Summary
On August 19, 2026, Cloudflare Access added resource-scoped roles so members can list only the applications, policies, service tokens, and identity providers they are permitted to manage.
What changed
Cloudflare Access resource lists now support resource-scoped roles, filtering the visible applications, policies, service tokens, and identity providers to a member's permissions.
Why it matters
Scoping what administrators can see and manage supports least-privilege delegation in Zero Trust deployments, letting large teams divide Access administration without exposing the full estate.
Evidence excerpt
Members with resource-scoped Access roles can now list only the applications, policies, service tokens, and identity providers they can manage.