What problem does it solve? Migrating from an existing VPN, SWG, or SASE platform to Cloudflare One involves hundreds of policies, objects, and connectors that rarely map one-to-one, and missed rules silently weaken security. This Skill provides a structured assessment and mapping workflow so every source rule is accounted for before cutover. ## Core Features & Use Cases - Source-stack assessment: Builds a full inventory of identities, apps, tunnels, DNS/URL/firewall/DLP/TLS policies, and hit counts from Zscaler ZIA/ZPA, Palo Alto NGFW/Prisma, and legacy VPN exports. - Mapping plan with parity gaps: Maps each source object to a Cloudflare One target (Gateway policies, Access apps, Cloudflare Tunnel, DLP, device posture) with confidence levels, partial mappings, and explicit Not Migrated decisions. - Safe staged rollout: Creates dependencies first, uses migration prefixes and audit-mode rules, pilots with small groups, and validates with object-count comparisons and rollback paths. - Use Case: Given ZPA app segment and connector group exports, produce a tunnel-per-connector-group topology with CIDR/hostname routes, reusable Access policies, and the Gateway Network allow rule needed so private app traffic is not blocked. ## Quick Start Assess these Zscaler ZIA and ZPA exports and produce a Cloudflare One migration plan with policy mappings, parity gaps, and a pilot rollout.