The Observability Gap in a Distributed Enterprise
The traditional enterprise network was a contained environment. Employees worked from physical offices, authenticated at the edge, and accessed applications hosted on-premise. Network taps at these controlled entry points gave administrators complete visibility into traffic and operations.
That model no longer reflects how businesses operate. Employees now connect from anywhere, and the application stack is a mix of on-premise and SaaS services. This fragmentation creates a critical observability problem: SaaS applications live outside the enterprise perimeter, limiting security teams' visibility into how data is accessed and shared. For what remains on the corporate network, administrators are forced to stitch together network taps, flow data, synthetic probes, and disconnected dashboards to gain even partial insight.
A Single Pane for Network Troubleshooting
Cloudflare One Observability is being built to consolidate data from across the Cloudflare One SASE platform into a single troubleshooting experience. Instead of moving between separate tools for VPNs, firewalls, and policies, customers will be able to diagnose issues with enterprise applications and network connectivity in one place. This approach is intended to address several common operational pain points.
Bandwidth Monitoring Across Branches
Determining which applications consume the most bandwidth across distributed office locations traditionally requires installing taps or collecting flow data at each site, then building custom aggregation tools. Because Cloudflare One products run on the same infrastructure, the platform handles that collection and aggregation automatically, letting engineers move directly to visualizing usage patterns and resolving the underlying problem.
Security Posture and Attack Visibility
Assessing network vulnerability typically means auditing separate applications to understand VPN, firewall, user policy, and endpoint status. With these functions consolidated on a single platform, administrators can review their security posture from one vantage point. The experience also surfaces security patches that Cloudflare applies automatically, along with indicators of whether the network has been targeted by specific attacks.
Latency and Performance Diagnostics
Slow application performance is a notoriously difficult problem to isolate, especially for remote employees. The Cloudflare One architecture uses single-pass inspection: when a request lands on a server, it moves through each configured service on that same machine. This design makes it feasible to trace the end-to-end path of a request and pinpoint a bottleneck or misconfiguration without correlating logs from separate systems.
The Network as a Foundation for Analytics
Cloudflare One Observability is built on the company's global network, which spans data centers in 270+ cities across over 100 countries. Every Cloudflare One product runs on every server, so data pipelines and logging services share the same infrastructure. This is a contrast to zero trust platforms assembled through acquisitions, where siloed applications complicate data sharing. The unified design gives customers access to tools like Instant Logs for live network data and ABR analytics for large-scale data analysis.
Evolution of a Platform
Cloudflare has operated its foundational network since 2009, and Cloudflare One Observability represents the latest step in applying that infrastructure to the zero trust transition. The product is still under construction, and interested customers can join a wait list to gain access when it becomes available.



