← Back to issue11 / 18 · Week of Aug 3, 2026

Cloudflare OS makes data access part of the agent runtime

Cloudflare has open-sourced Cloudflare OS, a browser-based workspace for company agents, connected apps, documents, and workflows. Agents can use curated company context and skills, while apps run as isolated Workers with their own state. Why it matters: The strongest idea is not another chat interface. Cloudflare treats access as a runtime property: agents start with no access, credentials remain outside generated code, and policies can account for the resources an agent has already observed before it shares an output or makes an external request.

Try this: For one internal agent workflow, list the resources it may read, who may view each derived output, and which writes require approval. Then test whether a sensitive source can leak through a dashboard, shared workspace, or outbound tool call.

Source
Cloudflare Blog: Cloudflare OS
View source →

Get the field brief every week.

Important AI developments, useful explanations, and practical resources in one weekly read. Context to understand what matters, with links to the original sources and deeper reading.

Subscribe free →
Free weekly·No spam·Unsubscribe anytime