Granular account access arrives for every Cloudflare plan
Until now, only customers on higher-tier plans could grant team members access to a subset of their Cloudflare account. Everyone else faced an all-or-nothing choice: either hand over full administrative control or share nothing at all. That changes today. Role-based access controls (RBAC) and the full set of additional roles are rolling out to users on every plan, including FREE and PAYGO.
The intent is straightforward: whether you are a solo operator or a growing business, you can add users to your account while keeping them scoped to only the parts of Cloudflare they actually need.
Why scoped access matters
Restricting access to the minimum required for a job is a core security principle. The reasoning is practical. If a user's credentials are compromised, the damage they can do is bounded by their permissions. A read-only account that falls into the wrong hands generates far less fallout than an administrative one, where an attacker could alter site behavior or critical configuration.
Scoped access also reduces the risk of accidents. Team members who do not work with, say, firewall rules or DNS settings should not be able to change them. Granting access on a per-product basis keeps operational changes in the hands of the people responsible for them.
The role model at Cloudflare
Roles in Cloudflare are collections of permissions grouped around product suites. Because Cloudflare functions as critical infrastructure for many customers, roles are designed so that you can give team members the access they need without opening up unrelated parts of the account. Assigning a role scopes a user to the products they will interact with.
Once RBAC is enabled for your account, navigate to "Manage Account" and then "Members" in the left sidebar to see the available roles.
Each role grants access to a distinct subset of the Cloudflare offering. For a growing team, this means you can delegate firewall and DNS administration to a network admin, billing tasks to a bookkeeper, and Workers development to a developer. No one gets more access than their job requires.
The role list includes a Super Administrator role, which lets you grant full administrative privileges to another user without ever sharing your password or two-factor authentication credentials.
Applying roles in practice
Adopting RBAC begins with an audit of your team's responsibilities. Identify what each person works on, then assign them the role or roles that correspond to those duties. Roles are additive: you can grant a single user multiple roles, so as their responsibilities expand, you grow their access incrementally rather than giving them everything up front.
Rollout schedule
The rollout of RBAC to all plans happens over the next few weeks. When the roles appear in your account, refer to Cloudflare's documentation for a detailed breakdown of each role's permissions.



