Back
Cloudflare Deploys Multi-Agent AI Harness to Triage Security Alerts
SiTech AI Team2 min read

Cloudflare Deploys Multi-Agent AI Harness to Triage Security Alerts

Cloudflare's Managed Defense now uses a multi-AI-agent harness to gather evidence, aggregate detections, and recommend next steps for security alerts, reducing analyst workload at scale.

Why a single agent was not enough

Cloudflare's first prototype gave one general-purpose AI agent the full investigation. It produced useful analysis but also hallucinated claims the evidence did not support. Telemetry, detector descriptions, policies, and threat intelligence were flattened into one prompt, blurring their distinct roles. Three problems recurred: context became authority, scope drifted, and failures disappeared, since a timed-out lookup could not be distinguished from a checked-and-not-found result.

Recon first, inference second

The front half of the harness contains no AI agents. Deterministic code runs fixed reconnaissance workflows with versioned API calls, collecting customer identity, detection history, traffic baselines, enforcement outcomes, and network observations. Each piece of data is stored with its source, version, and timestamp, and the same snapshot can be replayed so differences between agents come from interpretation rather than retrieval.

Cloudflare's open-source decision model Clef, running on Workers AI, scores each alert against its reconnaissance data. Alerts with a high likelihood of being false positives skip the specialist agents entirely, while known high-volume noise is classified as passive on arrival.

Specialist agents and evidence checks

A coordinator agent runs four specialists in parallel: traffic analysis, customer context, global telemetry, and threat intelligence. A synthesis agent combines their typed findings into one advisory and cannot fetch new evidence or choose classifications outside an approved vocabulary. Specialists must cite items from a versioned evidence package, and application code validates every citation. Clef scores the evidence a second time to pick from a reduced list of attack classifications and dispositions.

Global telemetry works only with aggregates, never another customer's records. The system distinguishes three states for incomplete evidence: not checked, checked with no matching result, and checked with evidence supporting absence. When evidence is insufficient, no classification or disposition is recommended.

Analysts keep final authority

Managed Defense Analysts remain responsible for decisions and mitigations. The advisory suggests concrete remediations such as rate limiting rules, WAF custom rules, or DDoS protection changes. Cloudflare plans a Custom Managed level and continuous AI agents that monitor traffic for patterns fixed rules may miss. The early beta is available in Managed Defense for eligible application-security alerts and cases.

Sources: Cloudflare

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.