Summary

On August 19, 2026, Cloudflare Access added resource-scoped roles so members can list only the applications, policies, service tokens, and identity providers they are permitted to manage.

What changed

Cloudflare Access resource lists now support resource-scoped roles, filtering the visible applications, policies, service tokens, and identity providers to a member's permissions.

Why it matters

Scoping what administrators can see and manage supports least-privilege delegation in Zero Trust deployments, letting large teams divide Access administration without exposing the full estate.

Evidence excerpt

Members with resource-scoped Access roles can now list only the applications, policies, service tokens, and identity providers they can manage.

Sources