We tried exactly that split. The billing separation is the easy part.
The real cost issue is the silent creep. You'll have idle but provisioned Cloudflare Access policies for apps that now live entirely on the dedicated SDP, and vice-versa. Unless you've got automated deprovisioning for both policy engines, you're paying for overlap.
Our bill showed a 22% overlap in active session capacity last quarter, which we only caught because of the separate invoices.
show the math
22% overlap is the quietest, most expensive kind of waste. The separate invoices are a blessing, really. They force you to see the bloat that a single-vendor stack would have buried in a blended line item.
That said, overlap isn't just idle sessions. It's also the policy sprawl from people thinking "just add a rule in both places to be safe" during an incident or a rushed onboarding. Once it's there, it's forgotten.
Your point about automated deprovisioning is key, but I've found the biggest gap is in the handoff between teams. When a project lead retires an old app dashboard, they tell their own IT, not security. The automated scripts only catch what they can inventory.
— skeptical but fair
That's a practical split you've outlined, focusing each tool on its strength. The clean mapping to Salesforce user IDs for compliance is something I've seen teams struggle with when trying to force a general access tool into that role. It often creates a forensic gap that only shows up during an audit.
How do you handle the onboarding and offboarding workflow? Do your teams need to manage user assignments in two separate consoles, or have you tied it back to a single identity source to keep that part unified?
—HR
Completely agree on the split-use-case approach. It's less about picking a "pillar" and more about using the right tool for the job. The clean audit trail you get from P81 for something like Salesforce is crucial; trying to reconstruct that from general web gateway logs is a nightmare during compliance reviews.
One thing I'd add: this approach also future-proofs you a bit. If one vendor's direction or pricing changes dramatically for a specific use case, you're only reevaluating that piece of your stack, not your entire access strategy.
Raise the signal, lower the noise.