What problem does it solve? Cloudflare One spans Access, Gateway, WARP, Tunnel, WAN, DLP, and CASB, and misconfiguring any boundary between them causes broken connectivity or unintended exposure. This Skill provides structured workflows and guardrails so changes are planned, validated, and rolled back safely. ## Core Features & Use Cases - Design and Configuration Guidance: Walks through assessment prompts, prerequisites, exact resources to change, validation steps, and rollback plans for Access apps, tunnels, Gateway policies, TLS inspection, and DLP. - Troubleshooting Workflow: Traces failures from Gateway activity logs and Access audit logs back to the responsible rule, route, or policy instead of guessing. - Safety Guardrails: Enforces rules like never guessing category IDs or API bodies, starting broad policies in disabled or pilot scope, and keeping secrets out of transcripts. - Use Case: When migrating from a legacy VPN to ZTNA, use it to plan tunnel routes, split tunnel mode, enrollment rules, and device profiles, then verify end-to-end access from a test device before rollout. ## Quick Start Ask the assistant to design a Cloudflare Access policy and private tunnel route for an internal application, including validation and rollback steps.