Domain Scoped Roles Go GA for Enterprise Accounts

Cloudflare has announced general availability of Domain Scoped Roles, a feature that lets account owners limit user permissions to individual domains or groups of domains rather than granting account-wide access.

The capability addresses a common operational need: allowing development and pre-production domains to remain accessible to a broader team while restricting production domains to a smaller set of authorized members. With Domain Scoped Roles, a user without explicit access to a production domain cannot make changes to it.

The feature is rolling out across all Enterprise accounts, and affected customers will be notified by email when it is enabled. Existing account-level permissions will not change, and all legacy account-wide roles remain available for assignment. Enterprise customers who want early access can contact their Customer Success Manager.

Inviting Users and Assigning Scope

To use Domain Scoped Roles, navigate to the members page in the Cloudflare dashboard. From there, you can invite new users or modify permissions for existing members.

When inviting one or more users, the scope selection list offers three options:

  • All domains — grants account-wide access, with all legacy roles available at this level
  • A specific domain — restricts access to that domain only
  • A domain group — applies a predefined set of domains

After selecting a user and scope, you can assign one or more roles to define the specific permissions granted. Before sending the invite, a confirmation screen shows the users, scope, and roles selected.

Managing Domain Groups

Domain Groups allow account owners to grant access to multiple domains at once, and to update that access centrally. Domains can be added or removed from a group, automatically adjusting permissions for all users who were granted access to it. This reduces the operational overhead of managing user access individually.

Domain Groups can be created in two places:

  • Through the member invitation flow
  • Directly from Account Configurations → Lists

When creating a group, you select the domains to include, and the group becomes available for use when inviting users.

Underlying Authorization Changes

This release marks a step in Cloudflare's migration to a new authorization system designed for scale. The architecture is intended to support expansion of these capabilities to more products in the future, giving customers finer-grained control over team access across Cloudflare's services.