Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Cloudflare MCP server portals vs Workday Agent System of Record

Cloudflare MCP server portals

Cloudflare One feature that puts MCP servers behind one governed endpoint

Workday Agent System of Record

Workday system of record to find, add, register, configure, monitor, and manage AI agents

Short answer

Cloudflare MCP server portals put multiple MCP servers behind one endpoint, governed by Cloudflare Access.⁠Source 1, Source 2 Workday Agent System of Record (ASOR) lets a company find, register, configure, monitor, and manage AI agents in its Workday tenant, each with a unique Workday identity under Workday security policies.⁠Source 3, Source 4, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both set access rules for AI agents and keep records: portals through Access policies and tool-request logs, ASOR through Workday security policies and an audit trail report.⁠Source 1, Source 6, Source 7
Where they differ
Portals manage MCP servers and their tools.⁠Source 1 For portals, a registry of agents is not publicly documented. ASOR registers agents, and for agents working with Workday, tools are Workday APIs.⁠Source 3
Running both
Neither vendor publicly documents using the two together. Cloudflare’s portals accept remote MCP clients; Workday’s docs say ASOR registers external agents through its API.⁠Source 1, Source 8
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

Cloudflare MCP server portals

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedIdentity provider or service token⁠Source 1
  • Registry and governance: OfferedCentrally managed MCP servers⁠Source 1
  • Traffic between agents, tools, and models: OfferedProxy for MCP tool calls⁠Source 1
  • Agents across organizations: Not publicly documented

Workday Agent System of Record

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent System User per agent⁠Source 5
  • Registry and governance: OfferedAgent Registry in Management Hub⁠Source 3
  • Traffic between agents, tools, and models: OfferedAgent Gateway for Workday APIs⁠Source 9
  • Agents across organizations: Not publicly documented

At a glance

TopicCloudflare MCP server portalsWorkday Agent System of Record
What it managesMCP servers and their tools: which ones a portal exposes, and who can use them through it.⁠Source 1AI agents built by Workday, by partners, or by your own teams, each with its status in the Agent Registry.⁠Source 3
Where it runsAt a proxied hostname on a domain you have on Cloudflare, pointing to gateway.agents.cloudflare.com.⁠Source 1Inside Workday: a functional area you enable and configure in each tenant.⁠Source 4
Agent identityAgents connect as MCP clients, with a person’s identity provider login or an Access service token.⁠Source 1, Source 10Each agent gets a unique Workday identity, using Agent System User accounts.⁠Source 5
Pricing modelCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 11 A separate price for portals is not publicly documented.No additional specific SKU for ASOR.⁠Source 3 Workday-built agents in production need a Flex Credits policy opt-in; credits depend on each agent’s skills.⁠Source 3, Source 12 The price of a Flex Credit is not publicly documented.
Generally availableSince 24 September 2026.⁠Source 11Generally available since February 2026.⁠Source 13

What each one is

Cloudflare MCP server portals

Cloudflare says its MCP server portals, part of Cloudflare One, put multiple Model Context Protocol (MCP) servers behind one HTTP endpoint.⁠Source 1, Source 14 Cloudflare Access decides who can connect, by identity provider login or service token, and logs each request made with the portal’s tools.⁠Source 1

Workday Agent System of Record

Workday Agent System of Record (ASOR) is where a Workday customer finds, adds, registers, configures, monitors, and manages its AI agents.⁠Source 3 Each agent gets a unique Workday identity, using Agent System User accounts, and its permissions come from Workday security policies and security groups.⁠Source 5, Source 6

The differences that matter

  1. How access is decided

    Cloudflare MCP server portals

    Access policies set who can connect to the portal; for servers authorized through it, selectors such as groups, country, and device posture are enforced.⁠Source 1

    Workday Agent System of Record

    Workday security groups and policies set what an agent can reach; an Agent Interaction Policy sets which users may use its delegate-mode skills.⁠Source 6, Source 15

    Portal service-token sessions use the admin credential upstream; in ASOR, an agent acting on its own reaches secured items only once its security group is assigned to policies.⁠Source 1, Source 5, Source 16

  2. Agents built elsewhere

    Cloudflare MCP server portals

    MCP clients that support remote MCP servers can connect; autonomous agents can use a service token instead of a browser sign-in.⁠Source 1, Source 10

    Workday Agent System of Record

    External agents are currently registered only through the ASOR API, which records the platform each one runs on.⁠Source 8, Source 17

  3. Logs and analytics

    Cloudflare MCP server portals

    Logs can be viewed per portal or per server, and an API returns daily or monthly tool-call counts.⁠Source 1

    Workday Agent System of Record

    An audit trail report covers agent transactions; per-agent analytics reports cover Workday-built agents only.⁠Source 3, Source 7

    Portal logs can be exported to SIEM tools with Logpush, on Enterprise plans only.⁠Source 1 For ASOR, SIEM export is not publicly documented.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicCloudflare MCP server portalsWorkday Agent System of Record
Network exposurePrivate MCP servers connect out through Cloudflare Tunnel, with Gateway routing on; OAuth authorization endpoints must be public.⁠Source 1, Source 18, Source 19Third-party agents reach Workday APIs through Agent Gateway, a single regional endpoint.⁠Source 9 Whether agents need inbound endpoints: not publicly documented.
IdentitySign-in is by identity provider or service token; independent MFA isn’t enforced for servers authorized through a portal.⁠Source 1A unique Workday identity per agent.⁠Source 5 OAuth 2.0 or signed JWTs; third-party (self-built) agents’ tokens last 4 hours.⁠Source 3, Source 5, Source 20
Access changes and revocationDeleting a service token revokes it.⁠Source 21 Blocked users can reach a server directly; Cloudflare advises making Access its OAuth provider.⁠Source 1Deactivating hides an agent from users; Workday says it can take up to a minute to reach Agent Gateway requests.⁠Source 3, Source 9
Audit trailAccess logs each tool request; Enterprise-plan log exports record the user’s email and the tool called.⁠Source 1, Source 22Delegated actions log the agent as By User and the person as On Behalf Of User.⁠Source 5
ComplianceAccount Super Administrators can get PCI, SOC 2, ISO, and other documents.⁠Source 23 Which ones cover portals is not publicly documented.Workday says its SOC 2 report covers Workday Enterprise Products and ISO 42001 covers Workday Platform; neither names ASOR.⁠Source 24

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Cloudflare MCP server portals and Workday Agent System of Record compared on 18 criteria
Cloudflare MCP server portalsWorkday Agent System of Record
What it is
What it is and who it’s forCloudflare says portals, part of Cloudflare One, secure AI agents’ access to corporate resources.⁠Source 14, Source 25 A portal puts multiple MCP servers behind one endpoint.⁠Source 1Workday’s place to find, register, configure, monitor, and manage AI agents, which Workday describes as an agent analytics hub for IT and business leaders.⁠Source 3, Source 26
MaturityGA since 24 September 2026, after an open beta announced on 26 August 2025.⁠Source 11, Source 27 Once called Agents Gateway in some contexts.⁠Source 1Generally available since February 2026.⁠Source 13 Workday first announced it in February 2025.⁠Source 28
Control
Agent registry and discoveryAdmins add third-party and internal MCP servers to Access, up to 80 per portal.⁠Source 1, Source 2 A registry of agents is not publicly documented.The Agent Registry lists Workday-, partner-, and self-built agents with status.⁠Source 3 Workday says some, such as HiredScore and Evisort agents, aren’t in ASOR.⁠Source 3
Identity and access controlPeople sign in through Access with their identity provider; agents and bots can use a service token.⁠Source 1, Source 10 Policies set who can reach the portal.⁠Source 1Each agent has a unique Workday identity.⁠Source 5 Access rests on Workday security groups; a delegated agent gets only what both it and the user may do.⁠Source 5, Source 6
Ownership, policy, and revocationAdmins choose the tools and prompt templates each portal exposes; turned-off tools can’t be called through it.⁠Source 1 Service tokens can be turned off or deleted.⁠Source 21Admins set each agent’s skills and who can use it; a deactivated agent is hidden from users and can be reactivated.⁠Source 3 Profiles show who built each.⁠Source 8
Audit log and observabilityAccess logs each request made with a portal’s tools, viewable per portal or per server.⁠Source 1 Logpush export to a SIEM needs an Enterprise plan.⁠Source 1An audit trail report covers agent transactions; delegated actions record the agent and the user.⁠Source 5, Source 7 Per-agent analytics cover Workday-built agents only.⁠Source 3
Connection
How agents connectMCP clients connect to the portal’s HTTPS URL.⁠Source 1 Private MCP servers join through outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 19Third-party agents must send Workday API calls through Agent Gateway, a single regional endpoint.⁠Source 9 An external agent’s definition records its hosting URL.⁠Source 17
Agents across organizationsPortals can include third-party MCP servers; ones using OAuth keep their own sign-in.⁠Source 1, Source 2 Another company registering its agents there is not publicly documented.Partner-built agents are supported; a definition can carry an ID locating each in the partner’s system.⁠Source 3, Source 17 Partner-held controls are not publicly documented.
Protocol supportStateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.⁠Source 1 A2A support is not publicly documented.API registration is based on the A2A Agent Card.⁠Source 17 Outside assistants can call the Self-Service Agent over A2A.⁠Source 29 Tool search can filter by SOAP, REST, or MCP.⁠Source 30
Frameworks, models, and clouds supportedMCP clients that support remote MCP servers.⁠Source 1 Upstream servers can use OAuth, a static bearer token, custom headers, or no authentication.⁠Source 1Workday-built, partner-built, and self-built agents.⁠Source 3 Registering Azure AI Foundry and Copilot Studio agents was announced in 2025.⁠Source 31
Operations
Deployment options and data residencyAt a proxied hostname on a domain you have on Cloudflare.⁠Source 1 Self-hosting a portal is not publicly documented.Set up in each Workday tenant.⁠Source 4 Agent Gateway endpoints: US, EU, UK, Canada, Australia, Singapore, India, Japan.⁠Source 9 Self-hosting: not publicly documented.
Compliance attestationsSuper Administrators can get PCI, SOC 2, ISO, and other compliance documents in the dashboard.⁠Source 23 Which ones cover portals is not publicly documented.Workday says its SOC 2 report covers Workday Enterprise Products, and ISO 42001 covers Workday Platform.⁠Source 24 Coverage of ASOR is not publicly documented.
Support and SLASupport varies by Zero Trust plan, with professional services as Contract add-ons.⁠Source 32 Cloudflare states a 100% uptime SLA for paid Zero Trust plans.⁠Source 32Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.⁠Source 33 An ASOR uptime SLA is not publicly documented.
Time and effort to get runningNeeds a domain on Cloudflare and an identity provider on Zero Trust.⁠Source 1 Add MCP servers, create a portal with tools and policies, then connect users.⁠Source 1Enable the ASOR functional area and set its security policies.⁠Source 4 Registering an external agent includes finding the IDs of the Workday APIs it will use.⁠Source 8
Pricing model and public pricesCloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 11 A separate price for portals is not publicly documented.No additional specific SKU for ASOR.⁠Source 3 Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 3 Credit prices aren’t publicly documented.
Building
Agent building toolsWith Cloudflare’s separate Agents SDK, you build and host agents on Cloudflare.⁠Source 34 Remote MCP servers can be built on Cloudflare Workers.⁠Source 2You supply an external agent’s definition through an API.⁠Source 3 Workday says its separate Workday Build opened Developer Agent to early access in June 2026.⁠Source 35, Source 36
Model accessModels included with or required by portals are not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across providers.⁠Source 25Workday’s AI agents use large language models.⁠Source 3 Which models ASOR supports or includes is not publicly documented.
Integrations and ecosystemConnection steps for Claude Desktop, Workers AI Playground, OpenCode, Windsurf, and other MCP clients.⁠Source 1 Portals can be managed with Terraform.⁠Source 1In February 2026, Workday said more than 65 partners were connecting agents to ASOR.⁠Source 13 Workday said partner agents reached Workday Marketplace in June 2025.⁠Source 37

Which to choose

Choose Cloudflare MCP server portals if

  • You want MCP servers, internal or third-party, behind one endpoint, with admins choosing the tools each portal exposes.⁠Source 1, Source 2
  • You use Cloudflare One, which Cloudflare says includes portals, and want Access selectors like groups and device posture enforced on portal servers.⁠Source 1, Source 14
  • Your MCP servers sit on a private network that you can connect through outbound-only Cloudflare Tunnel, with Gateway routing on.⁠Source 1, Source 18, Source 19
  • Your AI assistants are MCP clients such as Claude Desktop or Windsurf, and you want their tool requests logged in one place.⁠Source 1

Choose Workday Agent System of Record if

  • Your agents work with Workday data, and you want each one to have a unique Workday identity under your security groups.⁠Source 3, Source 5, Source 6
  • You want an agent acting for a person held to that person’s permissions and its own skills, with audit naming both.⁠Source 5
  • You want assistants outside Workday, such as Google Gemini Enterprise, to call Workday’s Self-Service Agent over A2A.⁠Source 29
  • You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR itself.⁠Source 3, Source 4

Questions buyers ask

Do Cloudflare MCP server portals and Workday Agent System of Record support MCP and A2A?

Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers.⁠Source 1 Portal A2A support is not publicly documented. ASOR’s API registration uses the A2A Agent Card, outside assistants can call Workday’s Self-Service Agent over A2A, and its tool search includes MCP tools.⁠Source 17, Source 29, Source 30

How are Cloudflare MCP server portals and Workday Agent System of Record priced?

Cloudflare says MCP server portals are available to all Cloudflare customers.⁠Source 11 A separate price for portals is not publicly documented. ASOR needs no additional specific SKU; Workday-built agents in production need a Flex Credits policy opt-in, and non-production testing is free.⁠Source 3, Source 12

Can either one govern agents from other companies?

ASOR supports partner-built agents, whose definitions can carry an ID from the partner’s system.⁠Source 3, Source 17 Partner-held controls are not publicly documented. Portals can include third-party MCP servers, with separate sign-in where OAuth is required.⁠Source 1, Source 2 Another company registering its agents in a portal is not publicly documented.

Does either one build or host agents?

With Cloudflare’s separate Agents SDK, you build and host agents on Cloudflare; portals govern MCP servers.⁠Source 2, Source 34 For ASOR, you supply an external agent’s definition through an API.⁠Source 3 Workday announced the low-code Flowise Agent Builder for its separate Workday Build in 2025.⁠Source 38

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

43 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: MCP server portals · Cloudflare One docs Cloudflare · checked Back:abcdefghijklmnopqrstuvwxyz2728293031323334353637383940414243444546

  2. Source 2: MCP governance · Cloudflare Agents docs Cloudflare · checked Back:abcdefg

  3. Source 3: About Workday Agents (Workday Administrator Guide) Workday · checked Back:abcdefghijklmnopqrstuvwxyz

  4. Source 4: Set Up Agent System of Record (Workday Administrator Guide) Workday · checked Back:abcde

  5. Source 5: Concept: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdefghijklm

  6. Source 6: Setup Considerations: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdef

  7. Source 7: FAQ: Agent Security (Workday Administrator Guide) Workday · checked Back:abc

  8. Source 8: Register External Agents (Workday Administrator Guide) Workday · checked Back:abcd

  9. Source 9: Concept: Workday Agent Gateway (Workday Administrator Guide) Workday · checked Back:abcde

  10. Source 10: Service token support for MCP server portals · Changelog Cloudflare · checked Back:abc

  11. Source 11: MCP server portals are now generally available · Changelog Cloudflare · checked Back:abcde

  12. Source 12: Workday Flex Credits | Workday US Workday · checked Back:ab

  13. Source 13: The Workday Agent System of Record Is Now Generally Available Workday · checked Back:abc

  14. Source 14: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Cloudflare · checked Back:abc

  15. Source 15: Concept: Agent Interaction Policy (Workday Administrator Guide) Workday · checked Back to text

  16. Source 16: Configure Security Policies for Agent Skills (Workday Administrator Guide) Workday · checked Back to text

  17. Source 17: ASOR API Documentation v1.2 (Workday/asor on GitHub) Workday · checked Back:abcdef

  18. Source 18: Private MCP server support for MCP server portals · Changelog Cloudflare · checked Back:ab

  19. Source 19: Cloudflare Tunnel · Cloudflare One docs Cloudflare · checked Back:abc

  20. Source 20: Concept: External Agent ASU Considerations (Workday Administrator Guide) Workday · checked Back to text

  21. Source 21: Service tokens · Cloudflare One docs Cloudflare · checked Back:ab

  22. Source 22: MCP Portal Logs · Cloudflare Logs docs Cloudflare · checked Back to text

  23. Source 23: Compliance documentation · Cloudflare Fundamentals docs Cloudflare · checked Back:ab

  24. Source 24: Workday Compliance | Workday US Workday · checked Back:ab

  25. Source 25: AI Security | Cloudflare Cloudflare · checked Back:ab

  26. Source 26: Workday Agent System of Record | Workday US Workday · checked Back to text

  27. Source 27: MCP server portals · Changelog Cloudflare · checked Back to text

  28. Source 28: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Workday · checked Back to text

  29. Source 29: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Workday · checked Back:abc

  30. Source 30: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Workday · checked Back:ab

  31. Source 31: Workday and Microsoft to Deliver Unified AI Agent Experience for the Enterprise Workday · checked Back to text

  32. Source 32: Cloudflare Access | Zero Trust Network Access (ZTNA) Cloudflare · checked Back:ab

  33. Source 33: Workday Support | Workday US Workday · checked Back to text

  34. Source 34: Build Agents on Cloudflare · Cloudflare Agents docs Cloudflare · checked Back:ab

  35. Source 35: Workday Build | Workday US Workday · checked Back to text

  36. Source 36: Workday Launches New Tools for Developers to Build, Connect, and Verify AI Agents For HR, Finance, and IT Workday · checked Back to text

  37. Source 37: Workday Announces New AI Agent Partner Network and Agent Gateway Workday · checked Back to text

  38. Source 38: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Workday · checked Back to text

  39. Source 39: Your company's private network Blocks.ai · checked Back to text

  40. Source 40: Network requirements Blocks.ai · checked Back to text

  41. Source 41: Solutions: Agent sprawl Blocks.ai · checked Back to text

  42. Source 42: Solutions: Partner networks Blocks.ai · checked Back to text

  43. Source 43: Pricing Blocks.ai · checked Back to text