Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

Building an evidence-grounded agentic security operations harness on Cloudflare

Blog post from Cloudflare

Post Details
Company
Date Published
Author
-
Word Count
1,842
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

Cloudflare describes a multi-agent AI system for its Managed Defense service designed to reduce the workload of security analysts handling large volumes of related alerts. Rather than relying on a single general-purpose model, the system first uses deterministic reconnaissance workflows to collect versioned, scoped evidence on customer activity, detections, enforcement outcomes, historical decisions, and network observations, then filters likely false positives with Cloudflare’s Clef decision model. Alerts requiring further review are evaluated in parallel by specialized agents focused on traffic behavior, customer history, privacy-preserving global telemetry, and admitted threat intelligence, with a separate synthesis agent producing an advisory constrained by validated evidence and approved classifications. The platform records missing or unavailable data explicitly, validates citations and customer boundaries in application code, and allows analysts to inspect, revise, or act on recommendations such as rate limits, WAF rules, or DDoS protection changes. Cloudflare says human Managed Defense Analysts retain responsibility for final decisions, while the early beta is available for eligible application-security alerts and cases, with plans for more customizable and continuous monitoring capabilities.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 24 No monthly metrics for this publish month.
LLM 2 No monthly metrics for this publish month.
Zero Trust 1 No monthly metrics for this publish month.
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.