Gateway Logging Gets Granular
Cloudflare Gateway, the company's Secure Web Gateway with Zero Trust browsing controls, now offers administrators finer-grained control over what activity is logged and who can see it. The new capabilities roll role-based dashboard access and selective logging into the platform, giving teams a middle path between capturing everything and capturing nothing.
Beyond the All-or-Nothing Approach
Gateway replaces legacy firewalls by extending an organization's security perimeter to users wherever they are. The client (WARP) installs on macOS, Windows, iOS, Android, ChromeOS, or Linux devices, sends identity alongside outbound layer 4 traffic, and Cloudflare applies layer 7 HTTP and layer 4 network filters across its network of over 250 cities.
When proxy and TLS decryption are enabled, Gateway logs all traffic and surfaces it in the dashboard as raw logs and aggregate analytics. But that default raises a question: what happens when an administrator doesn't want to retain logs, or doesn't want every member of the security team viewing them?
Older solutions typically forced a trade-off. Turning logging off avoided storing personally identifiable information (PII) altogether, but it also killed visibility for investigating security events. Support tickets like "why was I blocked?" became nearly impossible to answer without any logged context. The new settings are designed to close that gap without forcing teams to retain everything.
Role-Based Access and Selective Logging
Two controls are now available. First, role-based dashboard access introduces granular permissions for the logging and analytics pages. Users with account access will see PII redacted from their dashboard view by default; specific team members can be delegated the ability to review and search using PII when an event calls for deeper investigation.
Second, administrators can choose what level of logging Cloudflare stores on their behalf, per component—DNS, Network, or HTTP. The options are the same for each: Capture all, Capture only blocked, or Don't capture.
Selective logging does not mean no logs—it means Cloudflare never stores them. Combined with the existing Logpush service, teams can stop storage on Cloudflare and configure a push job to a destination of their choice.
The redaction option (when PII is not explicitly permitted) strips anything that could identify a user: user name, user email, user ID, device ID, source IP, URL, referrer, and user agent.
Configuration and New Roles
To configure these settings, Gateway customers go to the Cloudflare for Teams dashboard and navigate to Settings > Network. The first option there sets activity logging preferences. The additional redaction option is also found on this page.

New dashboard roles, which go live in January 2022, provide more granular partitioning of administrator access to Access and Gateway components. Enterprise account owners can modify these roles via Account Home → Members.
The features are available to users on any plan. Those not ready to create an account can explore the platform's key use cases—including DNS and HTTP filtering setup—through an interactive demo.



