What problem does it solve? Cloudflare One spans many products (Access, Gateway, WARP, Tunnel, WAN, DLP, CASB), and misconfiguring policies, split tunnels, or TLS inspection can break connectivity or weaken security. This Skill provides a retrieval-first workflow with assessment prompts, guardrails, and validation steps so changes are grounded in current Cloudflare documentation rather than stale assumptions. ## Core Features & Use Cases - Architecture and Configuration Guidance: Classifies requests, gathers context (identity, sites, apps, traffic paths), and proposes change sets with prerequisites, validation, and rollback. - Product-Specific Guardrails: Covers Access policies, Gateway rule evaluation, split tunnel modes, TLS inspection, DLP rollout, CASB findings, device posture, and Cloudflare WAN connectivity. - Troubleshooting Workflow: Works from Gateway activity logs, Access audit logs, and DEX diagnostics back to the responsible rule, route, or policy. - Use Case: When migrating from a legacy VPN to Cloudflare Zero Trust, use this Skill to plan tunnel routes, split tunnel mode, enrollment rules, and a pilot-scoped Gateway policy rollout. ## Quick Start Ask the assistant to design a Cloudflare One rollout plan for replacing your corporate VPN with Access and WARP for 500 remote users.