Cloudflare One: The Zero Trust Stack, and How Agent Skills Accelerate Rollout and Migration
On June 17, 2026, Cloudflare introduced the "Cloudflare One stack" — and took an unusual step in doing so: not a new product, but bundled domain knowledge in the form of Agent Skills for planning, rolling out, and migrating a Zero Trust environment. A good occasion to sort out what Cloudflare One actually is, and why this approach matters especially for the move to SASE/SSE.
What is Cloudflare One?
Cloudflare One is Cloudflare's SASE/SSE platform: it brings network and security together along Zero Trust principles and replaces the traditional chain of VPN, web proxy, and per-site appliances. The key building blocks:
Cloudflare Access (Zero Trust Network Access): verified, minimal access to individual applications instead of an all-around VPN, governed per user, device, and application.
Cloudflare Gateway (Secure Web Gateway): protection of users, devices, and data through DNS, web, and data filtering, including data loss prevention approaches.
Connectivity (Tunnel, Mesh & WAN): secure connection of sites, data centers, and cloud resources, without open ports and without classic MPLS.
Management & visibility (Digital Experience Monitoring): troubleshooting and user experience in view, supported by automated policy recommendations.
The gap: agents lack context
The real point of the "Cloudflare One stack" lies elsewhere. Anyone trying to configure a Zero Trust environment with the help of AI agents quickly hits a limit: a generic agent does not know the organization-specific topology — which sites, applications, and legacy systems are in use. That is exactly the missing domain knowledge the stack fills in.
The Cloudflare One stack: domain knowledge as skills
The stack consists of structured skill files that are based on real implementation experience and hand an agent the contextual knowledge it needs. Two skills are at the center: "cloudflare-one" for building and managing a Zero Trust environment, and "cloudflare-one-migration" for a guided move away from legacy vendors.
Migration without a big bang: away from Zscaler, Netskope, and the rest
In practice, the migration part is the most interesting. The stack supports vendor transitions (from Zscaler, Netskope, or Palo Alto, for example), translates existing rule sets, creates network diagrams, and proposes concrete configurations. Instead of a risky big-bang project, the transition becomes traceable and incremental. Which is what Zero Trust demands anyway.
Built for partners, too
Cloudflare explicitly aims the stack at partners who implement customer environments as well. The structured domain knowledge speeds up work that otherwise takes a lot of experience and manual effort: from assessing the current state to translating rules to going live.
Our view at KAEMI
As a Cloudflare partner, we see this above all as an accelerator for the move to SASE/SSE. We plan, implement, and manage Cloudflare One as a managed service, aligned with your requirements and in phases. Whether Zero Trust access, secure web gateway, or securely connecting your sites: the new stack helps make that journey faster and more traceable.