Vibeleaderboard
← All Intel
Intel / blog

Cloudflare OS: an open platform for agents, apps, and work

Source
Cloudflare
Author
Cloudflare
Date
Key takeaways · AI-distilled
  • Every and app starts with access to nothing. Access is granted per resource and arrives as a typed binding — env.PROJECT is a capability to use that one resource under one policy — while the credential itself never enters the agent or its generated code.
  • Generated server code runs in a Worker with outbound networking switched off, and client code in a browser frame. The only route to the internet is a capability someone explicitly handed it.
  • A Gatekeeper is a per-service Worker that understands that service's API: it can scope an agent to one GitHub repo, allow reading issues but not source, mask fields, apply rate limits, and hold a pull request for human approval.
  • Knowing which tools an agent can call is not the same as knowing which data it saw. gives you the first; the platform logs the second, recording every resource an agent observes as it works.
  • That observation log drives sharing. Before another person can open a workspace or view a dashboard an agent produced, Gatekeepers check that person's access to the underlying resources the agent read to build it.
Terms in this piece · Glossary
  • AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
  • context window — The maximum amount of text a model can consider at once — its working memory for the current conversation or task.
  • sandbox — An isolated environment where AI-generated code or agent actions run without being able to touch anything real.
  • MCP — The Model Context Protocol — an open standard that lets any AI assistant plug into any tool or data source without custom integration code.
Why it matters

A major infrastructure provider shipping an org-wide agent platform sets a reference architecture for how company and skills get delivered to agents.

Key quotes

“It gives every person an agent and workspace built around their company: how it works, what it knows, and the systems it relies on.”

“Security had to be part of the platform, not something every person building an app or using an agent has to implement correctly.”

“But handing over API keys to people and agents is dangerous and does not scale.”

“Sharing the dashboard must not become a way to share the table with people who could not access it directly.”

“In Cloudflare OS, each “file” can be its own application, written by an agent for one person, one project, or one team.”

Read the source blog.cloudflare.com
More from Cloudflare
Recommended reads
Comments

Checking sign-in…

Loading comments…