Platform Security and Management Updates for Enterprise Teams

CIO Week highlights are usually about new products, but many of the most consequential changes are quieter: improvements to how the platform itself handles security, access, automation, and visibility. Over the past year, a series of updates have landed across those foundational areas, aimed at giving enterprise teams tighter control and less operational friction.

Streamlined SSO Setup

Single sign-on is a core requirement for controlling application access, but the original setup flow on the platform left room for improvement. That process has been reworked. Administrators can now configure SSO through the Cloudflare for Teams dashboard by leveraging SaaS Applications in Cloudflare Access, replacing the earlier manual steps with a more guided flow. For enterprise customers not yet using SSO, the recommendation is to coordinate with an account team to enable it. Further user management controls are expected next year.

Zone-Level Access Control

Accounts frequently hold both production and staging zones, which makes centralized management convenient but complicates access control. A beta program called Zone Scoped Roles addresses this by letting members be granted permissions for a specific subset of zones within an account. This allows broad read-only access for most users while restricting edit rights on production zones to those who actually need them. The beta is available on request through the account team.

Terraform Automation Grows

Terraform remains a primary automation path for managing infrastructure, and support for Cloudflare services has expanded considerably over the year:

  • Ten new resources were introduced, bringing the provider to 51 resources.
  • Support was added for the ruleset engine, which underpins Transform Rules, Managed WAF Rulesets, and Managed DDoS Rulesets.
  • A major update to cf-terraforming — the tool that generates Terraform configuration from existing Cloudflare setups — included support for more resources and a reworked interface.

Expanded Notifications and Alert Destinations

Notification coverage has grown to give teams faster awareness of issues. New alert types include DDoS alerts, firewall alerts, Workers CPU usage, and origin 5XX errors. Webhook destinations now reach DataDog, Discord, OpsGenie, and Splunk, joining the existing Slack, Microsoft Teams, Google Chat, and custom integrations. Alert history is available through the API, with UI support planned.

Data Locality Controls

Data residency requirements are tightening, particularly in the EU following the Schrems II ruling. The Data Localization Suite has added the Customer Metadata Boundary, which ensures that end-user traffic metadata for EU customers stays within the EU. This builds on existing capabilities that give customers more control over where data processing and storage occur.

Logging Visibility and Destinations

Logging coverage has been extended across more products, including firewall events, Gateway, Spectrum, and most recently audit logs. Customers can now push logs to any S3-compatible storage platform, and integrations with major analytics providers open up more options for log destinations. Support for storing logs in Cloudflare R2 is also in development.

The platform team also puts its own products into practice: internal sites, security infrastructure, and access management behind the firewall are run on the same services offered to customers. Terraform is used internally to manage security controls at scale, and the security team relies on platform logs for monitoring and threat detection — a dogfooding approach that surfaces the same rough edges customers encounter and turns them into priorities for the roadmap.