Cloudflare has published an Agent Access Model for securing AI agents that act on behalf of people or organizations. The proposal centers on strict identity brokering, continuous mediation, and stateful trust for task-scoped agents.
The core problem is that agents can combine reading, reasoning, and action across many systems. Giving them broad credentials creates risk if a prompt, tool call, or connected service behaves unexpectedly.
Cloudflare’s model treats access as something that should be negotiated and monitored throughout a task, not granted once and forgotten. That includes identifying the user, the agent, and the specific work being attempted.
The idea is architectural rather than a simple product toggle. It points toward a future where agent deployment depends as much on identity, policy, and audit trails as on model quality or tool integration.