Cloudflare has announced a multi-agent AI architecture for Managed Defense, separating evidence collection from model reasoning. The design helps analysts investigate security alerts while limiting unsupported conclusions and out-of-scope queries.
In its article on AI-assisted security operations dated October 7, 2026, Cloudflare said application code collects data before specialized agents analyze it. The output brings together evidence, information gaps, and suggested next steps for analysts.
A single-agent prototype reveals limitations
According to Cloudflare, a prototype that assigned the entire investigation to one general-purpose agent produced useful analysis but also made claims without supporting evidence.
When observations, detector descriptions, policies, and threat intelligence share a single prompt, their roles can easily become blurred. An alert is a hypothesis to test, not proof that an attack has succeeded.
The system also queried the wrong accounts or time windows and failed to distinguish failed lookups from lookups that returned no results. Cloudflare therefore moved collection and scope control into application code.
Preparing evidence before analysis
Fixed workflows collect customer identities, alert histories, normal traffic levels, protection enforcement results, and network observations. Each piece of data has a source, version, and timestamp.
The data snapshot can be reused for evaluation. With fixed inputs, differences in analysis results can more readily be attributed to interpretation rather than retrieval variability.
This relates to context management for long-running AI work: data sources and state need to remain clear, not just the conversation content.
Four specialized agents, one synthesis
Cloudflare uses Clef on Workers AI for initial assessment. Alerts highly likely to be false positives skip in-depth analysis. Known high-volume traffic noise patterns are classified using fixed logic and retained as context.
For alerts requiring further review, four agents run in parallel, covering traffic, customer history, global network signals, and threat intelligence. The synthesis agent is not allowed to retrieve additional evidence or select a classification outside the permitted list.
The agent responsible for global signals receives only aggregated data, not individual records or other customers' identities. A pattern common across the network does not automatically prove that a customer is facing the same attack campaign.
Control boundaries and results not yet quantified
Separating retrieval, interpretation, and recommendations has similarities to Muse's Sentinel control layer for action permissions, although the two systems serve different purposes.
The information provided does not yet include figures on accuracy or time saved. There is not enough evidence to conclude that this architecture completely eliminates flawed reasoning or replaces analysts.
Frequently asked questions
How can this approach to analysis be tested?
Fixing the evidence set and rerunning different model versions helps compare results without confounding them with retrieval variability. Evaluation still requires clear criteria and review by analysts.
