Skip to main content
Connect Cloudflare Access to sync your Cloudflare Zero Trust applications, users, and groups into Ravenna, then use them as targets in access policies, workflow actions, and agent rules. Cloudflare Access is an access provider integration at the organization scope. Each Cloudflare account connects once per Ravenna organization.

What you can do

Sync applications

Import Cloudflare Access applications so they can be requested and managed in Ravenna

Sync groups

Import Cloudflare Access groups with membership so they can grant application access

Sync users

Import users who have authenticated through Cloudflare Access, including seat and last-login details

Grant access

Add and remove users from Cloudflare Access groups directly from workflows and access policies

Approve requests

Use Cloudflare applications and groups as approvers or targets in

Answer access questions

Reference Cloudflare groups and applications in so agents resolve access requests without a handoff

How it works

Cloudflare Access is an access-provider integration, like Okta and JumpCloud. Once connected, Cloudflare applications and groups become selectable anywhere Ravenna offers an integration target:
  • Access policies: set a Cloudflare Access group as an approver, or a Cloudflare application as the resource being requested.
  • Workflows: add users to Cloudflare Access groups, remove them, or check membership as part of onboarding, offboarding, and access-request workflows.
  • Agent rules: reference Cloudflare groups and applications by name so an agent can grant access or answer “who has access to this app” without leaving the ticket.
Sync runs at the organization scope. The Cloudflare account you connect is unique per Ravenna organization, so the same account cannot be connected twice.

Semantic fields

Ravenna exposes Cloudflare Access user data as semantic fields, so workflow and agent rule builders can filter or branch on them. Cloudflare groups and applications are exposed as semantic loaders, so any workflow, policy, or agent rule that accepts a group or application from an access provider can also accept a Cloudflare group or application.
Last modified on September 16, 2026