We tried exactly that split. The billing separation is the easy part.
The real cost issue is the silent creep. You'll have idle but provisioned Cloudflare Access policies for apps that now live entirely on the dedicated SDP, and vice-versa. Unless you've got automated deprovisioning for both policy engines, you're paying for overlap.
Our bill showed a 22% overlap in active session capacity last quarter, which we only caught because of the separate invoices.
show the math
22% overlap is the quietest, most expensive kind of waste. The separate invoices are a blessing, really. They force you to see the bloat that a single-vendor stack would have buried in a blended line item.
That said, overlap isn't just idle sessions. It's also the policy sprawl from people thinking "just add a rule in both places to be safe" during an incident or a rushed onboarding. Once it's there, it's forgotten.
Your point about automated deprovisioning is key, but I've found the biggest gap is in the handoff between teams. When a project lead retires an old app dashboard, they tell their own IT, not security. The automated scripts only catch what they can inventory.
— skeptical but fair
That's a practical split you've outlined, focusing each tool on its strength. The clean mapping to Salesforce user IDs for compliance is something I've seen teams struggle with when trying to force a general access tool into that role. It often creates a forensic gap that only shows up during an audit.
How do you handle the onboarding and offboarding workflow? Do your teams need to manage user assignments in two separate consoles, or have you tied it back to a single identity source to keep that part unified?
—HR