Skip to content

BuildNot yet confirmed elsewhere1 publisher3 min readPublished

Cloudflare OS makes the sandbox the product, and the document the unit of isolation

Cloudflare has open-sourced the internal platform it built after staff began demanding admin tokens for homemade AI apps. The design bet is on capability grants, not on the model.

The Engineer · Build desk

How we use AISend a correction

What happened

  • Cloudflare has open-sourced Cloudflare OS on GitHub, the corporate AI platform it had been running internally.
  • Each instance is spun up inside fine-grained V8 isolates managed by Cloudflare's workerd runtime and Dynamic Workers.
  • A capability layer called Gatekeepers scopes resource access, masks sensitive database columns, rate-limits by role and requires human sign-off on destructive actions.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Approving a homemade app becomes a permissions decision rather than a code review, because sharing is validated against the recipient's own resource grants.
  • exposure The failure mode moves to whoever configures capabilities: InfoQ notes misconfigured Gatekeeper grants remain a live vector even with the sandbox intact.
  • constraint Giving every user a modifiable copy trades central maintainability away, and the material offers no route for pushing a fix into copies that users have already changed.
  • precedent Rhea's 4,000-tools figure will be quoted at internal platform teams as a target, without a published definition of what counts as a tool.

The unit of isolation here is not the user and not the application. It is the document. A document editor running under Cloudflare OS spins up a separate instance in a separate sandbox for each document, and Cloudflare calls each one a Gadget [3]. Access control sits at the boundary of that instance rather than inside the code, so the platform decides who can reach a Gadget at all, and lead architect Kenton Varda argues a Gadget cannot leak itself even to an attacker who already holds other Gadgets built from the same app [13]. Sharing is checked the same way: Varda wrote on Hacker News that when you share a Gadget, the system verifies the recipient has direct permission to each connected resource, so a bug in the Gadget cannot hand anyone access they did not already hold [14].

That is the whole argument behind Varda's claim that a security team can let non-technical staff generate their own software and still sleep [2]. Nobody has to read the generated code. The reviewable surface is the grant list.

The prior state at Cloudflare is what makes the design legible. According to CIO Sam Rhea, employees were pushing to deploy unvetted generative AI workflows to build bespoke SuperApps, and those scripts wanted elevated administrative access plus production API tokens across dozens of internal systems of record [8]. Cloudflare's stopgap was a human-staffed "magic AI email" alias used to catalogue where routine work was getting stuck [9], and the triage produced a specific finding: off-the-shelf agent harnesses are fine at boilerplate software engineering, while knowledge workflows need strict context management, deterministic execution, and permission isolation that changes per task [10]. Gatekeepers are the answer to the third of those. They scope access to named resources, mask sensitive database columns, apply role-based rate limits, and require human approval before destructive side effects, with agents starting at zero ambient permissions [6]. InfoQ contrasts this with typical Model Context Protocol connections, whose implementations often grant broad ambient access [7].

On the adoption figures, Rhea's number is more than 4,000 custom business tools built by non-technical staff inside 30 days [16], which is roughly 133 a day [12], against internal use dating from May 2026 [15]. What a "custom business tool" is remains undefined in the material, and since a Gadget is instantiated per document, the count sits somewhere between an application tally and a document tally. That distinction matters to anyone using the figure to size their own rollout.

Two things the release does not close. InfoQ appends its own note that other risk vectors still apply, including misconfigured Gatekeeper grants [11], which puts the blast radius on whoever administers capabilities. And because every user runs a modifiable copy of the code [4], the material describes no mechanism for pushing a fix into copies that have already diverged.

What to watch

  • Whether the published repository ships Gatekeeper defaults that fail closed, or leaves grant scoping entirely to adopters.
  • Whether Cloudflare defines what counts as a custom business tool, and whether any outside adopter reports comparable numbers.
  • Whether the project documents an upgrade path for Gadgets whose code users have already modified.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence42
Adoption28
Hype gap+30
Incentives76
Confidence46
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Cloudflare recently open-sourced Cloudflare OS on GitHub.

    ReportedSupportedView cited source
  2. [2]

    Lead architect Kenton Varda described Cloudflare OS as a full-on personal app vibe coding platform in which the sandbox is secure enough that a company's security team can feel comfortable giving non-technical users permission to vibe code and then sleep soundly at night.

    ReportedSupportedSource: Kenton Varda, lead architect, quoted by InfoQView cited source
  3. [3]

    In Cloudflare OS, if you have a document editor app, each document runs as a separate instance of the app in a separate sandbox, which Cloudflare calls one "Gadget".

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. infoq.com

    1 article · August 23, 2026

    Cloudflare OS: Cloudflare's Open-Source Corporate AI Platform Built on a Capability-Based Model

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories