Building an evidence-grounded agentic security operations harness on Cloudflare
Blog post from Cloudflare
Cloudflare describes a multi-agent AI system for its Managed Defense service designed to reduce the workload of security analysts handling large volumes of related alerts. Rather than relying on a single general-purpose model, the system first uses deterministic reconnaissance workflows to collect versioned, scoped evidence on customer activity, detections, enforcement outcomes, historical decisions, and network observations, then filters likely false positives with Cloudflare’s Clef decision model. Alerts requiring further review are evaluated in parallel by specialized agents focused on traffic behavior, customer history, privacy-preserving global telemetry, and admitted threat intelligence, with a separate synthesis agent producing an advisory constrained by validated evidence and approved classifications. The platform records missing or unavailable data explicitly, validates citations and customer boundaries in application code, and allows analysts to inspect, revise, or act on recommendations such as rate limits, WAF rules, or DDoS protection changes. Cloudflare says human Managed Defense Analysts retain responsibility for final decisions, while the early beta is available for eligible application-security alerts and cases, with plans for more customizable and continuous monitoring capabilities.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 24 | No monthly metrics for this publish month. | |||
| LLM | 2 | No monthly metrics for this publish month. | |||
| Zero Trust | 1 | No monthly metrics for this publish month. | |||
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.