Cloudflare opened a managed waitlist for Cloudflare OS on October 1, 2026, giving teams considering organizational AI workspaces a future alternative to operating their own deployment. The announcement is a waitlist opening, not general availability.
For buyers, the immediate choice is whether to evaluate the open-source edition now or seek managed-service terms. Neither the announcement nor the linked interest page gives a managed price or launch date.
Self-deployment and managed operation are different choices
The starter documentation describes both a browser installer and a customizable repository for deploying into your Cloudflare account. The installer reduces setup work; it is not the newly proposed managed service. The core README labels the software early access.
The comparison below combines those deployment documents with Cloudflare’s managed-service announcement. The final row is our recommendation, not a vendor commitment.
Decision | Self-deployed Cloudflare OS | Proposed managed Cloudflare OS |
|---|---|---|
Availability | Early-access software deployable into your Cloudflare account. | Waitlist registrations; no announced general-availability date. |
Operating responsibility | Your team configures, operates and updates the deployment. | Cloudflare proposes handling operation; you still choose access, organizational context and connected systems. |
Customization | The starter supports custom Gatekeepers and pinned upstream releases. | Customization parity and upgrade controls need confirmation. |
Suggested next step | Run a limited pilot if a platform owner can maintain it. | Request access and written terms if ongoing operation is the obstacle. |
Self-deployment here does not mean a turnkey on-premises edition. The own-server section still lists deployment documentation and tooling as forthcoming. If on-premises or air-gapped operation is a hard requirement, our IBM Bob self-hosting guide discusses those hosting and inference choices for a separate coding product; they should not be assumed for Cloudflare OS.
Evaluate the connector permissions, not just sign-in
Cloudflare says the workspace can now edit existing GitHub repositories, commit and push changes, and open pull requests. Its Google Workspace updates cover Gmail research, drafts and sending, plus connections to selected Drive resources or an entire Drive.
For a pilot, separate three questions: what permission the provider grants the connector, which resources the agent can use, and which external actions require approval. A successful login answers none of those by itself. The connector details below describe the reviewed open-source revision, not a confirmed managed build. Cloudflare calls these service connectors Gatekeepers.
GitHub: a selected repository is not the OAuth scope
The GitHub Gatekeeper README distinguishes identity-only sign-in from resource connections that request the repo OAuth scope. GitHub defines that scope broadly across public and private repository resources, within the authorizing user’s existing permissions. That provider grant is distinct from the selected resource exposed through the Gatekeeper.
Proposed pilot: use disposable repositories and specify whether the task may only read, edit locally, push a branch or open a pull request. Check organization restrictions, branch protection, denied actions and revoked access. Verify accepted changes in GitHub, not only in the agent’s response.
Google: reading Drive and editing Docs are different connections
The Google Gatekeeper documentation describes these distinct permissions:
Gmail: the connector requests
gmail.modify, which includes sending. Google’s scope reference confirms that breadth; a read-oriented task does not make the grant read-only.Drive: account, folder and exact-file bindings are read-only. Native Docs and Sheets opened through them use read-only scopes.
Direct Docs and Sheets: a direct Google Doc connection supports edits; selected spreadsheets are documented for metadata and bounded-range reads. Do not equate a Sheets connection with spreadsheet editing.
Proposed pilot: start with synthetic email and a test document or folder. Check reading, drafting and sending separately, then repeat sharing checks with an identity that lacks the source permission. Confirm the connector’s consent requirements for the intended users before expanding access.
Approval: distinguish prepared work from completed actions
The core README describes Gatekeepers simulating approval-requiring actions so agents can continue before a person accepts or rejects them. That is an architecture description, not proof that every connector behaves identically. Record prepared, approved and provider-confirmed states separately: an agent finishing its task is not sufficient evidence that an email was sent or a change was pushed.
Budget for the workload and the operating team
The Workers Paid minimum is $5 USD per account per month. Dynamic Workers require that plan and meter daily Worker creations alongside shared Workers request and CPU usage. The $5 minimum is neither an all-inclusive Cloudflare OS bill nor a managed-service quote.
For a useful comparison, estimate runtime, storage, model inference and any chargeable identity or logging services. Add staff time for connector administration, upgrades, recovery and output review. Compare the same tasks and review standard on each route; a managed-versus-self-deployed break-even figure is premature without a managed quote.
Get these managed-service terms before planning a cutover
The reviewed managed pages do not establish the terms below. Request them in writing; missing public detail does not mean a capability will be absent.
Access and cost: admission timing, launch availability, pricing units, included usage and overages.
Operations and data: tenant/account ownership, connector administration, model-provider data routes, retention, deletion, backups, recovery, audit export and support commitments.
Control and exit: supported customizations, upgrade control, whole-workspace export and migration from a self-deployed instance.
For document handoffs, Cloudflare lists XLSX, CSV, PDF, Markdown and HTML exports, depending on the artifact. DOCX and PPTX are still forthcoming. If either is mandatory, verify support before choosing the workflow; exporting a document is not evidence of complete workspace portability.
A sensible next step is one bounded workflow with a named owner and an acceptance record. Self-deploy if maintaining that pilot is feasible. Join the managed waitlist if outsourcing operation is the goal, but keep any production migration conditional on access, terms and a verified workflow.
Methodology: This AI-assisted decision guide draws on Cloudflare’s announcement, pinned repository documentation and official GitHub and Google permission references, checked on October 1, 2026. Capabilities are vendor-described; no hands-on deployment, permission test or performance benchmark was conducted.
