A2Techify / Field Notes

Cloudflare Workers Access Can Now Be Scoped Per App

Cloudflare Workers Access Can Now Be Scoped Per App

LinkedIn newsletter draft for A2Techify Field Notes.

Source post: https://blogs.a2techify.com/security/infrastructure/2026/09/17/cloudflare-workers-resource-scoped-access.html LinkedIn URL: TODO after publishing

Newsletter Title

Cloudflare Workers Access Can Now Be Scoped Per App

Intro

Cloudflare added resource-level roles for Workers, giving teams a cleaner way to give CI systems, teammates, and coding agents only the access one application needs.

Takeaways

  • Cloudflare introduced four Developer Platform roles that can be applied at platform, product, or resource scope:
  • Small teams tend to collect powerful tokens because narrow access was inconvenient.
  • Cloudflare’s docs describe permission policies as a role plus a scope.
  • The next important step is whether this model lands cleanly across D1, R2, KV, Queues, Vectorize, and Workers AI.

CTA

Read the full note: https://blogs.a2techify.com/security/infrastructure/2026/09/17/cloudflare-workers-resource-scoped-access.html

Publishing Notes

  • Publish manually from the A2Techify LinkedIn Page newsletter editor.
  • After publishing, add the LinkedIn newsletter URL to the source post front matter as linkedin_url.
  • Keep the blog post as the canonical article.

Topics: cloudflare, security, infrastructure, agents