Zero Trust Access Flow

Two views of the same platform. Toggle between the daily employee experience and one-time contractor onboarding.

Daily login flow — 4 steps, under 5 seconds
The point: Zero Trust isn't supposed to be painful. This is what your team experiences when they log in to any protected app — internal HR tool, financial system, code repo, whatever. Total time under 5 seconds. After the first login, single sign-on kicks in and most of these steps disappear entirely.
Speed
Total time: 0.0s
Click "Start the flow" to see what your employees experience when they log in.

You're being verified

Cloudflare is checking your identity and device before letting you in.

Appfinance-portal.tarheel.us
RequiredCorporate IdP + posture check
NetworkAnywhere (no VPN required)

Sign in with Okta

Your company has chosen Okta as your identity provider

••••••••••••
Sign in
⚙ Device Posture Check

Verifying your device

Cloudflare checks that your device meets your company's security requirements before granting access — including that its EDR (Endpoint Detection & Response) agent is present and running.

OS up to date (macOS 14.0+)
Disk encryption enabled (FileVault)
EDR agent running (SentinelOne)
Cloudflare One Client active

Acme Financial Portal

Welcome back, Mayah. Your last sign-in was 2 hours ago from your corporate MacBook.

📊 Daily trading dashboard — real-time market data, your team's positions, alerts.
💼 Client accounts (43 active) — quick search, recent activity, compliance flags.
📁 Documents — last quarterly report opened 2 days ago, 12 pending reviews.
✓ Verified via Cloudflare Zero Trust
⚠ 4 hours later — posture is checked again, automatically

EDR agent stopped responding

Cloudflare doesn't just check posture once at login. The same four signals are re-verified continuously in the background, no separate step for Mayah to notice.

OS up to date (macOS 14.0+)
Disk encryption enabled (FileVault)
EDR agent running (SentinelOne) — stopped responding
Cloudflare One Client active
Access to Acme Financial Portal restricted automatically. No admin had to act — policy already said "no EDR, no Finance." Mayah is routed to a remediation page until the agent comes back online. Low-sensitivity, non-regulated apps are unaffected — this isn't all-or-nothing.
⏱ Flow timeline
Step 1
URL + verify
0.0s
Step 2
IdP login (SSO)
0.0s
Step 3
Posture check
0.0s
Step 4
App loads
0.0s
Step 5
Continuous check
0.0s
What just happened: Mayah typed the app URL. Cloudflare intercepted the request, sent her to her corporate IdP for SSO, ran a posture check on her device without her seeing it as a separate step, then loaded the app. Total time: under 5 seconds. Identity verified. Device verified. Policy enforced. All before traffic ever hit the application. On her next visit today, SSO skips the password step entirely — she sees this flow once per day, not per app. Then, hours later, the EDR agent on her laptop stops responding and Cloudflare re-checks posture on its own. Nobody has to notice the agent died and manually pull her access — the policy already said "no EDR, no Finance," so it enforces itself the moment posture changes, not just at the next login.
The point: Onboarding a contractor on a traditional VPN means creating an AD account, shipping a laptop, installing a VPN client, configuring policies, and giving them a phone number to call when it breaks. This is the Cloudflare version — 60 seconds, no laptop, no account in your AD, scoped to specific apps, auto-revoke when the project ends.
Speed
Elapsed: 0s
Admin

Cloudflare Zero Trust Dashboard

Step 1 — Open dashboard

Access Controls → Applications

Open the existing "Finance Portal" application. Add a new contractor email.

Add contractor

Q4 audit contractors Employees Executives
2026-12-31 (90 days from today)

Send the invite

Send invite to contractor
Contractor gets an email with a magic link. No agent install. No account in your AD. When 2026-12-31 hits, access auto-revokes.

Confirmation

✓ Invite sent. Contractor has access to Finance Portal only. Will auto-revoke on 2026-12-31. Audit log entry created.
Contractor

Mayah's inbox + browser

Waiting…

📥 New email arrives

🔢 Verify with email OTP

Enter the 6-digit code

Sent to mayah.davis@independent-auditor.com

✅ App loads

Acme Financial Portal

Q4 Audit View — Limited Access
📊 Q4 financial statements (read-only)
📁 Approved audit documents (12 files)
📈 Variance reports — Q3 vs Q4
✓ Verified via Cloudflare Zero Trust
Access expires in 90 days. No employee account. No VPN client. No laptop shipped.
⏱ End-to-end timeline
Step 1
Open app
Step 2
Add email + group
Step 3
Send invite
Step 4
Contractor clicks
Step 5
App loads
What just happened: The admin added a contractor email, assigned a group, set an expiration date, and clicked Send. The contractor got an email, clicked a magic link, verified with a 6-digit code, and landed in the app — scoped to just the Q4 audit data, nothing else. No AD account. No laptop. No agent. No phone call. When the audit ends, access auto-revokes — no manual cleanup, no forgotten accounts. Compare that to a traditional VPN onboarding cycle: days, sometimes weeks.