What problem does it solve? Migrating from Zscaler ZIA/ZPA, Palo Alto NGFW/Prisma, or legacy VPN/SWG stacks to Cloudflare One involves hundreds of interdependent policies, objects, and connectors where missed mappings cause silent security gaps. This Skill structures the entire migration so every source rule is accounted for. ## Core Features & Use Cases - Source Inventory & Export Guidance: Specifies exactly which exports to request from ZIA, ZPA, and Palo Alto/Prisma, including policies, objects, tunnels, and hit counts. - Mapping Heuristics & Traps: Maps source constructs to Cloudflare Gateway policies, Access apps, Cloudflare Tunnel routes, DLP profiles, and Split Tunnels, while flagging partial or unsupported mappings like Zscaler caution/warn behavior and Palo Alto App-ID. - Staged Rollout & Validation Gates: Enforces disabled/audit-mode creation, pilot groups, object-count comparisons, rollback paths, and a final source-rule accounting table. - Use Case: Given a ZPA export with app segments and connector groups, produce a mapping plan that creates one Cloudflare Tunnel per connector group, CIDR and hostname routes per app segment, and reusable Access policies attached to each app. ## Quick Start Ask the assistant to plan a migration from your Zscaler ZIA and ZPA exports to Cloudflare One, including a policy mapping table and pilot rollout plan.