William OGOU Cybersecurity Blog

Published

- 11 min read

Cloudflare Agentic SOC: Managed Defense AI Harness Explained

img of Cloudflare Agentic SOC: Managed Defense AI Harness Explained

Security alerts rarely arrive one at a time. A single alert can trigger a manual investigation while similar detections queue up, each requiring an analyst to gather evidence, decide what is related, and determine whether the activity is actually malicious.

On October 7, 2026, Cloudflare described a new answer it is testing inside Cloudflare Managed Defense: an evidence-grounded, multi-agent security operations harness. The system gathers customer and network context, filters known noise, and asks specialist AI agents to analyze the remaining alerts. It gives Managed Defense Analysts a consolidated advisory with its supporting evidence and gaps.

The important distinction: this is an early beta for eligible application-security alerts and cases, not a fully autonomous SOC. Cloudflare says application code fixes customer scope before models see results, and the models cannot take action on the analysts’ behalf. Here’s how the harness works, what Cloudflare customers can access, and what new research suggests about the future of agentic SOCs.

What to Remember

  • Available in early beta: The harness is part of Cloudflare Managed Defense for eligible application-security alerts and cases; it is not a general self-service agent for every Cloudflare account.
  • Evidence before AI: Versioned, deterministic reconnaissance collects customer identity, detection history, traffic baselines, enforcement outcomes, and network observations before model analysis begins.
  • Clef filters and scores: Cloudflare’s open-source decision model helps route routine noise and assess whether evidence supports a classification.
  • Four specialist agents investigate: Traffic, customer history, privacy-preserving global telemetry, and admitted threat intelligence are reviewed in parallel, then synthesized into an advisory.
  • Scope and actions stay controlled: Code validates evidence citations and tenant scope; a Managed Defense Analyst remains responsible for decisions and mitigations.
  • No published performance score yet: Cloudflare describes the architecture and beta availability but does not report a measured reduction in alert volume, investigation time, or classification error in this announcement.

From an Alert Queue to a Grounded Advisory

Cloudflare’s harness is designed to move an alert through a predictable sequence before asking AI models for analysis:

Cloudflare Managed Defense Agentic SOC Harness

The sequence is deliberately not “give one model every tool and ask it to investigate.” Cloudflare says its first general-purpose-agent prototype could make unsupported claims, drift outside the intended scope, and blur “not checked” with “checked and not found.” The new design moves evidence retrieval, scope enforcement, and citation checks into application code.

Recon First: Collect Facts Before Inference

Before any language-model analysis, deterministic code runs a fixed set of versioned API workflows. The resulting reconnaissance snapshot can include:

  • Customer identity and the investigation’s scope
  • Detection history and prior analyst dispositions
  • Traffic baselines and relevant network observations
  • The enforcement control that fired and its outcome
  • Source, version, and timestamp for each collected item

Cloudflare sees both the request and the enforcement action applied to it. That lets the investigation connect the triggering behavior to the control that responded, instead of treating an alert description as proof that an attack succeeded.

Keeping retrieval fixed also makes the investigation replayable. If two model runs receive the same versioned snapshot, differences in their analysis are less likely to come from different queries or changing inputs. The fixed evidence package provides a record analysts can inspect and a basis for evaluating future versions of the harness.

Clef Filters Noise Before Specialist Agents Run

Most alerts are not incidents. Repeatedly paging analysts for a familiar traffic pattern creates alert fatigue and makes unusual events harder to spot. Cloudflare uses Clef, its open-source decision model running on Workers AI, for fast triage and evidence scoring.

Known high-volume noise can be classified deterministically as passive when it arrives. It remains available as investigation context but does not enter the active queue. For other alerts, Clef compares the reconnaissance data with prior detections and analyst dispositions, along with traffic behavior, to help decide whether specialist analysis is warranted.

Clef is a decision model rather than the free-form report writer: it returns among a constrained set of possible answers. Cloudflare uses approved OpenAI Daybreak Defense Network and Anthropic models including GPT-5.6 Cyber and Mythos for deeper model-backed analysis. The design gives a fast classifier the routine routing work and reserves larger models for alerts that need more interpretation.

Four Specialist Agents, Then a Constrained Synthesis

For alerts that merit deeper review, a coordinator runs four specialist agents in parallel:

  1. Traffic analysis reviews request behavior, historical changes, and enforcement outcomes.
  2. Customer context reviews earlier alerts, dispositions, and analyst decisions for that customer.
  3. Global telemetry compares activity against privacy-preserving Internet-wide aggregates.
  4. Threat intelligence checks indicators already admitted to the alert or case.

Each specialist has a narrow task and works from the investigation’s evidence, rather than independently expanding scope or querying arbitrary customer data. A synthesis agent combines the typed findings into one advisory, but Cloudflare says it cannot fetch new evidence or select a classification outside the approved vocabulary.

The separation is intended to make conclusions easier to challenge. If traffic analysis sees suspicious behavior but customer history shows the same pattern was repeatedly benign, the advisory can expose both pieces of context instead of flattening them into a single opaque verdict.

Global Context Without Cross-Customer Records

One Cloudflare-specific advantage is the network view. An IP address targeting one site, scanning thousands of sites, or appearing for the first time may have very different significance. Cloudflare says the global telemetry specialist uses aggregated signals only; it does not receive another customer’s individual records or identity.

The context draws on signals associated with Cloudflare’s CDN, WAF, DDoS protection, Turnstile, Rate Limiting, and Cloudforce One threat intelligence. Global prevalence informs the assessment, but it is not treated as a verdict: a pattern that is common across the network does not automatically mean that a specific customer is part of a campaign.

Customer history is also evidence, not an automatic allowlist. The reconnaissance dossier records how often an alert fired, how analysts previously handled it, and whether it was closed as a false positive. That history can help distinguish a repeat benign pattern from a first sighting, while current evidence remains visible for analyst review.

From Evidence to Decision Including What Is Missing

Before analysis, the harness creates a versioned evidence package containing the subject, scope, time anchor, admitted evidence, policy versions, sources, and coverage gaps. Specialists must cite items from that package. Application code checks that each citation exists, belongs to the investigation, and supports the attached claim; unsupported findings are corrected or recorded as limitations.

Clef then helps assess whether the evidence is sufficient, whether sources contradict each other, and which classification or disposition from a deterministically reduced list is appropriate.

Cloudflare's evidence-to-decision flow for Managed Defense investigations

The system distinguishes three outcomes when evidence is incomplete:

  • Not checked the source was not queried.
  • Checked, no match the source responded but had no matching result.
  • Checked, evidence supports absence the result itself provides evidence that an indicator or event was not present.

If global telemetry is unavailable, the system can still describe behavior relative to that customer’s baseline, but it cannot claim the pattern is widespread. If the remaining evidence is insufficient, Cloudflare says the harness makes no classification or disposition recommendation. Showing the gap is safer than filling it with a plausible-sounding guess.

Cloudflare’s Developer Platform Runs the Harness

Cloudflare also uses this project to showcase a stateful, multi-step application built on its developer platform:

Platform componentHarness role
WorkersAdmit evidence, enforce scope, and validate model findings in application code
WorkflowsCoordinate investigation stages, persist completed work, and retry failed steps without discarding validated results
D1Store investigation and advisory state
R2Hold bounded context and evidence artifacts
Durable ObjectsPersist case-chat state
Flue + AI SearchSupport case-chat orchestration and enrich its context
Workers AI + ClefProvide fast, structured triage and evidence scoring

The architecture separates the tools that retrieve and authorize data from models that interpret it. It also saves completed stages so a transient lookup or workflow failure does not force the whole investigation to start over.

What the Analyst Receives and What the Agent Cannot Do

The final output is an advisory using terms analysts already work with: affected surface, enforcement outcome, relevant controls, and next step. A recommendation may suggest a Rate Limiting rule for an abusive path, a WAF custom rule for a signature, or a DDoS protection change.

For fully managed customers, Managed Defense Analysts can apply suggested rules. Other customers receive recommendations in the dashboard and through their chosen alert path. In either case, the Managed Defense Analyst remains responsible for the decision and mitigation. The harness may help assemble and correlate evidence; it is not authorized to cross customer boundaries or execute a response on its own.

Cloudflare says the early beta is available to eligible Cloudflare Managed Defense customers for application-security alerts and cases. Customers using Cloudflare WAF, DDoS protection, Magic Transit, or another supported product can contact their enterprise account team about adding Managed Defense. This is not a general-purpose “connect your SIEM and let agents respond” product today.

How to Evaluate an Agentic SOC Harness

Cloudflare’s announcement describes the design and early-beta availability, but does not publish measurements for accuracy, false-positive reduction, analyst time saved, or mitigation outcomes. Security teams assessing this type of system should ask for a baseline and measure the entire investigation, not just whether the final label looks right:

  1. Evidence grounding: What percentage of factual claims cite valid, in-scope evidence? How often are citations missing or fail to support the claim?
  2. Coverage and uncertainty: Does the report distinguish not checked, no match, and evidence of absence? How does it behave when a source times out?
  3. Decision quality: Compare classifications and dispositions with analyst-reviewed outcomes, including false-positive and missed-threat rates.
  4. Operational impact: Measure time to a usable advisory, analyst edits and overrides, case-resolution time, and whether a recommendation led to a verified mitigation.
  5. Safety and scope: Test cross-tenant isolation, prompt-injection resistance, prohibited actions, and whether any model can execute changes without authorization.
  6. Replayability: Re-run investigations against fixed snapshots and versioned policies to understand whether differences come from model interpretation or changed evidence.

For the next generation of agentic SOCs, evaluation should include the investigation trajectory what the system queried, what it could not verify, what evidence supports each claim, and whether the proposed response stayed within policy. The security path is part of the product.

Conclusion: The Harness Is the Product

Cloudflare’s Managed Defense beta is a useful example of how agentic AI can enter security operations without handing the SOC to an unconstrained model. The central design choices are practical: deterministic reconnaissance first, narrow specialist agents, validated citations, explicit coverage gaps, privacy-preserving global context, and a human analyst who remains accountable for remediation.

The future direction is more continuous correlation and, eventually, carefully bounded action. But deployment maturity should be measured by evidence quality, safety, and analyst outcomes not by the number of agents or the level of autonomy. For now, Cloudflare’s harness is best understood as an analyst-augmentation beta with a clear path to broader customization, not a self-driving SOC.

To further enhance your cloud security and implement Zero Trust, contact me on LinkedIn Profile or [email protected].

Frequently Asked Questions (FAQ)

What is Cloudflare’s agentic SOC harness?

It is an early-beta, multi-agent security operations harness inside Cloudflare Managed Defense. Deterministic code gathers and scopes evidence first; Clef filters and scores alerts; specialist AI agents investigate; and Managed Defense Analysts review the resulting advisory.

Which AI models does Cloudflare use in Managed Defense?

Cloudflare says initial analysis and scoring use Clef, its open-source decision model on Workers AI. Deeper model-backed analysis can use approved OpenAI Daybreak Defense Network and Anthropic models, including GPT-5.6 Cyber and Mythos.

Can the Managed Defense AI agent automatically block traffic?

The described harness produces an advisory and does not act on behalf of Managed Defense Analysts. Analysts remain responsible for decisions and mitigations. For fully managed customers, analysts can apply suggested WAF, Rate Limiting, or DDoS changes; other customers receive recommendations.

How does Cloudflare reduce hallucinations and scope drift?

Cloudflare moves evidence retrieval and customer-scope enforcement into deterministic application code. Specialist agents work from a versioned evidence package and must cite its items; code verifies that citations exist, belong to the investigation, and support the claim. The synthesis agent cannot fetch new evidence or choose an unapproved classification.

Who can access the Cloudflare Managed Defense beta?

The early beta is available for eligible application-security alerts and cases in Cloudflare Managed Defense. Customers using Cloudflare WAF, DDoS protection, Magic Transit, or another supported product should contact their enterprise account team to discuss adding Managed Defense.

What is next for agentic SOCs?

Cloudflare plans to add a Custom Managed level and explore continuous agents that monitor traffic for patterns fixed rules may miss. More broadly, future SOC systems are likely to add bounded autonomy gradually, while retaining human review for ambiguous or high-impact responses and measuring evidence quality, safety, and operational outcomes.

Resources


William OGOU

William OGOU

Need help implementing Zero Trust strategy or securing your cloud infrastructure? I help organizations build resilient, compliance-ready security architectures.