What can the installer do in our account?
It asks for ten Cloudflare permissions, holds the key an hour at most, never logs it, revokes it when the job ends, and deletes the plan.
The installer gets a key from the Allow, holds it only in the install's job for an hour at most, never logs it, and revokes it when the job ends. Afterwards it keeps the install's record: no key and none of the plan's people, but the Cloudflare account's name, which may hold an email address.
The permissions
The Cloudflare Allow page lists the ten scopes the installer asks for:
| Scope | What the installer does with it |
|---|---|
account-settings.read | Lists the accounts the Allow covers, and reads the one picked |
user-details.read | Asked for with the account read; the code calls no user endpoint |
workers-scripts.write | Uploads the nine Workers and the web app; deletes them on removal |
workers-kv-storage.write | Makes the three key-value stores; deletes them on removal |
workers-r2.write | Makes the bucket; empties and deletes it on removal |
aig.write | Makes the AI Gateway default if the account has none |
access-app.write | Makes the sign-in app for the firm's address; deletes it on removal |
access-policy.write | Sets that app's rule: who may get in |
access-idp.write | Adds sign-in with email codes if the account has none |
access-org.write | Reads the account's Zero Trust team, or makes one |
The installer is a public OAuth client using PKCE, with no client secret. Tick one account on the Allow page: the key covers every account ticked until it is revoked, and firm os goes into one.
The key
- Only the install's job holds it, and it is never logged.
- It is held an hour at most from the Allow, less if the key Cloudflare gave runs out sooner.
- It is revoked as soon as the job ends. If Cloudflare doesn't confirm, the revocation is tried each minute until the key would have run out anyway.
- If a step stops, it stays for Try again until its hour is up, then is revoked.
- A key the job won't use, such as a second Allow during a running install, is revoked at once.
The plan
A plan holds the firm's name, a line for its agents, its email domains, and each person's name, email, role and admin flag. The Install link carries only the plan's number.
- It waits a day at most for its Allow, then is deleted.
- After the Allow, it is deleted when the install ends or when the key's hour is up, whichever comes first.
- The Install page shows counts of people and admins, and the domains: never an email.
What the installer keeps
- The install's record, so Remove can work later: the firm's name, the Cloudflare account's ID, the firm os address, the release, step times, and what it made. No name or email of the plan's people, and no key. The code sets no time limit on it.
- The Cloudflare account's name, as Cloudflare gives it. It often holds an email address: Cloudflare names a new account after the email that opened it, as in
ana@acme.example's Account. The installer reads it from the Cloudflare list of the accounts the Allow covers, so the install's pages can say which account firm os is in. It is kept with the install's record, with no time limit. When an Allow covers several accounts, the installer holds the name of every account it covered until the person picks one or the key goes back, an hour at most. - Anyone with the install's link can see that progress, the account's name included. Removing anything takes a new Allow that covers the account.
- Signups from the front page: each email once, when it came, and a short source label, 10,000 at most. The operator can delete any one.
- The installer's code writes no log lines of its own. Its Worker has Workers Logs turned on.
The AI Gateway default that the installer makes, when the account has none, keeps logs of model requests in your account, as firm os's own deploy expects. You can turn its logging off in the Cloudflare dashboard.
Updated This page as Markdown