Cloudflare
Your account, your infrastructure — from inside sSystm.
#What Cloudflare does
A window into the Cloudflare account you connected: the database holding your workspace, your domains, your traffic, your AI gateways and what is waiting for approval.
| Group | Workspace — included |
| Works with | AI access · Agents · Data |
- The approvals queue. Changes to your infrastructure — asked for by a person or proposed by AI — are risk-classified and held here until someone approves. Nothing reshapes live infrastructure on an ambiguous sentence.
- Database, domains, workers. The database holding your workspace, your zones and DNS, and what is deployed — without a second tab.
- Your AI gateways. The gateways on your own account, with the last seven days of requests, cache hits, errors, tokens and cost. A gateway caches identical calls, rate-limits them and logs every one, without any application code changing.
- Real traffic and blocked threats. Analytics from your own account. When nothing is connected the panel says so instead of inventing a chart.
- Granted one capability at a time. Reading, changing, connecting, writing to the database, deploying, managing domains — six separate permissions, owner-only by default.
#Why it exists
Bring Your Own Cloud is only a real promise if you can see what is happening on your account without leaving the product — and only safe if changes cannot happen behind your back.
Eight views onto your own account, and an approvals queue where every infrastructure change waits for a person. Access starts with the owner alone and is granted one capability at a time.
#What the eight views show
A window into the account you connected: Overview, Database, Domains, Security, Analytics, Workers, AI Gateway and Approvals.
Infrastructure changes — asked for by a person or proposed by AI — are risk-classified and wait here for someone to approve them. If a deploy seems to do nothing, this is usually where it is.
#AI Gateway, and why it is here
An AI Gateway is a single endpoint that sits in front of the AI providers. It caches identical requests, enforces rate limits and logs every call, without anything in the application having to change.
It is in this module for the reason the database is: sSystm can route its AI calls through your gateway instead of ours, so the usage and the cost land on your account. The same argument as bringing your own cloud, applied to the part of the bill that grows fastest.
The view lists the gateways on your account with their cache TTL and rate limit, and seven days of requests, cached hits, errors, tokens and cost. Creating a gateway is a change to your infrastructure, so it goes to Approvals like any other.
#Granting access to it
Cloud permissions start with the owner alone and are granted one capability at a time: reading, changing, connecting or disconnecting, writing to the database, deploying, managing domains.
Nothing about your cloud account arrives bundled with a job title. If you want an admin to deploy, you grant exactly that and nothing else.
#On the MCP surface
Your AI can propose infrastructure changes in plain language. It cannot execute them — every one is risk-classified and held for a human in the approvals queue.
#On the Cloudflare side
- This module IS the Cloudflare surface: it acts on the account you connected, using the fine-grained OAuth scopes you granted, with the token stored encrypted and decrypted server-side only.
#Works with
Verified against the app on