Cloudflare adds Worker-level access controls with four roles for teammates and agents
Cloudflare Blog · rss · 2026-09-15
Cloudflare introduced resource-level access controls for Workers: four roles (Metadata Read-Only for debugging without source access, Content Read-Only for code review without deploys, Editor for CI/CD with contained blast radius, Admin including deletion), each assignable at platform, product, or single-resource scope. Routes and custom domains require an extra Workers Routes permission, and 403 errors now link to the required permission docs — useful for scoping agents to least privilege. Available today, with plans to extend roles to D1, R2, and KV.
More from coding & agent
- Cloudflare Workers ships per-Worker scoped CI deploy tokens for least-privilege deploys — dinasaur_404 · 2026-09-15
- AI agent swarm beats NanoChat benchmark SoTA in 3 days with 15k-node knowledge graph — hyperparticle · 2026-09-15
- A/B testing the i-have-adhd plugin: making coding agent answers scannable — KhuyenTran16 · 2026-09-15
- rekursiv.ai open-sources trackinizer, an epistemological database for agent research — hyperparticle · 2026-09-15
- Give your coding agent GPUs via the Hugging Face CLI in one link — ben_burtenshaw · 2026-09-15
- Hybrid search put to the test: dense embeddings, BM25 and SPLADE on 47 SEC filings in Qdrant — qdrant_engine · 2026-09-15