Control whether Agent Lee appears in the dashboard, choose what it is allowed to read and change, and review the API tokens it holds.
Agent Lee acts on your account using an API token that it creates on your behalf, scoped to the permissions you grant. You decide whether the assistant appears at all, what it can read, and whether it can make changes.
Select Ask AI in the upper-right corner of any dashboard page, or use a keyboard shortcut:
Cmd+/on macOS, orCtrl+/on Windows and Linux.- Press
tthenato toggle the sidebar.
If you do not want to use Agent Lee, you can hide it from the dashboard entirely.
-
In the Cloudflare dashboard, go to Configurations > Preferences for your account.
-
Find the Cloudflare Agent card and turn the setting off.
Turning the setting off hides the Ask AI sidebar and disables the keyboard shortcuts, and the assistant loses its stored copy of your API token, so it can no longer reach your account. The dashboard also attempts to delete the underlying API token for you. To confirm the token is gone — or to remove it yourself — see Review the tokens Agent Lee holds.
Turning the setting back on does not restore access automatically. You are asked to grant permissions again the next time you open the assistant.
Turning Agent Lee off does not delete your conversation history.
When you first grant access, you choose how much of your account the assistant can use. Depending on your account, you may see the following permission templates:
| Template | What it allows |
|---|---|
| Full access | Read your resources, and propose changes. Every write still requires your approval before it executes. |
| Read only | Read and inspect your resources. Agent Lee cannot change anything. |
| Custom | Choose individual permissions yourself. |
Full access does not mean unattended access. Agent Lee shows you exactly what it intends to do and waits for your confirmation before any change is made.
Custom opens a curated list of permissions grouped into categories such as Developer Platform, DNS and Zones, App Security, AI, Cloudflare One, Analytics and Logs, and Account. Each entry has independent read and write toggles, and you choose which accounts the grant applies to.
This list is a subset of everything a Cloudflare API token can express — it covers the products Agent Lee knows how to work with, not the entire API surface.
Some permissions are withheld no matter which template you pick or what you select under Custom. Agent Lee cannot write to:
- Account settings
- Account membership
- Billing
- API tokens
Changing permissions issues a new API token with the updated scope and replaces the one the assistant was using. The previous token is then deleted. Because the new token is created before the old one is removed, both may exist briefly.
Permission changes apply to your next message. Actions the assistant has already completed are not affected, and you do not need to start a new conversation for a change to take effect.
An account administrator can prevent Agent Lee from making changes on your behalf. When this applies to you, the assistant shows a Write off indicator with a lock icon near the message box, and the tooltip reads:
Write access has been disabled for your account by an administrator. You can still read and inspect resources.
In this state Agent Lee can still answer questions, run diagnostics, and inspect your configuration, but it cannot create, update, or delete anything. You cannot lift the restriction yourself — contact your account administrator.
The restriction applies only to the account where it was set. Your permissions on other accounts are unchanged.
Agent Lee's tokens appear alongside your own. To audit or remove them:
-
Go to My Profile > API Tokens in the Cloudflare dashboard.
-
Look for tokens named
Cloudflare Agent Token -followed by a date. -
Delete any token you no longer want. Deleting the token the assistant is currently using revokes its access immediately; you are asked to grant permissions again the next time you open it.
Reviewing this list is the reliable way to confirm that access has been removed after you turn Agent Lee off or narrow its permissions.
Agent Lee is not available in the Cloudflare FedRAMP environment.
Availability is still rolling out, so the assistant and the controls on this page may not appear on every account yet.