AI analytics

AI Security Report dashboard operating guide

Use Cloudflare One's AI Security Report as the executive and operations view for workforce AI adoption, app review status, data movement, and MCP access governance.

Where It Fits

The dashboard belongs after Gateway and AI controls are in place. It is not the control itself; it is the feedback loop that shows whether your AI governance program is working.

DiscoverSee which AI applications users are visiting, and how adoption changes over time.
ClassifyTrack whether AI applications are approved, unapproved, in review, or still unreviewed.
Measure data movementWatch uploaded data volume by application status so unapproved and unreviewed tools do not quietly become data sinks.
Govern agentsTrack MCP servers protected by Access and monitor login events to those servers.

Prerequisites

To make the report meaningful, route outbound HTTP and DNS traffic through Cloudflare Gateway. Users also need to access SaaS AI applications, such as ChatGPT or Gemini, through Gateway. For the MCP views, place MCP servers behind Cloudflare Access policies.

Dashboard Path

In the Cloudflare dashboard, open Zero Trust, go to Insights, then Dashboards, and select AI security report.

Panels to Operationalize

Adoption

Top AI apps by user count

Use this to identify which AI tools are becoming standard workflow dependencies and which new tools need review.

Governance

AI app status counts

Drive the backlog of app reviews. Unreviewed should trend down as your AI acceptable-use process matures.

Data risk

Uploads by app status

Prioritize policy work where users upload data to unapproved or unreviewed AI applications.

MCP

MCP servers behind Access

Confirm that new MCP servers and agent tools are protected before teams rely on them.

Access

MCP login events

Watch for unusual spikes, unexpected users, or access patterns that do not match the intended agent workflow.

Action

Review cadence

Review weekly during rollout, then monthly once the approved AI catalog and enforcement policies stabilize.

Operating Workflow

1. BaselineCollect two to four weeks of AI app usage before broad enforcement.
2. ReviewMove high-use applications out of unreviewed status into approved, in review, or unapproved.
3. ControlApply Gateway policies: allow sanctioned tools, restrict risky actions, and block or isolate unapproved tools.
4. Protect dataPair upload visibility with DLP and prompt protection for credentials, PII, source code, customer data, and financial data.
5. Audit MCPEnsure every MCP server is behind Access and that login patterns match expected users or service identities.

Metrics to Report

For leadership, keep the report simple: top AI tools, approved-versus-unreviewed ratio, upload volume to unapproved tools, number of MCP servers protected by Access, and unusual MCP login spikes.

Source Reference

This operating note is based on Cloudflare's AI Security Report dashboard documentation. Keep the official doc handy for current dashboard labels and product behavior: Cloudflare One AI Security documentation.