📁 Other
Cloudflare Zero Trust Access Policy Map from Inventory (No Invented Device Posture Scores)
Turn a Cloudflare Zero Trust inventory into an Access policy map only. No invented device posture scores, tunnel secrets, or IdP credentials.
0Reviews
Prompt
Act as a Cloudflare Zero Trust Access engineer who only uses a pasted inventory. You write an Access policy map the inventory already supports. You do not invent device posture scores, tunnel secrets, IdP credentials, or WARP enrollment counts. This is not a live Cloudflare dashboard change and not a penetration test report. You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs. Inputs: - Zero Trust inventory I lock (apps, policies, tunnel stubs): [Inventory] - Cloudflare / Zero Trust version notes I lock: [Version] - Team or account label I may quote (or UNKNOWN): [Team] - Application names already present (or UNKNOWN): [Applications] - Access policy names already present (or UNKNOWN): [Policies] - Tunnel names already present (or UNKNOWN): [Tunnels] - IdP or rule labels already present (or UNKNOWN): [IdPs] - Words I must not use: [Banned] - What I must never invent (device posture scores, tunnel secrets, IdP credentials, WARP enrollment counts): [Never] - Output format: [Format] - Language: [Lang] Generate: 1. Honesty ledger: Inventory nouns, Version, Team, Applications, Policies, Tunnels, IdPs, Lang. Forbidden: invented device posture scores, tunnel secrets, IdP credentials, WARP enrollment counts. Banner: not a live Cloudflare dashboard change; not a penetration test report. Add not-advice de-identify note. 2. Access policy map table: one row per Inventory application stub. Missing notes write NOT IN INPUTS. Use Application, Policy, Tunnel, and IdP language only when Inventory supports it. 3. Tunnel set: only names in Tunnels. Unnamed tunnels stay NOT IN INPUTS. Never invent device posture scores. 4. Version lock: print Version. Refuse Zero Trust features newer than Version if Version is named. 5. Refuse list: inventing device posture scores, inventing tunnel secrets, inventing IdP credentials, inventing WARP enrollment counts. 6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format. Constraints: - Map from Inventory only. No invented device posture scores. Teach Cloudflare Zero Trust Access policy mapping, not a generic firewall ACL dump. - Honor Version. No emojis.
Instructions
Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.
Generated Output
This image was generated using the prompt above.

Examples
Example Input
Inventory: App Harbor Quay Staging as pasted; App River Gate Admin as pasted; Policy Cleat Email Allow as pasted; Tunnel UNKNOWN. Version: Cloudflare Zero Trust 2026-03 notes as pasted (do not invent unreleased AI posture APIs) Team: Harbor Quay Edge as pasted Applications: Harbor Quay Staging as pasted; River Gate Admin as pasted. Capstan Public UNKNOWN. Policies: Cleat Email Allow as pasted. Device High Score UNKNOWN. Tunnels: cleat-staging-tunnel as pasted. river-secret UNKNOWN. IdPs: Okta Cleat IdP as pasted. WARP Count Rule UNKNOWN. Banned: guaranteed posture score, invent tunnel secret, invent IdP password, invent WARP count Never: invent device posture scores, invent tunnel secrets, invent IdP credentials, invent WARP enrollment counts Format: ledger + table + tunnels + version + refuse + compliance Lang: English
Example Output
1. Ledger. Inventory: App Harbor Quay Staging; App River Gate Admin; Policy Cleat Email Allow; Tunnel UNKNOWN. Version Cloudflare Zero Trust 2026-03 notes. Team Harbor Quay Edge. Applications Harbor Quay Staging, River Gate Admin. Policies Cleat Email Allow. Tunnels cleat-staging-tunnel. IdPs Okta Cleat IdP. Lang English. Banner: not a live Cloudflare dashboard change; not a penetration test report. Not-advice: de-identify; not a pen-test certification. Forbidden: invented device posture scores, tunnel secrets, IdP credentials, WARP enrollment counts. 2. Access policy map. 1. Harbor Quay Staging | policy Cleat Email Allow as pasted | tunnel cleat-staging-tunnel as pasted | IdP Okta Cleat IdP as pasted | posture score NOT IN INPUTS | tunnel secret NOT IN INPUTS. 2. River Gate Admin | policy Cleat Email Allow as pasted | Capstan Public NOT IN INPUTS | Device High Score NOT IN INPUTS. 3. Tunnel root stub | UNKNOWN so write Tunnel NOT IN INPUTS. No invented VALUES beyond Inventory. 3. Tunnel set. cleat-staging-tunnel as Tunnels. river-secret UNKNOWN so write river-secret NOT IN INPUTS. Never invent device posture scores. 4. Version lock. Cloudflare Zero Trust 2026-03 notes as pasted. Unreleased AI posture APIs not used. Capstan Public UNKNOWN. 5. Refuse. Invented device posture scores, tunnel secrets, IdP credentials, WARP enrollment counts: refused. 6. Compliance. Banned hits none. Format ledger+table+tunnels+version+refuse+compliance. Gaps: Tunnel root, Capstan Public app, Device High Score policy, river-secret tunnel, WARP Count Rule. Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.