started · updated
Cloudflare launches WriteGuard beta to safeguard AI agent write actions
Cloudflare has begun a private beta of WriteGuard, a gate‑keeping feature for Model Context Protocol (MCP) servers that lets developers set fine‑grained policies on AI agents’ write operations. Each tool is assigned a risk tier and WriteGuard can allow, modify, or block actions, while logging the user, agent, tool and outcome for audit purposes. The system is designed to prevent incidents such as an AI agent unintentionally deleting large numbers of records or altering sensitive data, a risk that grows as agents move from read‑only to write‑enabled roles.
The company reports that its internal MCP portal now connects 27 servers, up from 13 in April, showing rapid adoption of AI‑driven tooling. WriteGuard supplements existing Access and OAuth permissions, ensuring agents cannot exceed the authority of the human account they run under, and provides clear attribution between human and agent changes.