Illustrative enterprise prototype

What are we working on?

Ask a question, create an output, or build an app that works across your tools and governed enterprise data.

Get started across the organization
Cyber Resilience Dashboard
Build a cyber resilience dashboard across customer-facing applications, APIs, airport and station services, workforce access, and third-party connectivity.
AI
I need scoped access to the enterprise service catalog and summarized security telemetry.
Gatekeeper: Security telemetry + service catalogRequesting read-only access to service ownership, control coverage, policy exceptions, and aggregated security events. Credentials remain isolated and every query is logged.
Approved. Do not expose raw event, passenger, or employee data.
AI
Access is limited to aggregated resilience metadata.
Executed code
const posture = await env.SECURITY_GRAPH.assess({
  domains: ["customer-digital", "api", "station-edge",
    "workforce", "third-party"],
  controls: ["ddos", "waf", "api-security",
    "zero-trust", "dns"]
});
const priorities = posture.findings.filter(f =>
  ["critical", "high"].includes(f.severity)
);
workspace.render(CyberResilience, { posture, priorities });
AI
Cyber Resilience Dashboard is ready with illustrative data. It highlights three architecture decisions without exposing raw telemetry.
Draft a target-state operational resilience architecture for customer digital, airport and station, workforce, cloud, and third-party services.
AI
I will use centrally governed standards from the context library.
Context library: Architecture + operationsLoading read-only architecture principles, resilience standards, service dependencies, data governance, and vendor requirements.
AI
The blueprint needs three explicit decisions:

1. Business-service ownership and measurable resilience objectives
2. Decoupling boundaries between customer journeys and core operational systems
3. Graceful degradation and recovery patterns for critical services
AI
Operational Resilience Reference Architecture v1.0 is ready. The document maps service domains to target patterns, guardrails, and validation evidence.
Build a 90-day AI portfolio roadmap that moves the highest-value use cases into governed pilots and creates a reusable enterprise platform.
AI
I will request read-only portfolio and architecture data.
Gatekeepers: AI intake + model registry + architecture repositoryRead use-case stage, business owner, risk tier, model, evaluation status, and milestone. Exclude prompts, passenger data, and employee content.
Approved for aggregate portfolio planning only.
AI
Executed code
const useCases = await env.AI_PORTFOLIO.list({
  horizon: "90-days", status: ["proposed", "pilot"]
});
const controls = await env.MODEL_REGISTRY.controlStatus();
deck.generate(AIPortfolioRoadmap, {
  useCases, controls, dataMode: "aggregate-only"
});
AI
90-Day AI Portfolio Roadmap is ready. It organizes foundation, pilot, evaluation, and scale gates around five workstreams.
Enterprise Cyber Resilience
Illustrative dataCISO live app
94%
Critical digital services with standard edge controls
4
High-priority resilience decisions
81%
Airport and station policy coverage
30m
Executive incident triage target
Priority architecture findings
Day-of-travel APIs: Two illustrative legacy paths sit outside standard API discovery and schema validation policy.
Third-party support: Four persistent vendor paths do not enforce device posture or time-bound authorization.
Airport and station edge: Nine illustrative locations use direct-origin failover that bypasses centralized inspection.
Control coverage by domain
Southwest.com + mobile96%Protected
Rapid Rewards + identity92%Protected
Corporate workforce88%Managed
Airport + station edge81%In progress
Third-party access73%Review
Legacy origin paths64%Priority
Operational Resilience Reference Architecture v1.0
CIO draft

Enterprise Operational Resilience Reference Architecture

Version 1.0 · Illustrative draft · August 2026 · Owner: Enterprise Technology

1. Purpose

Define a consistent target state for customer digital, airport and station, workforce, cloud, data, and third-party services. The architecture organizes technology around measurable business services and reduces coupling between experience layers and critical operating systems.

2. Design principles

  • Design around customer and employee journeys rather than application boundaries.
  • Use stable service and event contracts to isolate change.
  • Assign explicit ownership and resilience objectives to critical business services.
  • Build observability, graceful degradation, and tested recovery into target patterns.
  • Centralize control evidence while minimizing retained sensitive data.

3. Architecture decisions

Service domainTarget-state decisionRequired guardrailValidation evidence
Customer digitalExperience services decoupled from core operational systemsStable APIs, event contracts, caching, and graceful degradationJourney SLOs and dependency tests
Airport and stationResilient edge services with centrally governed policyOffline-safe patterns, segmented access, and remote observabilityStation recovery exercises
Workforce and crewIdentity-aware access to named applicationsStrong authentication, device posture, and least privilegeAccess and continuity tests
Third-party servicesContract-first integration with bounded failure modesTime-bound access, circuit breakers, and service ownershipSupplier dependency reviews
AI and automationShared model access, evaluation, and tool-control planeService identity, governed data, approval, and auditModel and agent evaluations
Architecture decision: Degraded-mode patterns must preserve operational safety and service continuity without creating permanent bypasses or unmanaged data paths.

4. Validation sequence

Map critical business services, normalize ownership, define target patterns and evidence, validate representative digital and station flows, test failure modes, and use measured outcomes as the gate for scaled modernization.

90-Day Governed AI Portfolio Roadmap
Head of AI deck
Slide 1 of 4

90-Day Governed AI Portfolio Roadmap

From isolated experiments to reusable, trusted enterprise capabilities

Slide 2 of 4

Priority workstreams

WorkstreamAccountable teamStageProgress
Model gateway + observabilityAI PlatformDesign40%
AI use-case governanceAI CouncilPilot60%
Enterprise retrievalData + AIDiscovery30%
Agentic workflow controlsSecurity + AIPilot45%
AI value + FinOpsStrategy + FinanceDesign35%

Illustrative portfolio data for demonstration.

Slide 3 of 4

Decision-gate success measures

100%Production models inventoried
>90%Required evaluation pass rate
100%High-impact actions approved
3Reusable pilot components
Slide 4 of 4

90-day execution path

Days 1-30Baseline. Inventory use cases and models; agree on risk tiers, evaluation, and ownership.
Days 31-60Build. Launch shared model access, approved tools, observability, and the first pilot cohort.
Days 61-90Validate. Measure quality, risk, cost, adoption, and realized value in production-like use.
DecisionScale gate. Productionize winners, retire low-value experiments, and fund shared capabilities.

Context

Illustrative, centrally governed reference material available read-only to authorized agents and workspaces across the organization.

MD

enterprise-strategy-fy2027.md

Company priorities, annual objectives, operating model, and key results by business function.

MD

brand-and-customer-experience.md

Brand voice, customer communications, accessibility standards, and approved experience patterns.

MD

safety-and-regulatory-standards.md

Safety principles, regulatory obligations, operating controls, and evidence requirements.

MD

cybersecurity-and-privacy-controls.md

Enterprise security controls, privacy guardrails, incident standards, and cryptographic policy.

MD

technology-architecture-principles.md

Technology standards, decision criteria, review templates, and reusable reference patterns.

MD

operational-resilience-playbook.md

Business services, continuity objectives, response patterns, and recovery exercises.

MD

service-and-dependency-catalog.md

Illustrative business-service ownership, criticality, dependencies, and support expectations.

MD

data-and-ai-governance.md

Data classification, stewardship, model risk, evaluation, human oversight, and approved AI use.

MD

people-and-workforce-policies.md

Hiring, onboarding, leave, performance, employee support, and compensation guidelines.

MD

finance-and-controls.md

Planning cadence, reporting definitions, approval policy, audit requirements, and internal controls.

Skills

Reusable, governed workflows available across business functions.

NameDescriptionGroupSource
meeting-prepCombine calendar, communications, and approved context into concise briefing material.GeneralEnterprise
weekly-reportCompile cross-tool activity, outcomes, risks, and next steps into a weekly summary.GeneralEnterprise
incident-responseDraft and update response procedures grounded in approved standards and control mappings.SecurityEnterprise
vendor-assessmentGenerate security questionnaires, gather evidence, and summarize third-party risk.SecurityEnterprise
architecture-reviewBuild decision-oriented reviews from project, service catalog, and architecture data.ArchitectureEnterprise
change-impactMap dependencies, affected services, business owners, and implementation risk.ArchitectureEnterprise
disruption-planningModel coordinated actions, dependencies, and customer impacts for operating scenarios.OperationsEnterprise
service-dependency-mapTrace a business service through applications, data, infrastructure, and vendors.OperationsEnterprise
runbook-draftConvert approved procedures and system context into reviewable operating runbooks.OperationsEnterprise
customer-insightsAnalyze approved loyalty and experience trends using aggregated customer measures.CustomerEnterprise
journey-analysisFind friction and improvement opportunities across planning, travel, service, and loyalty.CustomerEnterprise
budget-analysisCompare actuals to plan, explain variances, and forecast period-end outcomes.FinanceEnterprise
job-posting-draftDraft role descriptions using approved competencies, templates, and compensation guidance.HREnterprise
onboarding-guideCreate role-based onboarding plans from policy, team context, and access procedures.HREnterprise
model-risk-reviewApply proportional controls for data, models, outputs, actions, and human oversight.AIEnterprise
agent-designDefine an agent's tools, boundaries, approvals, evaluation, and operating ownership.AIEnterprise

Integrations

Illustrative enterprise connections. Gatekeepers isolate credentials, enforce scoped permissions, and log agent actions.

Enterprise systems
M365

Microsoft 365

Mail, calendar, documents, spreadsheets, presentations, and files.

TM

Microsoft Teams

Messages, channels, meetings, and governed collaboration workflows.

J

Jira

Projects, epics, issues, milestones, and delivery status.

C

Confluence

Enterprise knowledge, project spaces, and approved documentation.

SN

ServiceNow

IT services, HR cases, change requests, service catalog, and facilities.

W

Workday

Employee records, organizational structure, payroll, leave, and benefits.

SAP

SAP

Finance, supply chain, procurement, assets, and planning.

SF

Salesforce

Business relationships, service workflows, and approved customer programs.

GH

GitHub

Repositories, pull requests, issues, releases, and engineering metadata.

DB

Snowflake

Governed enterprise data, analytics, and cross-functional reporting.

SIEM

Security analytics

Alerts, summarized events, control telemetry, and security correlation.

BI

Power BI / Tableau

Dashboards, executive reporting, and governed visualization.

MCP servers
Customer Digital Servicesmcp://customer-digital
Authorized
Operational Data Fabricmcp://operational-data
Needs approval
Airport & Station Systemsmcp://airport-and-station
Needs approval
Employee Directorymcp://employee-directory
Authorized
Cloudflare APIhttps://mcp.cloudflare.com/mcp
Authorized

AI Gateway

Visibility and controls across every AI provider Southwest uses — one console.

Requests
128,400
▲ 11% vs last mo
Tokens
342M
▲ 8% vs last mo
Est. spend
$9,120
76% of budget
Cache-hit
27%
▲ saves ~$2.4k
Error rate
0.6%
▼ 0.2 pts
p50 latency
480 ms
across providers

Models in Use

This month
ModelRouteTokensSpendSharep50 latency
Llama 3.3 70BWorkers AI156M$2,140310 ms
Claudevia AI Gateway98M$3,980720 ms
GPT-4ovia AI Gateway61M$2,510640 ms
Workers AI embeddings (bge)Workers AI27M$19040 ms

Spend vs. Budget

9 days remaining
$9,120spent of $12,000 cap
76%
On track · ~$2,880 left with 9 days
Top Users
Aravind M.42M tok $1,180
Marcus R.31M tok $960
Aisha L.28M tok $840
Dev K.22M tok $610

Usage by Workspace / Team

342M tokens total
AI Platform
121M tokens · $3,240
Enterprise Technology
89M tokens · $2,460
Customer Digital Services
62M tokens · $1,510
Airport & Station Systems
41M tokens · $1,020
Security + AI
29M tokens · $890
Model observability & controls powered by Cloudflare AI Gateway

Governance

Guardrails enforced by Gatekeepers + AI Gateway, so Security + AI teams can operate safely at scale.

Per-team allowed models

Restrict which providers each workspace can call.

Llama 3.3ClaudeGPT-4o+ embeddings

Monthly spend caps

Hard limits per team; agents stop before overrun.

AI Platform $4,000Enterprise Technology $3,000

PII redaction

Strip sensitive fields from prompts before they leave.

Enabled

Prompt / response logging

Full request logs retained for audit & review.

Enabled · 90-day retention

Rate limits

Per-team request ceilings to protect budgets.

600 req / min|burst 1,000

Raise AI Platform cap to $6,000

Change queued by an agent — needs a human sign-off.

Requires approval

AI Gateway Explorer

Explore aggregate model traffic for This month.

4 models
ModelRouteTokensSpendSharep50
Llama 3.3 70BWorkers AI156M$2,14042%310 ms
ClaudeAI Gateway98M$3,98024%720 ms
GPT-4oAI Gateway61M$2,51018%640 ms
Workers AI embeddings (bge)Workers AI27M$19016%40 ms

Review spend cap change

AI Platform · Monthly spend cap

Original cap$4,000
Requested cap$6,000

Change queued by an agent — needs a human sign-off. Approval updates this demo for the current session only.