Cloudflare adds Worker-level access controls with four roles for teammates and agents

Cloudflare Blog · rss · 2026-09-15

Cloudflare introduced resource-level access controls for Workers: four roles (Metadata Read-Only for debugging without source access, Content Read-Only for code review without deploys, Editor for CI/CD with contained blast radius, Admin including deletion), each assignable at platform, product, or single-resource scope. Routes and custom domains require an extra Workers Routes permission, and 403 errors now link to the required permission docs — useful for scoping agents to least privilege. Available today, with plans to extend roles to D1, R2, and KV.

Original post →

More from coding & agent

coding & agent channel →