Building an evidence-grounded agentic security operations harness on Cloudflare
Cloudflare introduces a multi-AI-agent security operations system to automate alert analysis, reduce human workload, and accelerate incident response across its Managed Defense platform.
Security teams face an alert paradox where simultaneous alerts overwhelm analysts, forcing them to manually connect detections, gather data, and assess relevance while new alerts arrive. Cloudflare’s new AI agent harness automates this process by collecting and correlating evidence, accounting for missing sources, and providing a consolidated view of related alerts. The system uses approved models like GPT-5.6 Cyber and Mythos, alongside Cloudflare’s open-source Clef decision model, to streamline analysis and reduce the cognitive load on human analysts.
Initial prototypes revealed limitations when a single general-purpose agent processed entire investigations, leading to unsupported claims. Cloudflare redesigned the system to separate evidence collection and scope enforcement into deterministic application code before model analysis begins. This ensures reproducibility, as fixed reconnaissance snapshots prevent input drift between runs and allow specialist AI agents to focus on interpretation rather than data retrieval.
To prioritize alerts, Cloudflare employs a lightweight triage model that compares new alerts against historical data and known patterns, filtering out high-confidence false positives. Clef, running on Workers AI, classifies routine noise as passive, keeping it available as context without cluttering active queues. The system also integrates global telemetry from Cloudflare’s network services, weighting patterns like IP scanning behavior while preserving customer privacy through aggregate-only analysis.
The final system aggregates related alerts into versioned evidence packages, where application code validates citations and enforces structured reasoning. Managed Defense Analysts review findings, adjust recommendations, or group alerts into cases, while an LLM-powered agent generates advisory reports using standardized terminology. The platform leverages Cloudflare’s developer infrastructure—Workers, Workflows, D1, R2, and Durable Objects—to coordinate stages, preserve validated evidence, and maintain auditability throughout investigations.