Network Security Agent
Learn about an AI-powered network security agent that plans, executes, and automates
complex security workflows in Strata Cloud Manager.
| Where Can I Use This? | What Do I Need? |
|
|
- Strata Cloud Manager Pro
- This feature is currently in Beta and available on request.
Contact your account team to enable the feature.
- Superuser role (for agent administration, onboarding, and
managing permissions)
- Network Administrator or Security Administrator role (for agent
interaction)
|
This feature leverages a large language model or generative AI, and may contain
errors. Double-check for accuracy before applying changes.
The Network Security Agent in Strata™ Cloud Manager is an AI-powered entity that
augments your network security team’s expertise and capacity. You use natural
language to interact with the agent, review its proposed execution plans, and authorize
it to carry out multi-step security and networking workflows, including troubleshooting
tunnel outages, remediating threat exposures, and cleaning up unused policy objects.
Unlike traditional rule-based automation, the Network Security Agent generates a Target
Plan of discrete tasks and executes that plan under your supervision. The agent operates
within a hierarchy. The Network Security Agent (root) coordinates specialized Expert
Agents, including Deployment, Troubleshooting, Configuration, Threat, Posture, and Data
Protection. Each Expert Agent is responsible for a functional domain of network security
operations. You can invoke any Expert Agent directly by name, or let the root agent
route your request to the appropriate Expert agent.
There are two primary ways to interact with the Network Security Agent:
- Reactively, by submitting natural language queries or selecting contextual prompts
within Strata Cloud Manager pages.
- Proactively, by enabling pre-built plans that respond automatically to incidents,
scheduled events, or external triggers.
All agent actions respect your existing role-based access control (RBAC). The agent
cannot perform any read or write action that you could not perform independently through
the Strata Cloud Manager interface.
Strata Cloud Manager provides two levels of conversational detail. Basic Conversation
minimizes cognitive overhead by showing high-level plan progress and outcomes. Detailed
conversation view exposes the agent’s reasoning chain, data sources, and granular
tracing information for deep visibility into every step of execution.
Strata Copilot
Strata Copilot is the conversational
interface where you interact with the Network Security Agent using natural language.
You can describe a network issue, ask a security question, or request a
configuration change, and the agent analyzes your query, routes it to the
appropriate Expert Agent, and generates an execution plan. Type
@agent followed by your query, or select a specific Expert
Agent from the
@Agent drop-down to route your request
directly. Strata Copilot supports both Basic and Detailed (Thinking and Tracing)
conversation views.
Agent Hierarchy
The Network Security Agent uses a layered hierarchy to route your requests to the
appropriate domain specialist:
- Planner Agent (Network Security Agent): The top-level orchestrator. It
receives your query, determines intent, and delegates execution to the correct
Expert Agent. You can address the planner agent generically or specify an expert
directly.
- Expert Agents: Six domain specialists that own a functional area of
network security operations. Each Expert Agent has access to domain-specific
tasks, tools, and data sources.
Plans and Triggers
In Strata Cloud Manager, the Network Security Agent organizes its automated
security operations and response workflows into two core building blocks: plans and
triggers. Understanding these components helps you supervise agent activities,
manage execution approvals, and configure proactive automation rules to streamline
your network security operations.
The Network Security Agent organizes work using the following building blocks:
- Plan—A structured sequence of tasks that the agent generates to
achieve a stated objective. Canceled and failed plans do not count toward your
licensed plan usage, and plans in a nonterminal state expire after 30 days. Plan
types and states include:
- Reactive plan—Generated dynamically from a natural language
query.
- Proactive plan—Authored by Palo Alto Networks® or
saved from a previously successful execution.
- Plan states (visible in Action Center)—Progresses through
the following states: Pending, In Progress, Success, Failed, Canceled,
or Expired.
- Trigger—What wakes an agent up to begin planning and/or execution.
Supported triggers include:
- Natural language query—Initiates a reactive plan when you
submit a natural language query through Strata™ Copilot.
- In-Product Click—Initiates a plan from a contextual prompt
on a Strata Cloud Manager page.
- Incident trigger—Initiates an automatic response to a
detected security event.
- Scheduled trigger—Initiates a recurring plan at defined
intervals (such as daily, weekly, or monthly).
- Event trigger—Initiates a plan fired by an internal
API.
Action Center
Action
Center is the centralized day-to-day operational hub where you can
collaboratively monitor and manage all agent plan activity. If you have a Network
Administrator or Security Administrator role, you can track your own plans and any
plans shared with your role-based access control (RBAC) group. With a Superuser
role, you can view and manage all plans across the tenant regardless of who created
them.
Plans in Action Center appear in three states:
| State | What It Means | What You Can Do |
| Pending Input | The plan is paused, waiting for your input. This happens when a
write task requires approval in Supervised mode, or when the agent
needs additional information to continue. | Review the proposed action. Approve or reject individual write
actions or provide clarifications to continue execution. |
| In-Progress | The plan is actively executing. Read tasks are running
automatically; write tasks pause for approval. | Monitor real-time execution progress. Stop the plan immediately
if needed. |
| Completed | The plan reached a terminal state: Success (all tasks completed),
Cancelled (you stopped it), Failed (an unrecoverable error
occurred), or Expired (exceeded the max lifetime for a
plan). | Review the Completion Debrief. Submit follow-up queries. Roll
back write tasks. Download an execution report. Cancelled and failed
plans do not count toward your licensed plan usage. |
You can search and filter plans by keyword, Expert Agent, creator, or time range. You
can also configure plan visibility to control which RBAC groups can view and
interact with a plan.
Proactive Plans
Proactive Plans enable the Network Security Agent to act autonomously in
response to incidents, schedules, or events without requiring you to submit a
query. Only Superusers (Agent Administrators) can enable, disable, and configure
proactive plans.
Unlike reactive queries (where a user types a question and the agent responds),
proactive plans fire automatically when their associated trigger condition occurs.
The agent executes the plan using the Virtual Assistant identity (service account)
you assign, which determines the RBAC scope for the execution.
Control Center
Control Center is the administration hub where Superusers configure
agent behavior, permissions, and governance policies for the entire tenant. Only
Superusers (Agent Administrators) can access Control Center.
If you are a Network Administrator or Security Administrator: the settings your
Superuser configures in Control Center directly affect what agents and tasks are
available to you, which workflows can execute autonomously, and which pre-built
proactive plans are active. If an agent, task, or plan is unavailable to you,
contact your Superuser to review the current permissions configuration.
Control Center contains Agent Permissions where you can enable or disable the
Planner agent and individual Expert Agents or their product capabilities. Set the
permission mode at the Planner, Expert Agent, or product capability level. Use the
Emergency Disable (Red Button) for immediate full shutdown of ALL agents.
Context Library
Context Library lets you save reusable query augmentations called saved
contexts and apply them to any agent conversation with a single click. A saved
context bundles your agent selections, product scope, and uploaded reference files
so you do not re-enter the same inputs every time you start a new query. You can
use saved contexts to streamline daily workflows. With a Superuser role, you can
share contexts across teams by setting public visibility, and edit or delete any
context in the tenant.
A saved context requires a Virtual Identity, which set once at the RBAC scope for
controlled and secure execution to take place. When you apply a context to a
conversation, the agent uses that virtual identity to determine what actions are
permitted during automated execution.
What a saved context contains:
| Field | Description |
| Name and description | A human-readable label and optional description so you and your
team can identify the context quickly. |
| Agent selections | Which Expert Agents to route queries to when this context is
active. You can select one or more agents, or leave the root agent
selected to let it route automatically. |
| Product scope | Which managed products (for example, Prisma Access only, or all
managed NGFWs) the agent considers when generating plans. Narrowing
scope reduces noise in results. |
| Uploaded files | Reference documents or configuration exports the agent uses as
additional context when generating plans. Up to 100 MB per
file. |
| Virtual Identity | The Virtual Assistant identity (Network Admin, Security Admin, or
Superuser) that determines the RBAC scope when this context is used
with proactive or autonomous plan execution. |
| Visibility | Private (only you and Superusers) or Public (selected RBAC groups
can view, apply, and edit). |
Expert Agents
The Network Security Agent coordinates six Expert Agents, each specialized in a
functional domain of network security operations. When you submit a query, the
Planner agent routes your request to the appropriate Expert Agent. You can also
invoke one directly using the alias in Strata Copilot.
| Expert Agent | Alias | What It Does |
| Deployment | @agent/deployment | Automates infrastructure provisioning, device onboarding, and
network service adoption workflows across your managed security
estate. |
| Troubleshooting | @agent/troubleshooting | Diagnoses connectivity failures, device health anomalies, and
performance issues by correlating telemetry, logs, and network data
to identify root causes and generate remediation steps. |
| Configuration | @agent/config | Manages the configuration lifecycle across your security estate,
including change validation, conflict detection, drift tracking, and
rollback verification. |
| Threat | @agent/threat | Assesses threat exposure by correlating global threat
intelligence with your active security configuration, identifies
coverage gaps, and generates targeted remediation. |
| Posture | @agent/posture | Analyzes your security configuration to identify posture gaps,
unused objects, and deviations from best practices, and generates
remediation plans to close compliance gaps. |
| Data Protection | @agent/data | Monitors and enforces data loss prevention policies across your
network security infrastructure, identifying sensitive data exposure
risks and validating DLP enforcement. |
Each Expert Agent operates within the permissions configured in Control Center. If
you disable an Expert Agent in Agent Permissions, the Planner agent cannot route
work to that domain.