CLOUDFLARE outlines a shift to an evidence-grounded, agentic security operations harness designed to cope with surges of alerts at scale. The post explains why a single AI agent struggled: it could blur detections into proofs, drift across scope, and conceal incomplete results. To address this, Cloudflare builds the investigation around deterministic reconnaissance before any model runs, collecting identity, detection history, traffic baselines, enforcement outcomes and network observations. This fixed snapshot ensures reproducible evaluation and keeps interpretation separate from data retrieval.
For deeper analysis, the harness uses a coordinator AI that runs four specialist agents in parallel: Traffic analysis, Customer context, Global telemetry, and Threat intelligence, with a synthesis AI producing an advisory. Managed Defense analysts retain final judgment. Global context is drawn from aggregates to protect customer privacy, and evidence is linked to a versioned dossier, including sources, policy versions and coverage gaps.
Clef continues to score evidence and guide classifications, while the application code enforces boundaries and validates results. The system is designed to handle incomplete evidence, explicitly flagging not checked, checked with no result, or checked with evidence supporting absence. Remediation focuses on practical controls (rate limiting, WAF rules, DDoS changes) rather than tickets, with analysts empowered to adjust or override AI recommendations.
The early beta is available to eligible customers of Cloudflare Managed Defense, with plans to extend custom levels and continuous AI monitoring in coming quarters.