AI Demo Cloudflare AI security demo

AI Demo

Four deliberately ordinary-looking internal apps, each with its own MCP server, and one question: what does an AI agent get to see that the person driving it never could?

This is the guide to a Cloudflare AI security demo. The apps are real, deployed, and behind Cloudflare Access. The data in them is entirely synthetic but written to look and read like the real thing. Every gap an agent can walk through here is deliberate, documented, and closed again by a Cloudflare control on the protection page.

The apps

AppWhat it holdsMCP server
WorkWeek (HR)People, pay, reviews, home addresses, HR case notes
Pipeline (CRM)Accounts, contacts, deals, forecast and margin
Relay (Inbox/Calendar)Mail, calendar, an archived exec distribution list
Nexus (Wiki)Public and restricted spaces, exec planning, strategy
FlareIDThe identity provider behind Cloudflare Access for all of the above

The person in the chair

Delta Graham

Content Strategist, Marketing. Reports to Art Schowalter-Haag (VP Marketing). Joined 2016.

Sign in as delta.graham@company.com — password Savetheinternet!1.

In the web UI Delta can see the staff directory, her own pay and profile, her own mailbox and calendar, and the public wiki spaces. That is all. She owns no CRM accounts and is not a member of any restricted wiki space.

Nikita Crist

Chief Executive Officer. The person most of the intentional-misuse prompts are aimed at.

Her home address, pay, calendar, and the board material she is working on are all things Delta has no route to in any of the four web apps.

Two storylines everything hangs off

Project Ironwood

A confidential acquisition, mid-diligence. It shows up as an Executive wiki page, a CRM account and deal, a run of calendar entries, and an exec mail thread — so an agent can reconstruct most of it from pieces that each look harmless on their own.

The Q1 restructure

A planned reduction in Marketing, with a named list. It shows up as HR case notes and severance figures, "planning" meetings on the exec calendar, and a restricted People-space wiki page. Delta's own team is on the list.

How to run the demo

  1. The data — what each app holds, and exactly which of it the API and MCP servers hand out that the web UI never will.
  2. Setup — point opencode or Open WebUI at the MCP portal and at a model behind AI Gateway.
  3. Demo scripts — eleven scripted prompts, single-app and cross-app, intentional and accidental, plus one indirect prompt injection.
  4. Protection — what gets deployed when the protection layer is turned on, and which control stops which prompt.
The apps ship in two modes

The same repo deploys either just the apps and their Access configuration (the "before" state, where every prompt below succeeds), or the apps plus AI Gateway, DLP profiles, an MCP server portal routed through Gateway, and the Gateway rules that stop them. Flip between them by re-running one script — see protection.