Setup

Grant ScopedOps access to a Cloudflare domain

How to invite us to your Cloudflare account or zone so we can manage DNS and related settings safely.

Use this when DNS (or related settings) for your domain live in Cloudflare. The safest pattern is an account or zone invite with limited roles — not sharing your Cloudflare password.

What we need

  • Access to the zone (domain) in scope
  • Permission to edit DNS records (and SSL/TLS only if we agreed that’s in scope)

Invite us to the account / zone

Panels below are schematics — Cloudflare’s Members UI changes, but the invite flow is the same idea.

  1. 1Sign in to Cloudflare

    Sign in at Cloudflare with the account that owns the domain/zone we’re working on.

  2. 2Open Members

    Open Manage AccountMembers (or your account’sMembers / Invites screen).

  3. 3Invite our email

    Invite the email address we provided at Kickoff. Don’t share passwords or Global API keys.

  4. 4Pick the smallest useful role

    Choose the smallest role that still lets us edit DNS on the specific zone. If Cloudflare asks you to pick domains/zones, select only the domain(s) in this engagement.

  5. 5Send and tell us

    Send the invite and message us so we can accept and confirm the DNS tab is visible.

If the domain is on a free plan

Invites still work on most plans. If your UI doesn’t show Members, you may be on an older layout — look for Invite under account settings, or ask us and we’ll match the current Cloudflare UI with you on Kickoff.

After we accept

  • We’ll confirm we can open the zone and DNS tab
  • We’ll document any record changes we make
  • You can remove our membership anytime under Members

Don’t do this

  • Don’t share the account password or Global API Key in email/chat
  • Don’t put the domain in “DNS only” / break proxy settings unless we asked
  • Don’t delete the zone or move nameservers mid-engagement without telling us