SYSTEM Cited by 1 source
WriteGuard¶
Overview¶
WriteGuard is Cloudflare's server-side per-tool authorization control, applied across its internal MCP servers. Each tool has a risk tier and an enabled/disabled state; WriteGuard sits at the server — the last point a request can be denied before the tool handler runs — and does one of three things per call:
- pass a read through unchanged,
- add agent attribution + an audit event to an allowed write, or
- block a critical action before its handler runs.
Because the control lives at the server, "an end user cannot bypass it by switching clients or disabling a local hook." (Source: sources/2026-08-14-cloudflare-how-cloudflare-detects-mcp-traffic-and-helps-secure-it)
WriteGuard is the server control point in the three-control-points framing (client / network / server) and the canonical Cloudflare instance of patterns/tool-surface-minimization — the richest execution context (caller authenticated, message parsed, tool resolved, arguments validated) but coverage limited to servers that implement it. The article notes these checks should be performed before invoking the handler, especially for tools that write data or trigger external actions — logging only after execution can explain what happened but cannot prevent it.
Cloudflare covered WriteGuard in more depth in MCP Portal WriteGuard (private beta).
Caveats¶
The source describes the read-pass / write-annotate / critical-block behaviour, risk tiers, and the enabled/disabled state, but not the policy schema, how risk tiers are assigned, latency, or the private-beta availability details beyond the linked post.
Seen in¶
- sources/2026-08-14-cloudflare-how-cloudflare-detects-mcp-traffic-and-helps-secure-it — server-side per-tool authorization on Cloudflare's internal MCP servers.
Related¶
- systems/model-context-protocol — the protocol whose tool calls WriteGuard gates.
- systems/mcp-server-portal — the governed path WriteGuard complements at the server.
- systems/cloudflare-agents-sdk — the SDK altitude where such handlers live.
- three-control-points-for-agent-tool-calls — WriteGuard is the server point.
- patterns/tool-surface-minimization — the canonical pattern.