AI Demo Cloudflare AI security demo

AI Demo

Five deliberately ordinary-looking internal apps at Horizon Inc, each with its own MCP server, and one question: what does an AI agent get to see that the person driving it never could?

This is the guide to a Cloudflare AI security demo. Horizon Inc is invented; the apps are real, deployed, and behind Cloudflare Access. The data in them is entirely synthetic but written to look and read like the real thing. Every gap an agent can walk through here is deliberate, documented, and closed again by a Cloudflare control on the protection page.

The company is made up. The failures are not: every control here exists because of a published incident, and each one is cited on the real incidents page — EchoLeak against Microsoft 365 Copilot, the Gemini calendar-invite research, Samsung's engineers and ChatGPT, Asana's MCP server crossing tenants, GitHub MCP and DeepSeek's open database. It is a good four minutes to spend before anyone sees a screen.

What the deploy scripts build

Architecture of the deployed demo. On the left, a user at a desktop device running a browser and OpenCode, both carrying a signed-in Cloudflare One client device session. FlareID sits above as the identity provider, reached by SSO. In the middle, the Cloudflare layer: Access in front of everything, then Cloudflare OS as a hosted agent, the MCP Portal, the Web Gateway doing tool request and response DLP, and an AI Gateway fronting Workers AI. On the right, five applications - WorkWeek (HR), Pipeline (CRM), WorkBox (Inbox/Calendar), Nexus (Wiki) and Ledger (Finance, Executives only) - each a web app and an API with its own MCP server alongside. Blue arrows trace the browser and model path; orange arrows trace the MCP tool path.
Everything above is created by ./deploy.sh, except the hosted agent, which is optional. The two arrow colours are the point of the whole demo: the blue path is what the person can reach, the orange path is what their agent can reach, and they arrive at the same APIs by different routes.

Read it right to left and the argument is already visible. Each application has a web app and an API that have been careful about access control for years, and then an MCP server beside them that was added later and is not equally careful. The five Cloudflare boxes in the middle are the controls on the protection page, and every one of them sits in the path rather than inside an application — which is why none of the applications change between the "before" and "after" halves of a demo.

The apps

AppWhat it holdsMCP server
WorkWeek (HR)People, pay, reviews, home addresses, HR case notes
Pipeline (CRM)Accounts, contacts, deals, forecast and margin
WorkBox (Inbox/Calendar)Mail, calendar, an archived exec distribution list
Nexus (Wiki)Public and restricted spaces, exec planning, strategy
Ledger (Finance)Cost centres, payroll runs, the board pack — Executives only
FlareIDThe identity provider behind Cloudflare Access for all of the above—

The person in the chair

Alice Watson

Content Strategist, Marketing. Reports to Art Schowalter-Haag (VP Marketing). Joined 2016.

Sign in as alice.watson@company.com — password Savetheinternet!1.

In the web UI Alice can see the staff directory, her own pay and profile, her own mailbox and calendar, and the public wiki spaces. That is all. She owns no CRM accounts and is not a member of any restricted wiki space.

Nikita Chapman

Chief Executive Officer. The person most of the intentional-misuse prompts are aimed at.

Her home address, pay, calendar, and the board material she is working on are all things Alice has no route to in any of the web apps she can open.

Two storylines everything hangs off

Project Ironwood

A confidential acquisition, mid-diligence. It shows up as an Executive wiki page, a CRM account and deal, a run of calendar entries, and an exec mail thread — so an agent can reconstruct most of it from pieces that each look harmless on their own.

The Q1 restructure

A planned reduction in Marketing, with a named list. It shows up as HR case notes and severance figures, "planning" meetings on the exec calendar, and a restricted People-space wiki page. Alice's own team is on the list.

How to run the demo

  1. The data — what each app holds, and exactly which of it the API and MCP servers hand out that the web UI never will.
  2. Setup — point opencode at the MCP portal and at a model behind AI Gateway, with the two settings that stop the agent wasting a dozen steps looking for its tools.
  3. Demo scripts — eleven scripted prompts, single-app and cross-app, intentional and accidental, plus one indirect prompt injection.
  4. Protection — what gets deployed when the protection layer is turned on, and which control stops which prompt.
The apps ship in two modes

The same repo deploys either just the apps and their Access configuration (the "before" state, where every prompt below succeeds), or the apps plus AI Gateway, DLP profiles, an MCP server portal routed through Gateway, and the Gateway rules that stop them. Flip between them by re-running one script — see protection.