory explicitly distinguishes between different states of completeness. If global telemetry is temporarily unavailable, the system can describe what behavior appears unusual for a specific customer, but it refrains from declaring whether the pattern is widespread across the broader internet. When evidence is fundamentally insufficient, the system abstains from making any classification or disposition recommendation.
Remediation
A truly useful security recommendation must point toward a concrete solution rather than simply generating more administrative tickets. Depending on the scenario, an advisory might suggest implementing a rate-limiting rule for an abusive traffic path, deploying a WAF custom rule for a specific signature, or adjusting DDoS protection parameters. For fully managed customers, Managed Defense Analysts can apply these suggested rules directly, while other customers receive actionable recommendations right inside their dashboard and through their preferred alerting channels.
Ultimately, the Managed Defense Analyst remains fully responsible for final decision-making and any active mitigations. Every alert and case package includes the transparent evidence supporting the AI agent’s recommendations, empowering analysts to reach confident conclusions by accepting or refining the AI’s guidance.
Looking Ahead
While Managed Defense Analysts retain ultimate authority over judgment calls, the new AI agent harness successfully shoulders much of the repetitive operational burden—assembling investigations, connecting related events, and laying bare the evidence behind every recommendation. Over the coming quarters, Cloudflare plans to introduce a Custom Managed service tier offering greater flexibility tailored to individual organizational needs.
The company is also exploring continuous AI agents capable of monitoring Cloudflare traffic autonomously to surface subtle threat patterns that traditional fixed rules and thresholds might otherwise miss.
An early beta of this capability is currently available within Cloudflare Managed Defense for eligible application-security alerts and cases. Organizations already utilizing Cloudflare WAF, DDoS protection, Magic Transit, or other supported products are encouraged to speak with their enterprise account teams to learn more about adding Managed Defense to their security stack.
Leave a Reply