BuildNot yet confirmed elsewhere1 publisher3 min readPublished
Cloudflare OS makes the sandbox the product, and the document the unit of isolation
Cloudflare has open-sourced the internal platform it built after staff began demanding admin tokens for homemade AI apps. The design bet is on capability grants, not on the model.
The Engineer · Build desk
What happened
- Cloudflare has open-sourced Cloudflare OS on GitHub, the corporate AI platform it had been running internally.
- Each instance is spun up inside fine-grained V8 isolates managed by Cloudflare's workerd runtime and Dynamic Workers.
- A capability layer called Gatekeepers scopes resource access, masks sensitive database columns, rate-limits by role and requires human sign-off on destructive actions.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Approving a homemade app becomes a permissions decision rather than a code review, because sharing is validated against the recipient's own resource grants.
- exposure The failure mode moves to whoever configures capabilities: InfoQ notes misconfigured Gatekeeper grants remain a live vector even with the sandbox intact.
- constraint Giving every user a modifiable copy trades central maintainability away, and the material offers no route for pushing a fix into copies that users have already changed.
- precedent Rhea's 4,000-tools figure will be quoted at internal platform teams as a target, without a published definition of what counts as a tool.
The unit of isolation here is not the user and not the application. It is the document. A document editor running under Cloudflare OS spins up a separate instance in a separate sandbox for each document, and Cloudflare calls each one a Gadget [3]. Access control sits at the boundary of that instance rather than inside the code, so the platform decides who can reach a Gadget at all, and lead architect Kenton Varda argues a Gadget cannot leak itself even to an attacker who already holds other Gadgets built from the same app [13]. Sharing is checked the same way: Varda wrote on Hacker News that when you share a Gadget, the system verifies the recipient has direct permission to each connected resource, so a bug in the Gadget cannot hand anyone access they did not already hold [14].
That is the whole argument behind Varda's claim that a security team can let non-technical staff generate their own software and still sleep [2]. Nobody has to read the generated code. The reviewable surface is the grant list.
The prior state at Cloudflare is what makes the design legible. According to CIO Sam Rhea, employees were pushing to deploy unvetted generative AI workflows to build bespoke SuperApps, and those scripts wanted elevated administrative access plus production API tokens across dozens of internal systems of record [8]. Cloudflare's stopgap was a human-staffed "magic AI email" alias used to catalogue where routine work was getting stuck [9], and the triage produced a specific finding: off-the-shelf agent harnesses are fine at boilerplate software engineering, while knowledge workflows need strict context management, deterministic execution, and permission isolation that changes per task [10]. Gatekeepers are the answer to the third of those. They scope access to named resources, mask sensitive database columns, apply role-based rate limits, and require human approval before destructive side effects, with agents starting at zero ambient permissions [6]. InfoQ contrasts this with typical Model Context Protocol connections, whose implementations often grant broad ambient access [7].
On the adoption figures, Rhea's number is more than 4,000 custom business tools built by non-technical staff inside 30 days [16], which is roughly 133 a day [12], against internal use dating from May 2026 [15]. What a "custom business tool" is remains undefined in the material, and since a Gadget is instantiated per document, the count sits somewhere between an application tally and a document tally. That distinction matters to anyone using the figure to size their own rollout.
Two things the release does not close. InfoQ appends its own note that other risk vectors still apply, including misconfigured Gatekeeper grants [11], which puts the blast radius on whoever administers capabilities. And because every user runs a modifiable copy of the code [4], the material describes no mechanism for pushing a fix into copies that have already diverged.
What to watch
- Whether the published repository ships Gatekeeper defaults that fail closed, or leaves grant scoping entirely to adopters.
- Whether Cloudflare defines what counts as a custom business tool, and whether any outside adopter reports comparable numbers.
- Whether the project documents an upgrade path for Gadgets whose code users have already modified.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence42
- Adoption28
- Hype gap+30
- Incentives76
- Confidence46
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [2]
Lead architect Kenton Varda described Cloudflare OS as a full-on personal app vibe coding platform in which the sandbox is secure enough that a company's security team can feel comfortable giving non-technical users permission to vibe code and then sleep soundly at night.
- [3]
In Cloudflare OS, if you have a document editor app, each document runs as a separate instance of the app in a separate sandbox, which Cloudflare calls one "Gadget".
- [4]
Because everyone is running their own copy of the code, everyone can freely modify their copy, and each user can use generative AI to modify the source of their instance on the fly without cross-tenant data leakage.
- [5]
When a user prompts the system to generate a document, dashboard, or data view, the runtime instantiates a dedicated isolated app instance inside fine-grained V8 isolates managed by Cloudflare's open-source workerd runtime and Dynamic Workers.
- [6]
Access to resources is governed by a capability-based model Cloudflare calls "Gatekeepers", which scope access to designated resources, mask sensitive database columns, apply role-based rate limits, and mandate human approvals before destructive side effects; agents start in a zero-trust state with zero ambient permissions.
- [7]
InfoQ contrasts Gatekeepers with standard Model Context Protocol connections, whose implementations often provide ambient, broad access to systems and resources.
- [8]
Chief Information Officer Sam Rhea previously reported that employees were seeking to rapidly deploy unvetted generative AI workflows to create bespoke "SuperApps", and that those scripts required elevated administrative access and direct production API tokens across dozens of internal systems of record.
- [9]
To channel that demand without compromising security boundaries, Cloudflare initially operated a human-staffed "magic AI email" alias to catalogue routine operational friction points.
- [10]
The triage revealed that while off-the-shelf agent harnesses excel at boilerplate software engineering, traditional knowledge workflows require strict context management, deterministic task execution, and dynamic permission isolation.
- [11]
InfoQ adds an editorial note that other risk vectors may apply, including misconfigured Gatekeeper capability grants.
- [12]
More than 4,000 tools in 30 days works out to roughly 133 per day.
- [13]
Varda says the platform can manage all access control by controlling who can access the Gadget at all, and that there is no way the Gadget can accidentally leak itself to an attacker, even one with access to other Gadgets based on the same app.
ReportedInsufficientSource: Kenton Varda2 sources— create a free account to open themView cited source - [14]
Varda wrote on Hacker News that when a Gadget is shared, the system verifies the recipient also has direct permission to access each resource it is connected to, so no security bug in the Gadget itself could accidentally grant access to things they do not already have.
ReportedInsufficientSource: Kenton Varda on Hacker News2 sources— create a free account to open themView cited source - [15]
Cloudflare employees have used Cloudflare OS since May 2026, with reported significant productivity gains.
- [16]
According to Rhea, non-technical staff built more than 4,000 custom business tools within 30 days.
ReportedInsufficientSource: Sam Rhea, Cloudflare CIO2 sources— create a free account to open themView cited source
Sources
1 independent publisher whose own reporting we read for this story.
- infoq.comCloudflare OS: Cloudflare's Open-Source Corporate AI Platform Built on a Capability-Based Model
1 article · August 23, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- MCP Connector SecurityFollow
- Capability-Based SecurityFollow
- Vibe-Coding GovernanceFollow
- Open-Source Platform ReleasesFollow
- Enterprise Internal AI PlatformsFollow
- AI Agent SandboxingFollow