Why Cloudflare’s multi‑agent AI security harness matters for analysts

According to Cloudflare Blog, the company has rolled out a multi‑AI‑agent security operations harness that runs on its Managed Defense platform. The system promises to reduce the time analysts spend on repetitive evidence gathering while keeping human judgment in the loop.
The alert paradox and the single‑agent dead end
Security operations teams often face a flood of alerts that arrive together. When a single AI agent is handed the whole investigation, Cloudflare’s prototype showed three problems:
- Context became authority – the model treated a detection hypothesis as proof, blurring the line between a flag and a confirmed compromise.
- Scope drift – the agent sometimes queried the wrong account or time window because the prompt did not enforce boundaries.
- Failure disappeared – a timeout was indistinguishable from a “not found” result, letting missing data masquerade as a negative.
In practice, these issues led the model to hallucinate claims that the evidence did not support.
A two‑stage workflow: deterministic recon first
The new harness separates evidence collection from model inference. Before any language model runs, deterministic code executes a fixed set of reconnaissance workflows via version‑controlled API calls. It pulls:
- Customer identity and detection history
- Traffic baseline and enforcement outcomes
- Network observations linked to the alert
Each datum is stored with its source, version, and timestamp. Because the snapshot is reproducible, two runs of the specialist agents see identical inputs, making differences traceable to interpretation rather than retrieval.
Early triage with a lightweight model
Most alerts turn out to be harmless repeats. Cloudflare routes these through a fast triage model—Clef, running on Workers AI—to decide whether an alert should be escalated. The model checks:
- Has this event been seen for the customer before?
- What disposition did analysts give it previously?
- Does the traffic look like normal human activity?
If the score exceeds a false‑positive threshold, the alert skips the specialist agents. This early filter keeps the specialist queue lean and ensures analysts are not distracted by noise.
Specialist agents stay narrow and accountable
For alerts that survive triage, a coordinator agent launches four specialist agents in parallel:
| Specialist | Focus area |
|---|---|
| Traffic analysis | Request behavior, enforcement history |
| Customer context | Prior alerts, analyst decisions |
| Global telemetry | Internet‑wide patterns, privacy‑preserving aggregates |
| Threat intelligence | Indicators already attached to the alert |
Each specialist receives only the evidence it needs and returns typed findings. A synthesis agent then merges those findings into a single advisory, but it cannot fetch new data or choose a classification outside an approved vocabulary. By keeping tasks narrow, the system makes unsupported claims easier to spot and audit.
Global context without leaking customer data
The global telemetry specialist draws on Cloudflare’s worldwide network—CDN, WAF, DDoS, Turnstile, Rate Limiting, and Cloudforce One—using only aggregated signals. It never sees another customer’s raw records, preserving privacy while still giving weight to patterns such as a scanning IP that appears across many sites.
How evidence turns into a decision
Before the specialist agents run, the platform builds a versioned evidence package containing:
- Subject, scope, and time anchor
- Admitted evidence and policy versions
- Gaps where a lookup timed out or returned no data
Application code validates that every claim the specialists make cites an item from this package. A second pass of Clef scores the evidence, picks a deterministic classification from a reduced list, and produces a disposition (e.g., block, rate‑limit, ignore). The final advisory lists the evidence, the reasoning, and a concrete mitigation such as a new WAF rule.
What actually changes for security teams?
The trade‑off is tighter control versus flexibility. By moving scope enforcement and evidence collection out of the language model, Cloudflare eliminates hallucinations but also limits the model’s ability to explore beyond the pre‑collected snapshot. In practice this means analysts get faster, more reliable triage, but they must still intervene when evidence gaps appear. The system’s reproducibility is a win for audit trails; however, it introduces an extra engineering step—maintaining the deterministic recon scripts and versioned APIs.
Who should care? Teams already using Cloudflare’s WAF, DDoS, or Magic Transit will see the most immediate benefit, because the harness already has access to the necessary telemetry. Smaller shops that rely on third‑party SIEMs may find the integration effort outweighs the speed gain.
What to watch next? Cloudflare mentions plans for a “Custom Managed” tier with more flexibility and continuous‑monitoring agents that surface patterns missed by static rules. Watch for how they expose the custom‑agent API; if it opens up, the balance between control and flexibility could shift again.
Quick test you can run today
If you already have Cloudflare Managed Defense enabled for an application‑security alert, try the following on a single recent alert:
- Open the alert in the dashboard and note the “triage score” shown by Clef.
- Click the “view evidence package” link to see the collected sources and any gaps.
- Compare the advisory’s recommendation with the raw evidence—verify that every claim is cited.
- If the recommendation seems overly aggressive, use the “edit” button to adjust the mitigation and observe how the system records the change.
Even a brief walk‑through lets you see whether the multi‑agent approach reduces noise without hiding the reasoning behind a black‑box model.


