How we built Organizations to help enterprises manage Cloudflare at scale
Key Points
- Org Super Administrator role
- Cross-account analytics and shared policies
- Self-serve, security-first beta rollout
Summary
Cloudflare Organizations is a new enterprise-layer construct (built on the Tenant system) that lets administrators manage collections of Cloudflare Accounts together. It introduces an Org Super Administrator role with cross-account administrative capabilities, provides roll-up analytics and shared policy distribution (e.g., WAF and Gateway), and uses a security-first, self-serve invitation flow for beta onboarding. The feature is in public beta for enterprise customers with no additional fee.
Key Points
- Account list: flat list of onboarded accounts managed at the organization level.
- Org Super Administrator: organization-scoped role that has Super Administrator permissions across all child accounts without being listed in each account UI.
- Shared configurations: central policy sets can be shared from a source account to other accounts so teams can update WAF/Gateway rules centrally without org admin privileges.
- Analytics: roll-up HTTP traffic dashboard across accounts/zones; more org analytics planned.
- Security-first rollout: no automatic backfill; an enterprise Super Admin must create the organization via self-serve invitation to avoid privilege elevation.
- Technical improvements: consolidation onto domain-scoped roles, ~133k lines added and ~32k removed, and a ~27% improvement in permission-check performance for enumeration calls.
- Roadmap highlights: organization-level audit logs, billing reports, additional analytics, more org user roles, self-serve account creation, and partner support to follow.
- Support model: Cloudflare support will not make configuration changes for customers; coordinate internally to complete org rollouts.
Actionable notes for engineers
- If you are a Super Administrator of an enterprise account, claim your organization from the Dashboard > Organizations tab to start onboarding accounts.
- Expect centralized policy distribution for WAF/Gateway and a cross-account analytics view; plan integration with your existing reporting and change-management processes.
- Monitor the changelog and developer docs for upcoming APIs and organization-level features.