Skip to content
Sample workspace. All evidence is fictional. Feedback and outcomes last for this page session only. No infrastructure account is connected.

Assessment · assets.example.com

Your opportunities

September 1–7, 2026 · Seven complete UTC days

Opportunities

2

Plus one related remediation option

Rule coverage

4 of 5

Bot evidence needs confirmation

Estimated savings

Not estimated

Customer cost evidence needed

2 opportunities

SecurityHigh confidenceHigh priority

Review managed WAF protection

500,000 HTTP requests in 7 days; no effective managed-WAF deployment at zone or applicable account scope.

Recommended next step

Review the appropriate managed ruleset, validate application compatibility, and stage deployment with monitoring.

Evidence, assumptions & measurement

Impact

Potentially improve request inspection coverage. No monetary savings are asserted.

Effort & risk

Configuration review and staged rollout. Rules can block legitimate application traffic; review matches before enforcement.

Measure the outcome

Rescan after deployment and review false positives and application error rates.

Assumptions

  • Deployment absence does not prove an attack occurred.
  • Paid entitlement and commercial value require separate confirmation.

Evidence

  • Zone inventory

    Fictional active zone: assets.example.com.

  • Customer confirmation

    Fictional customer marked this scope production and non-test.

  • Zone managed-WAF entrypoint

    Fixture confirms readable zone scope with no effective deployment.

  • Applicable account managed-WAF entrypoint

    Fixture confirms readable account scope with no applicable deployment.

  • HTTP analytics

    500,000 eyeball requests; 12 GB response bytes; seven complete UTC days; unsampled fixture.

Rule CF-001 · Version 2026-09-19.2 · All sources are sample fixtures.

PerformanceHigh confidenceHigh priority

Improve cache realization for static assets

116,000 of 200,000 eligible requests (58%) contacted origin over seven days.

Recommended next step

Review cache eligibility, response headers, TTLs, and cache keys for the affected public static cohort. Test with a narrow rollout.

Evidence, assumptions & measurement

Impact

Potentially reduce origin requests and bandwidth. Cost evidence is needed to estimate savings.

Effort & risk

Application and cache configuration review. Incorrect caching can serve stale or private content. Keep authenticated and private responses excluded.

Measure the outcome

Compare origin-contact share in equivalent seven-day windows after the change.

Assumptions

  • MISS, EXPIRED, and REVALIDATED indicate origin contact, not guaranteed avoidable traffic.
  • The cohort is confirmed public and static; intentional bypass is excluded.
  • MISS/EXPIRED traffic persists on at least three distinct days in the cohort, not necessarily for the same object.
  • The owner confirmed that purges, deployments, development mode, or cache-policy changes do not explain the window’s misses.

Evidence

  • Zone inventory

    Fictional active zone: assets.example.com.

  • Customer confirmation

    Fictional customer marked this scope production and non-test.

  • HTTP analytics

    500,000 eyeball requests; 12 GB response bytes; seven complete UTC days; unsampled fixture.

  • Cache cohort and configuration review

    200,000 confirmed public static requests; 116,000 origin contacts; 105,000 MISS/EXPIRED. Repeated misses and cache intent confirmed; private/API/auth traffic excluded.

Rule CF-007 · Version 2026-09-19.2 · All sources are sample fixtures.

Related action: Evaluate tiered caching

tiered caching is off; 105,000 MISS/EXPIRED requests among 200,000 static requests in seven days.

Review tiered caching availability and origin topology, then trial it on this zone.

Potentially reduce repeat origin fetches. This is a cache remediation option, not an additional savings estimate.

Risk: Validate origin compatibility and monitor latency during rollout.

Measure: Compare origin fetches, latency, and errors across equivalent windows.

Coverage & limitations

CF-008 · No finding

No referenced load-balancer pools in the covered scope.

CF-003 · Needs evidence

Owner confirmation of Enterprise bot analysis entitlement and edge functions signal use is required.