What happened
On Oct 7, Cloudflare published how its Managed Defense now runs a multi-AI-agent security operations harness: deterministic recon code collects evidence before inference, Clef (Cloudflare's open-weights decision model) scores alerts to filter noise, then a coordinator runs four specialist agents (traffic analysis, customer context, global telemetry, threat intel) plus a synthesis agent, using approved OpenAI Daybreak (GPT-5.6 Cyber) and Anthropic Mythos models.
Why it matters
This is a production reference architecture for evidence-grounded agentic SOC triage (fixing hallucination/scope/failure-visibility problems) and confirms Cloudflare is operationalizing Daybreak/Mythos cyber models in a managed detection service.
Applicability
Security platform teams building multi-agent SOC harnesses should study Cloudflare's deterministic-recon-before-inference pattern and its constraint that synthesis agents cannot fetch new evidence.