Read zones, DNS, and WAF lists; change records as an approved step.
Connect Cloudflare and the agent can read your zones, DNS records, firewall rules, WAF lists, load balancer pools, and tunnels while you work. Ask what a record points at today, or which rules cover a zone, and get an answer straight away. Changes like creating a DNS record are previewed first and go out for approval before they touch the live zone.
20 tools: 10 read, 10 write. Reads answer instantly. Writes require approval by default. Everything is logged.
What a governed Cloudflare run looks like inside Luumen.
Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.
Read actions answer immediately. Anything that writes — create dns record, create waf list, create zone, delete dns record, and more — is shown as a plan and requires approval by default, including the 3 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.
You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.
Every call to Cloudflare — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.
Connect in minutes. Every action scoped, approved, and audited from day one.