Palo Alto Networks combines Cortex security analytics and AgentiX automation, with role-based actions, approval controls and annual licensing.
- 01What it does Combines security telemetry, AI investigation and automated playbooks across the Cortex portfolio.
- 02Best fit Security operations teams consolidating investigations or adding governed agents to an established Cortex environment.
- 03Key constraint An agent’s reasoning is only useful when its licensed tools, permissions and integration data are appropriate.
01 / ProductCortex adds AI reasoning to an established security portfolio
Palo Alto Networks sells network, cloud and security operations products. This blueprint focuses on Cortex XSIAM and Cortex AgentiX, where its AI relevance is concrete: analysing security context, investigating cases and coordinating response. XSIAM provides the security operations environment; AgentiX supplies agents and automation that can operate within Cortex workflows.
AgentiX supports prebuilt and custom agents, natural-language prompts within playbooks, and tools exposed through integrations or the Model Context Protocol. The Agentic Assistant provides an interface to these capabilities across Cortex products. Treat these as related deployment choices within one company’s offer, rather than independent companies or a single universally included feature bundle.
Palo Alto Networks completed its Chronosphere acquisition in January 2026. That announcement described an AgentiX integration as planned, so the acquisition itself should not be treated as proof that every promised observability-to-remediation workflow is available. The proposed workflow here relies on documented Cortex agents and controls. Sequenced has not tested the platform or verified vendor outcome statistics.
02 / AudienceA useful starting point is a repeatable security investigation
The platform is relevant to a security operations centre that handles recurring incidents across several systems. For example, a reported phishing message can lead to checks of sender information, recipient exposure, endpoint activity and identity events. The team needs a coherent case, not merely a fluent explanation of the original email.
Existing Cortex users can evaluate agents against familiar cases and permissions. Teams replacing a security information and event management system face a larger project: data ingestion, detection coverage, analyst procedures and historical access all need migration planning. An agent demonstration does not establish that these foundations are ready or that legacy detections can be retired safely.
Compare the broader enterprise AI and identity environment described in Microsoft’s blueprint when Microsoft systems dominate the operational estate. Compare ServiceNow when the main challenge is routing approved work through service and business processes. The relevant boundary is where security analysis ends and an accountable operational action begins.
03 / WorkflowProposed workflow: investigate a reported message with controlled actions
Start with a representative set of previously reviewed messages in an authorised test environment. Include confirmed phishing, legitimate external communication and uncertain cases. Define what an acceptable case must contain: original message identifiers, recipients, related events, evidence links and an explanation of the recommended next step. This is a proposed evaluation, not an account of hands-on use.
Connect only the data sources needed for that case type and check their freshness. If a connector can read email metadata but cannot retrieve a quarantined attachment, document the difference. A security agent should not be asked to infer the content of a file it has never inspected. Establish a visible path for incomplete investigations to reach an analyst.
Build the playbook around deterministic routing and narrowly scoped reasoning. A rule can select the correct queue and enforce a required case field; an agent can interpret related signals and propose follow-up checks. Make the generated assessment distinguish the event that was observed from the hypothesis it supports. This lets reviewers disagree with the interpretation without losing the underlying record.
The Agentic Assistant security guide says agents can use only assigned actions and operate within the user’s existing permissions. An inactive integration prevents its wrapped commands from working. Configure the pilot with an analyst role and deliberately test an unavailable integration, rather than demonstrating everything with an administrator account whose access hides permission failures.
Require a separate approval for any response that changes access or removes content. The guide states that sensitive actions require explicit approval. Show the specific account, message or endpoint affected before authorisation. Follow a completed action with a state check, because an accepted command and an effective response are different facts.
Review the agent’s plan, retrieved artefacts and audit entry. The documented audit dataset identifies the agent action and invoking user. In the pilot, retain the analyst’s correction alongside the original assessment so recurring errors can be investigated. An evidence trail is most useful when it captures disagreement, not just successful demonstrations.
Measure the number of cases requiring rework, the quality of evidence supplied and the elapsed time to an approved decision. Keep response latency separate from investigation latency. If the final approval waits for an unavailable person, quicker AI reasoning will not resolve the operational delay. Adjust the escalation process before widening the agent’s authority.
04 / PricingAnnual licences include specific user and compute allowances
The current AgentiX licensing guide describes annual per-user licensing and multi-year options. Base includes two users and 400 compute units per year; Enterprise includes four users and 800 compute units per year. Both describe incident history of 180 days, with retention extensions and additional compute available separately. These are licence allowances, not public currency prices.
| Offer | Commercial basis | Important boundary |
|---|---|---|
| AgentiX Base | Annual licence; two included users; 400 compute units/year | Playbook automation and case management; additional users available |
| AgentiX Enterprise | Annual licence; four included users; 800 compute units/year | Adds broader threat intelligence management |
| Development tenant | Separate development tenant licence | Allows multiple stakeholders to develop and test content |
| Retention and capacity | Additional compute and incident-retention options | Confirm the priced allowance and extension terms |
Published entitlements from Cortex AgentiX licensing, consulted 17 September 2026; monetary pricing requires a vendor or partner quote.
Do not convert those compute units into agent investigations without the applicable consumption definition. A unit is a vendor billing measure, and different operations may use it differently. Ask the account team to price the actual case volume and show how consumption appears in the tenant. Include testing and content development in the estimate rather than assuming production is the only environment that costs money.
XSIAM and other Cortex products have their own commercial scope. An AgentiX licence should not be presented as the price of a complete security operations deployment. The quote needs to identify the telemetry platform, endpoints or workloads, data retention, integrations and services required for the proposed workflow. Request equivalent scope when comparing proposals from different vendors.
05 / DistinctionsPermissions and playbooks give AI a defined operating context
AgentiX’s useful distinction is the combination of security-specific workflow tools and constrained agent actions. A security team can keep mandatory process steps explicit while introducing reasoning at particular points. That is more assessable than an open-ended instruction to resolve every incident, especially when the consequence of a mistaken action is a business interruption.
The same approach can preserve analyst knowledge. A well-maintained playbook records which evidence matters and when a specialist must be involved. An agent can help execute or interpret parts of that process, but the organisation still owns the procedure. Success should make that procedure easier to inspect and improve, rather than burying it inside an increasingly elaborate prompt.
06 / QuestionsConfirm regional processing and the real scope of each action
The security documentation describes regional processing boundaries, role-based access and retained audit information. These statements provide questions for an implementation review: which region hosts the actual tenant, what data moves through each integration, and who can view chat and action records? The answer needs to cover the deployment in question rather than the brand’s entire portfolio.
Check the difference between a tool being listed and a tool being operational. Credentials, permission scope and connector state can all change the available evidence. Test a revoked credential and a permission downgrade during the pilot. The desired behaviour is an explicit incomplete step with enough context for recovery, rather than a generated narrative that implies the entire investigation succeeded.
Finally, separate generally available capability from announced integrations. The Chronosphere announcement illustrates why this matters: ownership can change before an integrated workflow ships. Ask for a demonstration of the exact feature in the proposed tenant and a written entitlement. Do not justify a present purchase with a future automation path whose availability remains uncertain.
07 / DecisionEvaluate Cortex against a concrete case and an accountable operator
Palo Alto Networks is worth evaluating when the security team wants a common environment for investigation and controlled response. Start with one case type and compare the complete evidence trail against the existing procedure. Expansion should follow demonstrated coverage, workable approvals and understood licensing, with a named team maintaining both the agents and the playbooks.
You want agents inside established security operations
Test one investigation using ordinary analyst permissions and compare the resulting evidence package.
You are replacing several security tools
Validate ingestion, detections and historical access before making automation the deciding factor.
You mainly need to route approved tasks
Compare general workflow platforms and retain the security system as the evidence authority.
A business worth understanding.
Suggest your business or one you find interesting. Tell us what you want to understand about its product, positioning, design or workflows.
Suggestions are free. Selection and publication stay with the desk.
- Cortex AgentiXConsulted
- Cortex XSIAMConsulted
- Cortex AgentiX licensingConsulted
- Agentic Assistant securityConsulted
- Chronosphere acquisitionConsulted


