What problem does it solve? Migrating from existing VPN, SWG, or SASE platforms like Zscaler ZIA/ZPA or Palo Alto to Cloudflare One is error-prone: policies, objects, tunnels, and identity rules rarely map 1:1, and missed rules create security gaps. This Skill provides a structured assessment and mapping workflow so every source rule is accounted for before cutover. ## Core Features & Use Cases - Source Stack Inventory: Builds a complete inventory of identities, apps, connectors, DNS/URL/firewall/DLP policies, objects, and hit counts from ZIA, ZPA, Palo Alto/Prisma, and legacy VPN exports. - Mapping Plan with Parity Gaps: Maps each source object to a Cloudflare One target resource (Gateway policies, Access apps, Cloudflare Tunnel, DLP, device posture) with confidence levels, partial mappings, and explicit Not Migrated decisions. - Safe Staged Rollout: Creates dependencies in order, uses migration prefixes and audit-mode rules, pilots with small groups, and validates with object-count comparisons and rollback paths. - Use Case: A network team replacing Zscaler ZPA uses this Skill to map connector groups to Cloudflare Tunnels, convert app segments to CIDR and hostname routes, and produce a source-rule accounting table before decommissioning ZPA. ## Quick Start Assess my exported Zscaler ZIA and ZPA configuration files and produce a Cloudflare One migration plan with policy mappings and a pilot rollout.