Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Cloudflare MCP server portals vs Workday Agent System of Record
Cloudflare MCP server portals
Cloudflare One feature that puts MCP servers behind one governed endpoint
Workday Agent System of Record
Workday system of record to find, add, register, configure, monitor, and manage AI agents
Short answer
Cloudflare MCP server portals put multiple MCP servers behind one endpoint, governed by Cloudflare Access.Source 1, Source 2 Workday Agent System of Record (ASOR) lets a company find, register, configure, monitor, and manage AI agents in its Workday tenant, each with a unique Workday identity under Workday security policies.Source 3, Source 4, Source 5, Source 6
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Cloudflare MCP server portals
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
Workday Agent System of Record
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Cloudflare MCP server portals
Cloudflare says its MCP server portals, part of Cloudflare One, put multiple Model Context Protocol (MCP) servers behind one HTTP endpoint.Source 1, Source 14 Cloudflare Access decides who can connect, by identity provider login or service token, and logs each request made with the portal’s tools.Source 1
Workday Agent System of Record
Workday Agent System of Record (ASOR) is where a Workday customer finds, adds, registers, configures, monitors, and manages its AI agents.Source 3 Each agent gets a unique Workday identity, using Agent System User accounts, and its permissions come from Workday security policies and security groups.Source 5, Source 6
The differences that matter
How access is decided
Cloudflare MCP server portalsAccess policies set who can connect to the portal; for servers authorized through it, selectors such as groups, country, and device posture are enforced.Source 1
Workday Agent System of RecordWorkday security groups and policies set what an agent can reach; an Agent Interaction Policy sets which users may use its delegate-mode skills.Source 6, Source 15
Portal service-token sessions use the admin credential upstream; in ASOR, an agent acting on its own reaches secured items only once its security group is assigned to policies.Source 1, Source 5, Source 16
Agents built elsewhere
Logs and analytics
Cloudflare MCP server portalsLogs can be viewed per portal or per server, and an API returns daily or monthly tool-call counts.Source 1
Workday Agent System of RecordAn audit trail report covers agent transactions; per-agent analytics reports cover Workday-built agents only.Source 3, Source 7
Portal logs can be exported to SIEM tools with Logpush, on Enterprise plans only.Source 1 For ASOR, SIEM export is not publicly documented.
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Cloudflare MCP server portals | Workday Agent System of Record | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Cloudflare says portals, part of Cloudflare One, secure AI agents’ access to corporate resources.Source 14, Source 25 A portal puts multiple MCP servers behind one endpoint.Source 1 | Workday’s place to find, register, configure, monitor, and manage AI agents, which Workday describes as an agent analytics hub for IT and business leaders.Source 3, Source 26 |
| Maturity | GA since 24 September 2026, after an open beta announced on 26 August 2025.Source 11, Source 27 Once called Agents Gateway in some contexts.Source 1 | Generally available since February 2026.Source 13 Workday first announced it in February 2025.Source 28 |
| Control | ||
| Agent registry and discovery | Admins add third-party and internal MCP servers to Access, up to 80 per portal.Source 1, Source 2 A registry of agents is not publicly documented. | The Agent Registry lists Workday-, partner-, and self-built agents with status.Source 3 Workday says some, such as HiredScore and Evisort agents, aren’t in ASOR.Source 3 |
| Identity and access control | People sign in through Access with their identity provider; agents and bots can use a service token.Source 1, Source 10 Policies set who can reach the portal.Source 1 | Each agent has a unique Workday identity.Source 5 Access rests on Workday security groups; a delegated agent gets only what both it and the user may do.Source 5, Source 6 |
| Ownership, policy, and revocation | Admins choose the tools and prompt templates each portal exposes; turned-off tools can’t be called through it.Source 1 Service tokens can be turned off or deleted.Source 21 | Admins set each agent’s skills and who can use it; a deactivated agent is hidden from users and can be reactivated.Source 3 Profiles show who built each.Source 8 |
| Audit log and observability | Access logs each request made with a portal’s tools, viewable per portal or per server.Source 1 Logpush export to a SIEM needs an Enterprise plan.Source 1 | An audit trail report covers agent transactions; delegated actions record the agent and the user.Source 5, Source 7 Per-agent analytics cover Workday-built agents only.Source 3 |
| Connection | ||
| How agents connect | MCP clients connect to the portal’s HTTPS URL.Source 1 Private MCP servers join through outbound-only Cloudflare Tunnel, with Gateway routing on.Source 1, Source 19 | Third-party agents must send Workday API calls through Agent Gateway, a single regional endpoint.Source 9 An external agent’s definition records its hosting URL.Source 17 |
| Agents across organizations | Portals can include third-party MCP servers; ones using OAuth keep their own sign-in.Source 1, Source 2 Another company registering its agents there is not publicly documented. | Partner-built agents are supported; a definition can carry an ID locating each in the partner’s system.Source 3, Source 17 Partner-held controls are not publicly documented. |
| Protocol support | Stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers; upstream over Streamable HTTP or SSE.Source 1 A2A support is not publicly documented. | API registration is based on the A2A Agent Card.Source 17 Outside assistants can call the Self-Service Agent over A2A.Source 29 Tool search can filter by SOAP, REST, or MCP.Source 30 |
| Frameworks, models, and clouds supported | MCP clients that support remote MCP servers.Source 1 Upstream servers can use OAuth, a static bearer token, custom headers, or no authentication.Source 1 | Workday-built, partner-built, and self-built agents.Source 3 Registering Azure AI Foundry and Copilot Studio agents was announced in 2025.Source 31 |
| Operations | ||
| Deployment options and data residency | At a proxied hostname on a domain you have on Cloudflare.Source 1 Self-hosting a portal is not publicly documented. | Set up in each Workday tenant.Source 4 Agent Gateway endpoints: US, EU, UK, Canada, Australia, Singapore, India, Japan.Source 9 Self-hosting: not publicly documented. |
| Compliance attestations | Super Administrators can get PCI, SOC 2, ISO, and other compliance documents in the dashboard.Source 23 Which ones cover portals is not publicly documented. | Workday says its SOC 2 report covers Workday Enterprise Products, and ISO 42001 covers Workday Platform.Source 24 Coverage of ASOR is not publicly documented. |
| Support and SLA | Support varies by Zero Trust plan, with professional services as Contract add-ons.Source 32 Cloudflare states a 100% uptime SLA for paid Zero Trust plans.Source 32 | Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.Source 33 An ASOR uptime SLA is not publicly documented. |
| Time and effort to get running | Needs a domain on Cloudflare and an identity provider on Zero Trust.Source 1 Add MCP servers, create a portal with tools and policies, then connect users.Source 1 | Enable the ASOR functional area and set its security policies.Source 4 Registering an external agent includes finding the IDs of the Workday APIs it will use.Source 8 |
| Pricing model and public prices | Cloudflare says MCP server portals are available to all Cloudflare customers.Source 11 A separate price for portals is not publicly documented. | No additional specific SKU for ASOR.Source 3 Workday-built agents in production need a Flex Credits policy opt-in.Source 3 Credit prices aren’t publicly documented. |
| Building | ||
| Agent building tools | With Cloudflare’s separate Agents SDK, you build and host agents on Cloudflare.Source 34 Remote MCP servers can be built on Cloudflare Workers.Source 2 | You supply an external agent’s definition through an API.Source 3 Workday says its separate Workday Build opened Developer Agent to early access in June 2026.Source 35, Source 36 |
| Model access | Models included with or required by portals are not publicly documented. Cloudflare says its separate AI Gateway manages model traffic across providers.Source 25 | Workday’s AI agents use large language models.Source 3 Which models ASOR supports or includes is not publicly documented. |
| Integrations and ecosystem | Connection steps for Claude Desktop, Workers AI Playground, OpenCode, Windsurf, and other MCP clients.Source 1 Portals can be managed with Terraform.Source 1 | In February 2026, Workday said more than 65 partners were connecting agents to ASOR.Source 13 Workday said partner agents reached Workday Marketplace in June 2025.Source 37 |
Which to choose
Choose Cloudflare MCP server portals if
- You want MCP servers, internal or third-party, behind one endpoint, with admins choosing the tools each portal exposes.Source 1, Source 2
- You use Cloudflare One, which Cloudflare says includes portals, and want Access selectors like groups and device posture enforced on portal servers.Source 1, Source 14
- Your MCP servers sit on a private network that you can connect through outbound-only Cloudflare Tunnel, with Gateway routing on.Source 1, Source 18, Source 19
- Your AI assistants are MCP clients such as Claude Desktop or Windsurf, and you want their tool requests logged in one place.Source 1
Choose Workday Agent System of Record if
- Your agents work with Workday data, and you want each one to have a unique Workday identity under your security groups.Source 3, Source 5, Source 6
- You want an agent acting for a person held to that person’s permissions and its own skills, with audit naming both.Source 5
- You want assistants outside Workday, such as Google Gemini Enterprise, to call Workday’s Self-Service Agent over A2A.Source 29
- You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR itself.Source 3, Source 4
Questions buyers ask
Do Cloudflare MCP server portals and Workday Agent System of Record support MCP and A2A?
Portals support stateless MCP 2026-07-28 and earlier 2025 Streamable HTTP clients and servers.Source 1 Portal A2A support is not publicly documented. ASOR’s API registration uses the A2A Agent Card, outside assistants can call Workday’s Self-Service Agent over A2A, and its tool search includes MCP tools.Source 17, Source 29, Source 30
How are Cloudflare MCP server portals and Workday Agent System of Record priced?
Cloudflare says MCP server portals are available to all Cloudflare customers.Source 11 A separate price for portals is not publicly documented. ASOR needs no additional specific SKU; Workday-built agents in production need a Flex Credits policy opt-in, and non-production testing is free.Source 3, Source 12
Can either one govern agents from other companies?
ASOR supports partner-built agents, whose definitions can carry an ID from the partner’s system.Source 3, Source 17 Partner-held controls are not publicly documented. Portals can include third-party MCP servers, with separate sign-in where OAuth is required.Source 1, Source 2 Another company registering its agents in a portal is not publicly documented.
Does either one build or host agents?
With Cloudflare’s separate Agents SDK, you build and host agents on Cloudflare; portals govern MCP servers.Source 2, Source 34 For ASOR, you supply an external agent’s definition through an API.Source 3 Workday announced the low-code Flowise Agent Builder for its separate Workday Build in 2025.Source 38
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
43 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: MCP server portals · Cloudflare One docs Back:abcdefghijklmnopqrstuvwxyz2728293031323334353637383940414243444546
Source 2: MCP governance · Cloudflare Agents docs Back:abcdefg
Source 3: About Workday Agents (Workday Administrator Guide) Back:abcdefghijklmnopqrstuvwxyz
Source 4: Set Up Agent System of Record (Workday Administrator Guide) Back:abcde
Source 5: Concept: Agent Security (Workday Administrator Guide) Back:abcdefghijklm
Source 6: Setup Considerations: Agent Security (Workday Administrator Guide) Back:abcdef
Source 7: FAQ: Agent Security (Workday Administrator Guide) Back:abc
Source 8: Register External Agents (Workday Administrator Guide) Back:abcd
Source 9: Concept: Workday Agent Gateway (Workday Administrator Guide) Back:abcde
Source 10: Service token support for MCP server portals · Changelog Back:abc
Source 11: MCP server portals are now generally available · Changelog Back:abcde
Source 13: The Workday Agent System of Record Is Now Generally Available Back:abc
Source 14: Securing the AI Revolution: Introducing Cloudflare MCP Server Portals Back:abc
Source 15: Concept: Agent Interaction Policy (Workday Administrator Guide) Back to text
Source 16: Configure Security Policies for Agent Skills (Workday Administrator Guide) Back to text
Source 17: ASOR API Documentation v1.2 (Workday/asor on GitHub) Back:abcdef
Source 18: Private MCP server support for MCP server portals · Changelog Back:ab
Source 20: Concept: External Agent ASU Considerations (Workday Administrator Guide) Back to text
Source 22: MCP Portal Logs · Cloudflare Logs docs Back to text
Source 23: Compliance documentation · Cloudflare Fundamentals docs Back:ab
Source 26: Workday Agent System of Record | Workday US Back to text
Source 28: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Back to text
Source 29: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Back:abc
Source 30: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Back:ab
Source 31: Workday and Microsoft to Deliver Unified AI Agent Experience for the Enterprise Back to text
Source 32: Cloudflare Access | Zero Trust Network Access (ZTNA) Back:ab
Source 34: Build Agents on Cloudflare · Cloudflare Agents docs Back:ab
Source 36: Workday Launches New Tools for Developers to Build, Connect, and Verify AI Agents For HR, Finance, and IT Back to text
Source 37: Workday Announces New AI Agent Partner Network and Agent Gateway Back to text
Source 38: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Back to text