Private beta · 20 seats Cloudflare fleet operations Est. 2026
Features

Everything, by the job you came to do.

Seven jobs. Every tier gets all of them — no feature or integration is held back for a higher plan.

Ask

Questions in plain language, answered against Cloudflare's analytics API directly. The server injects the zone, so a question can never reach one outside your context.

  • Arbitrary analytics. traffic, status codes, geography, ASNs, paths, user agents — the model writes the GraphQL, you read the answer
  • Who is attacking this zone. with severity and a verdict per source
  • Everything you've configured. DNS, WAF rules, cache rules, rate limits, managed rulesets, access rules, zone settings, edge and platform config
  • Plan-aware degradation. denied fields are dropped and retried, denied datasets isolated so one doesn't starve the rest, span caps clamped, sampling reversed so counts are real. Free zones degrade instead of failing
  • Conversations kept indefinitely. nothing expires

See

Requests rendered live on a globe, from the client's geography to the Cloudflare colo that served them. Thirty-minute rolling window, ten-second poll.

  • Render modes. pulse, flow, heat, trace, hex-binned bars
  • All 157 points of presence. as a layer, scaled against camera distance to stay legible at any zoom
  • Day/night terminator. following the real sun
  • DVR. pause, scrub, 24-hour replay
  • Fleet view. every zone on one globe, colour-coded per site
  • Honest status semantics. 2xx served, 3xx redirected, 4xx–5xx rejected. A redirect is never counted as a hit
  • Composable dashboard. a widget grid you arrange and save: traffic, security, performance, origin health, network, fleet overview, Google Analytics, and any chart you've built
  • Graph builder. ad-hoc charts against Cloudflare analytics; the model proposes a visualisation for any result set; save the ones you keep to a library
  • Zone and incident reports. hourly traffic, status mix, top paths, countries, ASNs and user agents, highlights written in prose — each rendered as a page you can share with a client, or export as CSV

Investigate

Traffic classified into nine attack categories with a composite severity score per source — built to be right about what isn't an attack, not just what is.

  • Nine categories. WordPress brute force, CMS and plugin probing, secrets and config scanning, admin panel probing, path traversal, SQLi/XSS, shell and upload probes, credential stuffing, scanner tooling
  • False positives designed out. static assets, uploads, /cdn-cgi/, well-known files, recognised crawlers including AI crawlers, research scanners like Censys and Shodan, and anything that was requested and served — all excluded, and listed with the reason rather than silently dropped
  • Per-attacker evidence. status mix, paths served, methods, hosts, user agents, and whether the same source is hitting your other zones
  • Blast radius preview. a proposed rule is run against your real traffic before it exists
  • Automatic mitigation, off by default. managed challenge only, never block; single IPs only, never a range; requires a corroborating pattern, not just volume; refuses anything the origin served; capped hourly; auto-expiring; every decision logged and revertable

Operate

Every change through the same nine-step pipeline: propose, classify, preview, approve, drift-check, execute, read back, audit, revert.

  • DNS. create, update, delete — admin only, with apex and wildcard detection
  • WAF. custom rules, skips, rate limiting, managed rulesets, Super Bot Fight Mode
  • Protections. IP access rules, lockdowns, AI-bot blocking
  • Cache and rules. cache rules, purge by URL / host / tag / everything; redirect, rewrite, header, configuration and origin rules
  • Zone settings and lifecycle. SSL mode, minimum TLS, security level, HSTS; create, pause, activation checks
  • Bulk apply. one change across a saved group of zones, with a separate acknowledgement above a threshold

Monitor

Detectors that watch, incidents that get investigated, and channels your team already uses.

  • Detectors. firewall block surge, bot score surge, cache-hit-ratio drop, latency anomaly, origin reachability, plus custom detectors composed in natural language
  • Incidents. deduplicated, acknowledged, resolved, with an AI investigation of probable cause and a suggested fix — an investigator that may not propose DNS changes, deletes or WAF skips
  • Channels, by name. Email through Resend, SendGrid, Mailgun or any SMTP server · Slack incoming webhooks · Microsoft Teams via Power Automate workflows · PagerDuty events · SMS through Twilio · generic webhooks (JSON, signed) for anything else
  • Per rule, per channel. each detector subscribes to the channels it should reach; a test send from the channel screen; a delivery log showing what went where and whether it arrived
  • Live stream. alerts pushed to the browser as they happen

Connect

Everything Zonesteward reads from, writes to, or talks through. Bring your own accounts for all of it; credentials are stored encrypted and used only for your workspace.

  • Cloudflare. any number of API tokens across any number of Cloudflare accounts; the connection wizard builds the exact token-creation link and tells you what the pasted token can do
  • Anthropic. your own API key; usage billed to you at Anthropic's rates, never marked up
  • Google Analytics 4. OAuth into the GA4 properties you can already see, to put site analytics beside Cloudflare traffic on the same dashboard
  • Email. Resend, SendGrid, Mailgun, or plain SMTP
  • Chat. Slack, Microsoft Teams
  • Paging. PagerDuty
  • SMS. Twilio
  • Anything else. signed JSON webhooks on every alert, so your own systems can react

Govern

Multiple clients, multiple tokens, multiple people — and a record of every one of them.

  • Fleet roster. every zone across every token, with its plan tier
  • Zone groups. named collections for bulk work and for scoping what a client sees
  • Sign in with. Google, Microsoft or GitHub, or an emailed link — no passwords to hold. Only provider-verified addresses can create an account
  • Share links. hand a client a link to their zone, a group, a dashboard or a report — no login, time-limited, revocable, and never carrying more than the role of the person who made it
  • Roles. owner, admin, user, viewer, enforced at three layers
  • Audit trail. every attempt, successful or not
  • Cloudflare error log. every refusal classified and attributed, so plan limits become measured rather than assumed
  1. 01You
  2. 02Your fleet
  3. 03Fit
Who should we write back to?

Takes about two minutes.