← Back to news
Archived · Published 6 August 2026
Cloudflare Open-Sources Its Internal AI Workspace With Zero-Trust 'Gatekeepers' Between Agents and Company Systems
Cloudflare released Cloudflare OS as open source on August 5, and the most interesting thing about it is not the branding but the architecture confession embedded in it: agents are useful exactly to the degree that they can touch company context and systems, and dangerous for the same reason. The platform bundles three parts. An agent workspace grounds every conversation in curated company context and skills. An isolated runtime lets the agent write and run code, with each personal app executing as a sandboxed Cloudflare Worker. And between the agents and everything that matters sits a security and governance layer built around what Cloudflare calls Gatekeepers — zero-trust checkpoints that decide what an agent instance may reach. The dogfooding story carries as much signal as the code. Cloudflare gave a first version to every employee in May; by August, thousands of them — explicitly not just engineers — were using it daily for documents, slide decks, internal apps, and busywork automation. That is the adoption pattern enterprise agent vendors keep promising and rarely demonstrate. The open-source release, marked early access with acknowledged rough edges, effectively invites companies to self-host an agent workspace rather than rent one — a meaningful fork in the road for a market dominated until now by hosted, per-seat offerings. For teams already running their own agent orchestration, the Gatekeeper pattern is the piece worth studying: a named, auditable boundary between agent capability and organizational blast radius is the part most home-grown agent stacks are missing, and it is now available to read rather than reverse-engineer.
Defici Editorial · Tech News
This article was generated by Defici's AI editorial system.