The problem with batch alerting

Security alerts do not arrive evenly spaced. A single event can ripple across an environment, and simultaneous detections force an analyst to work out which ones are connected and what they collectively mean. Under that load, even experienced Managed Defense Analysts drown. Cloudflare's answer is a multi-AI-agent security operations harness, now built into Cloudflare Managed Defense, that absorbs more of this work at Cloudflare scale.

The harness compresses the chores that dominate analyst time: gathering data, connecting and aggregating detections, and accounting for missing sources while new alerts keep landing. Cloudflare supplements the analysis with approved models through the OpenAI Daybreak Defense Network and its Anthropic partnership, including GPT-5.6 Cyber and Mythos. First-pass analysis and scoring run on Clef, Cloudflare's open-source decision model.

Even a sophisticated SIEM leaves a long tail of human review. Which alerts should be silenced? Which warrant action? Which are false positives, which are true, and which should pull in the incident team? The harness answers those questions as a consolidated view for analysts, surfacing related alerts, admitted evidence, visible gaps, and recommended next steps.

Where a single agent breaks down

Cloudflare's first prototype handed one general-purpose agent the entire investigation. It produced usable analysis, but it also asserted claims the evidence did not support. Telemetry, detector descriptions, policies, and threat intelligence were flattened into a single prompt, and their distinct roles blurred together. Three failure modes recurred:

  • Context became authority. A detection is a hypothesis, not proof that an exploit succeeded or an attack occurred, and a broad agent tends to lose that distinction.
  • Scope drifted. An agent can query the wrong account, time range, or source — a prompt is not a boundary.
  • Failure disappeared. A timed-out lookup may be indistinguishable from a lookup that ran and found nothing.

The fix was architectural: evidence collection and scope enforcement moved into application code, ahead of any model analysis.

Deterministic reconnaissance before inference

Placing an agent at every step is tempting. The front half of this harness has none. Before inference is called, deterministic code runs a fixed set of reconnaissance workflows through versioned API calls, collecting the customer's identity, detection history, traffic baseline, enforcement outcome, and network observations. Every datum is stored with its source, version, and timestamp.

Because Cloudflare sees both the request and the action applied to it, an investigation can link the behavior that triggered an alert to the control that fired and that control's outcome. The fixed snapshot also makes evaluation reproducible: agents that fetch their own data can disagree simply because their inputs changed, whereas replaying one snapshot means any divergence between specialists comes from interpretation rather than retrieval.

Triage as the first filter

Most alerts are not incidents. A rule firing repeatedly on known traffic trains analysts to ignore pages, which is how real incidents get missed. A lightweight triage model therefore compares each alert against its recon data: has this event been seen for this customer before, how did analysts dispose of it previously, and does the traffic match normal human behavior? Alerts scored as likely false positives skip the specialist agents entirely.

Clef on Workers AI handles this fast agentic reasoning. Known high-volume noise is classified deterministically as passive on arrival — still available as context, but never entering the active queue.

Four specialists, one synthesis step

For alerts that survive triage, a coordinator agent runs four specialists in parallel:

  • Traffic analysis — request behavior, historical changes, enforcement.
  • Customer context — earlier alerts, dispositions, analyst decisions.
  • Global telemetry — comparison against privacy-preserving Internet-wide signals.
  • Threat intelligence — indicators already admitted to the alert or case.

A synthesis agent merges their typed findings into a single advisory. It cannot fetch new evidence or select a classification outside the approved vocabulary. Narrow tasks make unsupported claims easier to catch and recommendations easier to audit.

Global signal without customer exposure

A deployed security tool knows its own environment and little beyond it. Cloudflare compares each alert to patterns across its network — an IP hitting one site differs from one scanning thousands, or from one appearing for the first time. The global telemetry specialist works only with aggregates and never receives another customer's individual records or identity.

This view draws features from CDN, WAF, DDoS, Turnstile, Rate Limiting, and Cloudforce One threat intelligence. The synthesis agent weighs global reputation together with customer history, so a globally common pattern can inform a per-customer judgment without automatically implying a widespread campaign.

Prior decisions as admitted evidence

Every evaluation carries its history. The recon dossier records how many times a service alert has fired, how many of those were dispositioned as false positives, and what the analyst concluded. A pattern that has been benign at every prior sighting is a different object from a first sighting, and the specialists are told which they are looking at. Approved background context is retrieved from previous alerts and cases, so yesterday's conclusions feed today's decision rather than being rebuilt.

Related alerts are aggregated into a single case holding evidence, findings, and recommendations. The system joins and correlates deterministically, but confirming actual scope stays with the analyst. A case can accumulate network, application, and Zero Trust evidence over time while retaining provenance for every item.

Evidence packaging and validation

Before analysis begins, the system assembles a versioned evidence package: subject, scope, time anchor, admitted evidence, policy versions, sources, and coverage gaps. Specialists must cite items from that package, and application code verifies each citation exists, belongs to the investigation, and supports the claim attached to it. Findings that fail are corrected or downgraded to recorded limitations.

Clef returns for a second role, scoring the evidence itself: is it sufficient for a decision, and does any of it contradict? From that score, Clef selects from a deterministically reduced list of attack classifications and dispositions.

The pipeline runs on Cloudflare's developer platform. Workers code admits evidence and validates results; Workflows coordinates each stage and persists completed work before the next stage starts, so a failed stage reuses already-validated evidence and findings instead of restarting. D1 holds investigation and advisory state, R2 stores bounded context and evidence artifacts, and case-chat state lives in Durable Objects, uses Flue, and is enriched through AI Search.

A final agent produces an advisory in the vocabulary analysts already use: affected surface, enforcement outcome, relevant controls, next step. Analysts can inspect the evidence, dig further, revise the recommendation, or group alerts into a case. Customer scope is fixed in application code before any model sees results, each specialist receives only the evidence it needs, and no model is granted authority to cross tenant boundaries or to act on the analyst's behalf.

Failure is a recorded state

At network scale, sources fail: a comparison times out, metadata is missing, a threat intelligence lookup returns no match. The harness keeps whatever evidence it already has and records the gap. Advisories separate three conditions — not checked, checked with no matching result, and checked with evidence supporting absence. If global telemetry is unavailable, the system can still say what is unusual for that customer, but it cannot say whether the pattern is widespread. When evidence is insufficient, it issues no classification or disposition.

Recommendations that resolve alerts

A useful recommendation leads to a fix, not a ticket. Advisories may propose a rate limiting rule for an abusive path, a WAF custom rule for a signature, or a DDoS protection change. Fully managed customers have analysts apply the suggested rules; others see recommendations in the dashboard and through their chosen alert path.

Responsibility stays with the analyst in every case. Each alert and case carries the evidence behind the agent's recommendation, so the analyst can accept it, amend it, or overrule it.

Roadmap and availability

Analysts retain judgment while the harness takes on the repetitive work: assembling investigations, connecting related events, and displaying the evidence behind each recommendation. Over the coming quarters Cloudflare plans a Custom Managed level with more per-organization flexibility, and intends to explore continuous agents that watch Cloudflare traffic for patterns fixed rules and thresholds miss.

The early beta is available in Cloudflare Managed Defense for eligible application-security alerts and cases. Customers already using Cloudflare WAF, DDoS protection, Magic Transit, or another supported product can talk to their enterprise account team about adding it.