Building an evidence-grounded agentic security operations harness on Cloudflare

Curated from Cloudflare Blog

Most AI security demos rely on hallucinated confidence, which is unacceptable in production SRE workflows. This Cloudflare implementation offers a pragmatic counterpoint by strictly decoupling deterministic evidence gathering from probabilistic model inference. By anchoring agent recommendations in verifiable, global network telemetry rather than pure LLM intuition, the system reduces the risk of catastrophic false positives. The architecture treats the AI not as an autonomous decision-maker, but as a specialized analyst assistant operating within defined guardrails. For security teams currently struggling with alert fatigue and the trust gap inherent in generative tools, this approach demonstrates how to build auditability into agentic pipelines. The key takeaway is that you must design your harness to force agents to cite raw, verifiable data points before they are permitted to generate any actionable recommendation.

Cloudflare Managed Defense uses a team of specialized AI agents built on Workers and global network telemetry to analyze security alerts. By separating deterministic evidence collection from model inference, the system delivers grounded recommendations to Managed Defense Analysts.

— Cloudflare Blog

Read the full article on Cloudflare Blog →