What Cloudflare says is new
Cloudflare on Oct. 7, 2026, described an early beta of AI alert reviews in its Managed Defense service. The beta covers eligible application-security alerts and cases. Fixed workflows gather evidence before any AI model analyzes an alert. Four specialist agents handle alerts that need deeper review. Managed Defense Analysts remain responsible for decisions and mitigation.
Key facts from Cloudflare’s post
- Beta scope: Eligible application-security alerts and cases in Managed Defense.
- Before inference: Deterministic code runs fixed reconnaissance workflows with versioned API calls.
- Deeper review: A coordinator runs four specialist AI agents in parallel.
- Evidence checks: Specialists cite a versioned evidence package. Code checks that each citation belongs to the investigation and supports the claim.
- Responsibility: The Managed Defense Analyst remains responsible for the decision and any mitigation.
Evidence comes first
Cloudflare describes reconnaissance as the first step. Here, reconnaissance means fixed workflows that deterministic code runs before model inference. The workflows use versioned API calls. They collect the customer’s identity and detection history. They also gather the traffic baseline, the enforcement outcome, and network observations. Each piece of data is stored with its source, version, and timestamp. That gives an investigation a record of where each item came from and when. Analysts get a quick, consolidated view of related alerts. The view also shows admitted evidence, visible gaps, and recommended next steps.
Four specialist roles
For alerts that need deeper review, Cloudflare says a coordinator runs four specialist AI agents in parallel. Traffic analysis covers request behavior, historical changes, and enforcement. Customer context covers earlier alerts, dispositions, and analysts’ decisions. Global telemetry compares activity with privacy-preserving Internet-wide signals. Threat intelligence checks indicators already admitted to the alert or case. Each role matches one evidence area. An analyst can match a question to a role by its subject.
Cloudflare’s named specialist roles
Which investigation area matches the alert evidence you are reviewing?
Is the question about request behavior, historical changes, or enforcement?
- Yes → Traffic analysis
- No → next question
Is it about earlier alerts, dispositions, or Managed Defense Analysts’ decisions?
- Yes → Customer context
- No → next question
Is it about comparing activity with privacy-preserving Internet-wide signals?
- Yes → Global telemetry
- No → next question
Is it about indicators already admitted to the alert or case?
- Yes → Threat intelligence
- No → No listed match
Reviews request behavior, historical changes, and enforcement.
Source: Cloudflare, Oct 7, 2026Reviews earlier alerts, dispositions, and Managed Defense Analysts’ decisions.
Source: Cloudflare, Oct 7, 2026Compares activity with privacy-preserving Internet-wide signals. The specialist works only with aggregates and never receives another customer’s individual records or identity.
Source: Cloudflare, Oct 7, 2026Checks indicators already admitted to the alert or case.
Source: Cloudflare, Oct 7, 2026The task does not match a review area in Cloudflare’s stated specialist-role descriptions.
Source: Cloudflare, Oct 7, 2026This maps Cloudflare’s listed roles; it does not rank them or show how often each handles an alert.
Filtering and scoring
Cloudflare describes triage and evidence scoring as separate steps. In triage, alerts with a high likelihood of being false positives skip the specialist agents. In scoring, Clef rates the collected evidence. It then picks from a deterministically reduced list of attack classifications and dispositions. When the evidence is insufficient, the system makes no classification or disposition recommendation. That gives uncertainty a defined outcome in the workflow.
How the advisory is bounded
Before analysis, Cloudflare’s system builds a versioned evidence package. It holds the investigation’s subject, scope, and time anchor. It also lists admitted evidence, policy versions, sources, and coverage gaps. Specialists must cite items in that package. Application code checks that each citation exists. It also checks that the citation belongs to the investigation and supports the attached claim. A synthesis agent then merges the typed findings into one advisory. It cannot fetch new evidence. It also cannot pick a classification outside the approved vocabulary. The evidence scope is fixed before synthesis begins.

The global view
Cloudflare says its global telemetry specialist compares activity with privacy-preserving Internet-wide signals. The specialist works only with aggregates. It never receives another customer’s individual records or identity.
Recommendations and responsibility
Cloudflare says recommendations follow different paths depending on the customer arrangement. For fully managed customers, Managed Defense Analysts can apply suggested rules. Other customers receive recommendations in the dashboard. They also get them through their chosen alert path. In every case, the Managed Defense Analyst remains responsible for the decision and any mitigation. The agents supply evidence and advice. The decision stays with the analyst.
Analysis: traceability, advice, and authority
The design Cloudflare describes separates three things: traceability, advice, and authority. Evidence packaging and citation checks address traceability. They test whether a finding points to material admitted for the investigation. The synthesis limits address advice. They restrict what evidence the agent can add and which classifications it can choose. The analyst’s responsibility addresses authority. Teams weighing a similar tool could ask three separate questions. Can they inspect the evidence path? Do they understand the advisory’s limits? Who approves an action? Taking these one at a time is clearer than treating AI review as a single step.
Limitations
Cloudflare’s Oct. 7 post gives no outside test results, pricing, customer numbers, or performance figures for the beta.
Eligibility and access
Cloudflare directs customers who already use a supported Cloudflare product to their enterprise account team. Those customers can ask that team about adding Managed Defense. The beta covers eligible application-security alerts and cases. The full post sets out the workflow and evidence checks in more detail.
Sources: Cloudflare, Oct 7, 2026
ZIPMEX promotes trading on trade.zipmex.com. Promotions are labelled and kept separate from news coverage, which is selected and checked without regard to them. Perpetual futures are leveraged derivatives. Prices can move fast and you can lose all of your margin. Not available in every jurisdiction. Not investment advice.