Cloudflare Managed Defense: a multi-agent harness to filter security alerts
Cloudflare has put into beta a multi-agent system that separates evidence gathering from AI analysis to cut false positives on Managed Defense.
UptimeMag editorial team · 7 October 2026 · 2 min read

Cloudflare has put into beta a new analysis engine for Managed Defense, the Enterprise service that pairs human analysts with the management of WAF, DDoS and Magic Transit. The problem the company says it's solving is one every sysadmin knows well: a single event can trigger dozens of correlated alerts, and an analyst has to quickly decide which to silence, which are false positives, and which need escalating.
Why one agent isn't enough
The first prototype used a single generalist AI agent handed the entire investigation. The new architecture separates deterministic evidence gathering and scope enforcement from model inference to prevent hallucinations: a fixed reconnaissance phase collects versioned, timestamped evidence, a lightweight triage model (Clef, Cloudflare's open-source decision model) filters out likely false positives, and four specialist agents (traffic, customer context, global telemetry, threat intelligence) analyse the remaining alerts in parallel.
A synthesis agent combines the typed outputs of the four specialists into a single advisory; application code validates every citation against an evidence package before producing recommendations. Final responsibility remains human, however: Managed Defense analysts retain final decision-making authority over classifications and mitigations.
Clef, twice in the pipeline
The Clef model — whose weights Cloudflare published on Hugging Face under the Apache 2.0 licence in early October — is used twice: first as a quick filter on low-priority alerts, then to assess whether the evidence collected is sufficient for a decision. Unlike a generative LLM, Clef reads an input state and a set of typed questions, then returns a probability for each permitted answer, giving the agent a structured decision to act on immediately — for instance, routing the ticket, blocking the request, or escalating to a human.
When a data source doesn't respond — a timeout, a threat intelligence lookup with no match — the system doesn't force a conclusion: it distinguishes between "unchecked", "checked with no findings" and "checked with proof of absence", and if the evidence is insufficient it doesn't propose a classification.
Who can try it
The beta is available for eligible application security alerts within Managed Defense. Anyone already running Cloudflare's WAF, DDoS protection or Magic Transit in production can request access through their Enterprise account team.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50).