Setup
Grant ScopedOps access to a Cloudflare domain
How to invite us to your Cloudflare account or zone so we can manage DNS and related settings safely.
Use this when DNS (or related settings) for your domain live in Cloudflare. The safest pattern is an account or zone invite with limited roles — not sharing your Cloudflare password.
What we need
- Access to the zone (domain) in scope
- Permission to edit DNS records (and SSL/TLS only if we agreed that’s in scope)
Invite us to the account / zone
Panels below are schematics — Cloudflare’s Members UI changes, but the invite flow is the same idea.
1Sign in to Cloudflare
Sign in at Cloudflare with the account that owns the domain/zone we’re working on.
2Open Members
Open Manage Account → Members (or your account’sMembers / Invites screen).
3Invite our email
Invite the email address we provided at Kickoff. Don’t share passwords or Global API keys.
4Pick the smallest useful role
Choose the smallest role that still lets us edit DNS on the specific zone. If Cloudflare asks you to pick domains/zones, select only the domain(s) in this engagement.
5Send and tell us
Send the invite and message us so we can accept and confirm the DNS tab is visible.
If the domain is on a free plan
Invites still work on most plans. If your UI doesn’t show Members, you may be on an older layout — look for Invite under account settings, or ask us and we’ll match the current Cloudflare UI with you on Kickoff.
After we accept
- We’ll confirm we can open the zone and DNS tab
- We’ll document any record changes we make
- You can remove our membership anytime under Members
Don’t do this
- Don’t share the account password or Global API Key in email/chat
- Don’t put the domain in “DNS only” / break proxy settings unless we asked
- Don’t delete the zone or move nameservers mid-engagement without telling us