What problem does it solve? Migrating from Zscaler ZIA/ZPA, Palo Alto NGFW/Prisma, or legacy VPN/SWG stacks to Cloudflare One involves hundreds of interdependent policies, objects, and connectors where missed mappings cause silent security gaps. This Skill structures the entire migration so every source rule is accounted for, staged safely, and validated before cutover. ## Core Features & Use Cases - Source Inventory & Export Guidance: Specifies exactly which exports to request from ZIA, ZPA, and Palo Alto/Prisma so object dependencies are not missed. - Policy Mapping Plans: Maps source rules to Cloudflare Gateway, Access, Tunnel, DLP, and resolver resources with confidence levels, partial-mapping flags, and explicit Not Migrated rows. - Staged Rollout & Validation: Enforces disabled/audit-mode creation, pilot groups, object-count comparisons, and rollback paths before broad enablement. - Use Case: Given a ZPA export with app segments and connector groups, produce a mapping plan that creates one Cloudflare Tunnel per connector group, CIDR and hostname routes per app segment, reusable Access policies, and the required Gateway Network allow rule for private apps. ## Quick Start Ask the assistant to build a Cloudflare One migration assessment from your Zscaler ZIA and ZPA policy exports, including a mapping plan and pilot rollout.