Solutions

Reusable Cloudflare One designs.

Architecture patterns, rollout plans, validation checks, and operating notes for common security and networking outcomes.

Access

VPN replacement with Access and Tunnel

Replace broad network VPN with per-app identity, posture, and connector-based private access.

Open design
Identity

Bring your IdP or use Cloudflare-native identity

Pick the right login model for employees, admins, contractors, partners, and cross-account teams.

Open design
AI security

Safe workforce AI adoption

Discover AI apps, allow sanctioned tools, restrict uploads, and apply prompt-level DLP.

Open design
Data

DLP for SaaS and browser traffic

Baseline sensitive data flows, tune confidence, and enforce on high-risk destinations first.

View guidance
Network

Branch modernization with Cloudflare WAN

Connect sites with IPsec/GRE, apply route controls, steer traffic to Gateway, and test failover.

View module map
Contractors

Clientless partner access

Use Access and Browser Isolation where installing a device client is not possible or desirable.

Browse notes
MCP

Secure AI agent tool access

Put MCP portals and tool access behind Zero Trust policy, service auth, and request logging.

View module map