What problem does it solve? Cloudflare One spans many products (Access, Gateway, WARP, Tunnel, DLP, CASB, WAN), and misconfiguring policies, split tunnels, or TLS inspection can break connectivity or weaken security. This Skill guides architecture, configuration, troubleshooting, and review of Zero Trust deployments using current Cloudflare documentation. ## Core Features & Use Cases - Architecture and Configuration Guidance: Walks through assessment prompts for Access apps, Gateway policies, tunnels, device posture, and Cloudflare WAN before proposing changes. - Guardrails and Best Practices: Enforces rules like reusable Access policies, split tunnel alignment with tunnel routes, and pilot-first rollouts for risky changes. - Troubleshooting Workflows: Directs log-driven diagnosis using Gateway activity logs, Access audit logs, DEX, and Logpush. - Use Case: A network engineer migrating from a legacy VPN asks for a ZTNA rollout plan; the Skill gathers identity, site, and app context, then produces a phased design with validation and rollback steps. ## Quick Start Ask the assistant to design a Cloudflare One rollout plan for replacing your corporate VPN with Access and Tunnel for 500 remote users.