Remote Work Raised a Tax Question
For most of business history, determining where an employee worked was straightforward—it's where the office is. But widespread remote work dissolving that link raised a practical problem: employers are obliged to pay payroll taxes based on where work is performed, and if employees can be anywhere, finance and legal teams lose the answer. Employees who crossed state or national borders during the pandemic created a compliance challenge for even normally well-documented organizations, and manual methods—plane tickets, spreadsheets, check-ins—weren't scaling or convincing enough to stand up to scrutiny.
Cloudflare's answer is a new beta feature for Cloudflare for Teams called Workplace Records, which turns existing Access and Gateway logs into country- and state-level location data for every workday. The feature is available now for all Cloudflare for Teams subscribers, and is free to use for up to 50 users.
Workday Logins, Refined into Jurisdiction Data
Workplace Records is built on logins to Cloudflare Access, the Zero Trust service that sits in front of corporate applications. Each time an employee connects, Access checks identity alongside signals like multi-factor method, and also captures from which region the login occurred. That regional data—currently available in country detail within Access logs and Access group rules—is what the Workplace Records feature turns into useful indicators like "this was a workday from Texas."
Crucially, this collection only happens on corporate devices used to log in to work applications. If a laptop stays closed over a weekend, no location is captured. The goal is to produce a payable jurisdiction record, not an employee-tracking dossier. The system deliberately provides resolution only to the level of a taxable jurisdiction, not a street address, keeping the information aligned to what finance, legal, and HR need to satisfy obligations.
Policy Enforcement Without an Address Book
Beyond retrospective records, the underlying regional data is useful in real time. Administrators can configure Access rules to allow connections only from countries where they operate, or block specific countries outright. This works for internal resources as well as SaaS applications. The kinds of scenarios span payroll compliance—some regions impose strict tax penalties for work performed without a local entity—and IP protection, for companies that need to ensure engineering work occurs only in countries where transfer agreements exist.
For daily enforcement, country-specific rules are already available in Access. The company-wide country-by-day reporting view is in development and slated for release later this quarter, with a broader company report due earlier. Users can pull per-user login country data today through the UI or export it to an external SIEM.
Built for the Payroll Team, Not Just the Security Team
The design of Workplace Records pushed against the tendency to hand legal and finance groups raw, unstructured access logs. Instead, the reporting layer summarizes workdays in specific regions per user in a dedicated UI, so payroll staff don't have to triage huge volumes of connection history. That report is free for all Cloudflare for Teams customers.
The next milestone is direct data integration with Human Capital Management (HCM), Human Resource Information Systems (HRIS), Human Resource Management Systems (HRMS), and payroll providers, removing even the intermediate export step.
Cloudflare for Teams customers can start using the feature now, and new subscribers can access Workplace Records at no cost for up to 50 users.



