Security alerts rarely arrive one at a time in modern enterprise environments. A single security anomaly can trigger a cascading spike across an entire digital infrastructure, forcing human analysts to rapidly decipher which alerts are genuinely related and what they actually signify. When multiple alerts flood in simultaneously, the sheer volume can quickly overwhelm even the most seasoned security professionals. This fundamental industry dilemma is widely known as the alert paradox. To address this mounting pressure, Cloudflare has introduced a built-in, multi-AI-agent security operations harness designed to handle the heavy lifting of threat triage at Cloudflare scale.
The newly deployed Cloudflare Managed Defense AI agent harness is engineered to dramatically speed up the complex process of gathering data, connecting and aggregating disjointed detections, and accounting for missing data sources while a continuous stream of new alerts keeps pouring in. To conduct deeper context analysis, the system integrates advanced models through the OpenAI Daybreak Defense Network and an ongoing partnership with Anthropic. Specifically, Cloudflare utilizes approved models such as GPT-5.6 Cyber and Mythos to execute sophisticated model-backed analyses. Meanwhile, the crucial initial analysis and scoring phases are managed by Clef, Cloudflare’s open-source decision model.
Collecting the necessary evidence to understand the precise meaning of every incoming alert demands a significant investment of time and human capital. Even within a highly sophisticated Security Information and Event Management platform, far too much analytical weight is left for human reviewers to handle manually. Analysts must constantly gather raw data, connect and aggregate detections, and account for missing telemetry sources while navigating a relentless wave of incoming alerts.
Every time a human analyst reviews a security alert, they are forced to weigh a complex series of questions: Which alerts should we silence? Which immediate actions should we take? Which alerts can be safely ignored? Which should be resolved as false positives, and which require classification as true positives? Finally, which alerts carry enough severity to trigger the incident response team? Cloudflare’s new AI agent strategy aims to directly address this operational predicament. The approach significantly streamlines these decisions, providing Managed Defense analysts with a quick, consolidated view that delivers immediate insight into related alerts, admitted evidence, visible gaps, and recommended next steps. The overarching result is a sharp reduction in the time required for deep analysis, creating a hyper-focus on actually resolving security alerts and deploying necessary mitigations.
Why a Single Agent Fails
Early prototyping made the inherent limitations of a single, general-purpose AI agent glaringly obvious. When researchers and engineers fed an entire security investigation into a single AI agent, the system certainly produced useful analysis, but it also suffered from hallucinations, generating claims that were entirely unsupported by the underlying evidence. Critical variables such as raw telemetry, detector descriptions, security policies, and threat intelligence were flattened into a single prompt, causing their distinct functional roles to merge together destructively.
Faced with these recurring architectural hurdles in a single-shot AI agent harness, Cloudflare realized that a fundamentally different strategy was required. To eliminate these challenges, the engineering team moved evidence collection and scope enforcement directly into application code, ensuring strict parameters are enforced before any model analysis even begins.
Recon First, Inference Second
While it might be tempting to deploy an AI agent at every single stage of an investigation, Cloudflare’s architecture deliberately keeps the front half entirely free of inference models. Before any AI model is ever called, deterministic code runs a fixed set of reconnaissance workflows using versioned API calls. This initial phase systematically collects the customer’s identity, historical detection records, traffic baselines, enforcement outcomes, and broad network observations. Each discrete piece of data is securely stored alongside its source, versioning information, and precise timestamp.
Because Cloudflare occupies a unique position where it observes both the incoming request and the specific security action applied to it, the investigation can successfully connect the exact behavior that triggered an alert with both the control mechanism that fired and its ultimate outcome. This fixed reconnaissance snapshot also ensures that evaluations remain entirely reproducible. If AI agents are permitted to fetch their own raw data dynamically, two separate runs might easily disagree simply because their underlying inputs shifted in the interim. By utilizing a fixed snapshot, the exact same data can be replayed, ensuring that any differences found between specialist AI agents stem from differing interpretations rather than inconsistent data retrieval.
Filter Noise Early
The reality of network security is that the vast majority of alerts do not represent actual security incidents. A single protective rule often fires repeatedly on a known, benign traffic pattern, and paging Managed Defense analysts every time this occurs only leads to fatigue, making it far easier to miss a genuine security breach.
To combat this, Cloudflare recognized the need for a lightweight triage model capable of comparing each incoming alert against its established reconnaissance data: Has this specific event been detected for this customer before? What did Managed Defense analysts decide the last time it occurred? Does the traffic pattern look entirely consistent with normal human behavior? Alerts that are scored with a high statistical likelihood of being false positives are filtered out entirely, skipping analysis by the specialist AI agents.
Clef, running efficiently on Workers AI, proved to be the ideal engine for this type of fast, agentic reasoning. Known, high-volume noise is deterministically classified as passive the moment it arrives at the network edge. While it remains safely available as historical context, it is successfully kept out of the active analyst queue.
Specialist AI Agents Handle the Investigation
For alerts that genuinely require a deeper, more rigorous review, a primary coordinator AI agent oversees four specialist AI agents operating concurrently in parallel. Each of these specialists is assigned a sharply defined domain to investigate.
To tie their work together, a synthesis AI agent combines their typed findings into a single, cohesive advisory report. Crucially, the synthesis agent lacks the ability to fetch new evidence or independently choose a classification outside of a strictly approved vocabulary. Keeping each task narrow and compartmentalized makes unsupported claims much easier to catch and ensures that recommendations remain fully auditable.
Global Context Without Customer Data
A traditional security tool typically possesses deep knowledge of what happened strictly inside the local environment where it is deployed, yet remains entirely blind to the broader threat landscape beyond its borders. Cloudflare solves this visibility gap by comparing individual alerts against threat patterns observed across its massive global network.
For instance, an incoming IP address might be targeting a single site, aggressively scanning thousands of sites simultaneously, or appearing across the network for the absolute first time. Each of these distinct patterns carries a different weight in a security assessment. To strictly preserve customer privacy, the global telemetry specialist agent works exclusively with aggregated data; it never receives another customer’s individual records or identifying information.

This expansive view combines features drawn directly from Cloudflare’s CDN, WAF, DDoS protection, Turnstile, Rate Limiting, and Cloudforce One threat intelligence services. The synthesis AI agent carefully weighs both global reputation data and specific customer history. This guarantees that a globally common pattern can still be evaluated properly on a per-customer basis, while preventing a widespread pattern from automatically being misconstrued as a coordinated campaign across every single tenant on the network.
History is Evidence
Every evaluation conducted by the system remains fully conscious of what transpired before it—the alert itself, the historical pattern, and the specific customer profile. The reconnaissance dossier meticulously records an alert’s track record, including how many times a particular service alert has fired in the past, how many of those instances were dispositioned as false positives, and what the human Managed Defense analyst ultimately concluded.
An attack pattern that has proven completely benign every single time Managed Defense analysts have encountered it is treated as a fundamentally different entity compared to the first sighting of an entirely novel threat, and the specialist AI agents are explicitly briefed on this distinction. Approved background context is seamlessly pulled from previous alerts and historical cases, allowing yesterday’s conclusions to inform today’s decisions rather than forcing the system to rebuild context from scratch.
Furthermore, the system aggregates related alerts into a consolidated case. Within each case, it stores relevant evidence, analytical findings, and actionable recommendations. While the system deterministically joins and correlates this data, final confirmation of the actual scope is deliberately left to a human Managed Defense analyst. Over time, a single case can successfully connect network, application, and Zero Trust evidence together, while continuously tracking the precise source of that evidence for additional reference and auditing purposes.
From Evidence to Decision
Before any deep analysis takes place, the system compiles a versioned evidence package containing the subject, operational scope, time anchor, admitted evidence, policy versions, data sources, and any noted coverage gaps. Specialist agents are strictly required to cite items contained directly within that package. Application code continuously checks that every single citation genuinely exists, belongs to the ongoing investigation, and actually supports the attached claim. Any invalid findings are automatically corrected or recorded as known analytical limitations.
Clef is leveraged a second time to score the assembled evidence. The model evaluates whether the collected evidence is robust enough to form a definitive decision and checks whether any pieces of evidence actively contradict one another. Based on this evaluation, Clef selects from a deterministically reduced list of attack classifications and dispositions.
Cloudflare’s robust developer platform powers this entire operational workflow. Application code running on Workers admits incoming evidence and validates analytical results, while Workflows coordinates each discrete stage and saves completed work before the next phase begins. This ensures that if a stage fails, the system can reuse evidence and findings that already passed validation instead of restarting the entire process from scratch. D1 maintains the core investigation and advisory state, while R2 holds bounded context and raw evidence artifacts. Case-chat state persists securely in Durable Objects, utilizes the Flue framework, and is further enriched with AI Search.
Finally, an LLM-powered agent produces a clear advisory report utilizing terminology that Managed Defense analysts already use daily: affected surfaces, enforcement outcomes, relevant controls, and recommended next steps. Managed Defense analysts retain the full ability to inspect underlying evidence, investigate further, revise recommendations, or group related alerts into broader cases. Crucially, application code locks down the customer scope before any AI model ever sees the data, granting each specialist only the specific evidence it requires. Under no circumstances does the model receive the authority to cross tenant boundaries or act independently on behalf of the Managed Defense analysts.
Handling Incomplete Evidence
Operating at massive network scale means that a data source will inevitably fail on occasion. A comparison query may time out, vital metadata might be missing, or a threat intelligence lookup may return no matching records. To ensure operational resilience, the system retains whatever evidence has already been successfully collected while formally documenting the data gap.
The resulting advisory explicitly distinguishes between different operational states. If global telemetry is temporarily unavailable, the system can accurately describe what appears unusual for a specific customer, but it will refrain from asserting whether that pattern is part of a widespread global campaign. When the available evidence is deemed fundamentally insufficient, the system deliberately refrains from making any classification or disposition recommendations whatsoever.
Remediation
A truly useful security recommendation must ultimately lead toward a concrete solution rather than just another administrative ticket. Depending on the threat, the advisory might suggest implementing a new rate-limiting rule to combat an abusive traffic path, deploying a WAF custom rule to block a specific signature, or adjusting overarching DDoS protection settings. For fully managed customers, Managed Defense analysts can apply these suggested rules directly; other customers receive their recommendations cleanly delivered within their dashboard and via their chosen alert notification path.
Ultimately, the human Managed Defense analyst remains fully responsible for the final decision and any corresponding mitigation steps. Every alert and case includes the transparent evidence behind the AI agent’s recommendation, empowering analysts to reach a well-founded conclusion by either accepting or updating the AI agent’s advice.
What Comes Next
Managed Defense analysts remain the ultimate arbiters of human judgment in the security pipeline. The new AI agent harness simply handles more of the repetitive, high-volume work: assembling complex investigations, connecting related events, and surfacing the exact evidence underlying each recommendation. Over the coming quarters, Cloudflare plans to introduce a Custom Managed level that offers even greater flexibility tailored to the unique needs of individual organizations.
The company also plans to explore continuous AI agents capable of monitoring Cloudflare traffic in real time to surface subtle threat patterns that fixed rules and static thresholds might otherwise miss.
An early beta of the system is currently available within Cloudflare Managed Defense for eligible application-security alerts and cases. Organizations already utilizing Cloudflare WAF, DDoS protection, Magic Transit, or other supported products are encouraged to speak with their enterprise account teams about integrating Managed Defense into their security posture.
Leave a Reply