What problem does it solve? Cloudflare One spans Access, Gateway, WARP, Tunnel, DLP, CASB, and Cloudflare WAN, and misconfiguring any of them causes broken connectivity, security gaps, or failed rollouts. This Skill guides architecture, configuration, troubleshooting, and review of Zero Trust deployments with current documentation and guardrails. ## Core Features & Use Cases - Architecture and Configuration Guidance: Classifies the ask, gathers context on identity, sites, and traffic paths, then proposes change sets with prerequisites, validation, and rollback. - Product-Specific Guardrails: Covers Access reusable policies, Gateway rule evaluation order, TLS inspection exceptions, split tunnel modes, DLP rollout, CASB findings, and device client enrollment. - Troubleshooting Workflow: Works from Gateway activity logs, Access audit logs, and DEX diagnostics back to the responsible rule, route, or policy. - Use Case: When migrating from a legacy VPN to ZTNA, use this Skill to plan tunnel connectors, split tunnel configuration, Access policies, and a pilot-group rollout with validation steps. ## Quick Start Ask the assistant to design a Cloudflare One Zero Trust architecture for replacing your corporate VPN with private app access through Cloudflare Tunnel and WARP.