What you are evaluating
The scored scope is Access plus Gateway HTTP filtering with the required client, tunnel and TLS trust configuration. DLP, browser isolation, CASB API scanning and WAN services are excluded from the selected baseline.
A useful evaluation context
Consider for teams seeking clearly separated application authorization and outbound traffic policy within one cloud platform.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Access policy combines actions with user, group and contextual selectors.
- Gateway HTTP policy can inspect supported web requests when traffic routing and certificate trust are configured.
- Separate authentication, Gateway and administrative log categories support investigation.
Where it fits in the work
- Publish a lab application through a supported connector and require an approved test identity.
- Steer a managed endpoint’s web traffic through Gateway and configure its trust certificate.
- Test a denied application request and a blocked web request, then inspect the different logs.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A lab user can open one private application but cannot upload a harmless file to a blocked test destination.
Evidence to look for
Show the Access decision separately from the Gateway HTTP decision and identify whether content inspection was enabled.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which client mode and split-tunnel rules apply to this resource?
- Is HTTPS decrypted, bypassed or unsupported on this path?
- What log retention and export entitlements meet the investigation requirement?
Names you may encounter: Cloudflare Access · Cloudflare Gateway. Historical names do not establish current availability or feature equivalence.