Someone still has to update zone security level. It does not have to be you
It reads every dns record your Cloudflare account holds, drafts the changes that follow, and hands you a card for each one before a single dns record moves.
Open the dns record. Check it against something else. Write the change. Move to the next one. That is the Cloudflare afternoon nobody can hand off, and a companion does the whole pass and gives you back the batch, with nothing landing on a dns record until you approve it.
What it can do is exactly what Cloudflare exposes to an account you authorise and nothing beyond it: 19 operations, 5 reads and 14 writes. In practice that means it can update a zone security level, revoke a certificate and purge a files by URL, and work across the dns records, certificates and files.
The Cloudflare API stops at Cloudflare. A companion does not. The same run opens the customer's website, the supplier portal, the internal tool somebody built in 2019, because it is working the browser you are already signed into rather than calling in from outside it.
Can it patch DNS record on its own?
5 of the 19 operations are reads.
Your account, not a guess at it: a companion can patch DNS record, list DNS records and list certificates, and the full list below is the whole list, with nothing inferred from Cloudflare's documentation.
The dns records are what most of this inventory is about, alongside the certificates. A companion can hold all 19 of these operations and forty open tabs in the same pass, which is how an afternoon of Cloudflare admin becomes a queue you review.
- Patch DNS Record
- List DNS Records
- List Certificates
- Export DNS Records
- Query Worker Analytics
Can it change a dns record without asking?
All 14 write operations wait for you.
A companion can update a zone security level, revoke a certificate and purge a files by URL, and each one is staged on an approval card first: you see the dns record, the field and the new value before it lands in Cloudflare.
Nothing in Cloudflare is sent, changed or deleted on your behalf without that click, and a rejected card leaves the dns record exactly as it was. The gate is the same one on every surface, described at security.
- Update Zone Security Level
- Revoke Certificate
- Purge Files by URL
- Purge All Files
- Import DNS Records
- Delete DNS Record
- Create Zone
- Create Namespace
- Create Key/Value Pairs
- Create IP Access Rule
- Create DNS Record
- Create a Certificate
- Change Development Mode
- Change Zone's SSL Setting
Can it update zone security level on a schedule?
Yes.
Saved as a routine, the Cloudflare dns records pass runs at the hour you pick: the Monday sweep, the overnight refresh, the Friday check. Keep Awake holds the machine awake for the length of a run, so a scheduled pass finishes with the lid closed.
The product and engineering playbook catalogues the other recurring shapes of the infrastructure checks, the Cloudflare dns records sweep among them, and finished runs are published at real runs.
Experience Strawberry for free
DownloadTrusted by fast-growing companies worldwide
Frequently asked questions
Strawberry is free to download and includes AI credits to start. Paid plans begin at $20/month. See pricing. · Reviewed · Canonical facts for AI agents