Network Security Agent
Focus
Focus
Strata Cloud Manager

Network Security Agent

Table of Contents

Network Security Agent

Learn about an AI-powered network security agent that plans, executes, and automates complex security workflows in Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Strata Cloud Manager Pro
  • This feature is currently in Beta and available on request. Contact your account team to enable the feature.
  • Superuser role (for agent administration, onboarding, and managing permissions)
  • Network Administrator or Security Administrator role (for agent interaction)
This feature leverages a large language model or generative AI, and may contain errors. Double-check for accuracy before applying changes.
The Network Security Agent in Strata™ Cloud Manager is an AI-powered entity that augments your network security team’s expertise and capacity. You use natural language to interact with the agent, review its proposed execution plans, and authorize it to carry out multi-step security and networking workflows, including troubleshooting tunnel outages, remediating threat exposures, and cleaning up unused policy objects.
Unlike traditional rule-based automation, the Network Security Agent generates a Target Plan of discrete tasks and executes that plan under your supervision. The agent operates within a hierarchy. The Network Security Agent (root) coordinates specialized Expert Agents, including Deployment, Troubleshooting, Configuration, Threat, Posture, and Data Protection. Each Expert Agent is responsible for a functional domain of network security operations. You can invoke any Expert Agent directly by name, or let the root agent route your request to the appropriate Expert agent.
There are two primary ways to interact with the Network Security Agent:
  • Reactively, by submitting natural language queries or selecting contextual prompts within Strata Cloud Manager pages.
  • Proactively, by enabling pre-built plans that respond automatically to incidents, scheduled events, or external triggers.
All agent actions respect your existing role-based access control (RBAC). The agent cannot perform any read or write action that you could not perform independently through the Strata Cloud Manager interface.
Strata Cloud Manager provides two levels of conversational detail. Basic Conversation minimizes cognitive overhead by showing high-level plan progress and outcomes. Detailed conversation view exposes the agent’s reasoning chain, data sources, and granular tracing information for deep visibility into every step of execution.

Strata Copilot

Strata Copilot is the conversational interface where you interact with the Network Security Agent using natural language. You can describe a network issue, ask a security question, or request a configuration change, and the agent analyzes your query, routes it to the appropriate Expert Agent, and generates an execution plan. Type @agent followed by your query, or select a specific Expert Agent from the @Agent drop-down to route your request directly. Strata Copilot supports both Basic and Detailed (Thinking and Tracing) conversation views.

Agent Hierarchy

The Network Security Agent uses a layered hierarchy to route your requests to the appropriate domain specialist:
  • Planner Agent (Network Security Agent): The top-level orchestrator. It receives your query, determines intent, and delegates execution to the correct Expert Agent. You can address the planner agent generically or specify an expert directly.
  • Expert Agents: Six domain specialists that own a functional area of network security operations. Each Expert Agent has access to domain-specific tasks, tools, and data sources.

Plans and Triggers

In Strata Cloud Manager, the Network Security Agent organizes its automated security operations and response workflows into two core building blocks: plans and triggers. Understanding these components helps you supervise agent activities, manage execution approvals, and configure proactive automation rules to streamline your network security operations.
The Network Security Agent organizes work using the following building blocks:
  • Plan—A structured sequence of tasks that the agent generates to achieve a stated objective. Canceled and failed plans do not count toward your licensed plan usage, and plans in a nonterminal state expire after 30 days. Plan types and states include:
    • Reactive plan—Generated dynamically from a natural language query.
    • Proactive plan—Authored by Palo Alto Networks® or saved from a previously successful execution.
    • Plan states (visible in Action Center)—Progresses through the following states: Pending, In Progress, Success, Failed, Canceled, or Expired.
  • Trigger—What wakes an agent up to begin planning and/or execution. Supported triggers include:
    • Natural language query—Initiates a reactive plan when you submit a natural language query through Strata™ Copilot.
    • In-Product Click—Initiates a plan from a contextual prompt on a Strata Cloud Manager page.
    • Incident trigger—Initiates an automatic response to a detected security event.
    • Scheduled trigger—Initiates a recurring plan at defined intervals (such as daily, weekly, or monthly).
    • Event trigger—Initiates a plan fired by an internal API.

Action Center

Action Center is the centralized day-to-day operational hub where you can collaboratively monitor and manage all agent plan activity. If you have a Network Administrator or Security Administrator role, you can track your own plans and any plans shared with your role-based access control (RBAC) group. With a Superuser role, you can view and manage all plans across the tenant regardless of who created them.
Plans in Action Center appear in three states:
StateWhat It MeansWhat You Can Do
Pending InputThe plan is paused, waiting for your input. This happens when a write task requires approval in Supervised mode, or when the agent needs additional information to continue.Review the proposed action. Approve or reject individual write actions or provide clarifications to continue execution.
In-ProgressThe plan is actively executing. Read tasks are running automatically; write tasks pause for approval.Monitor real-time execution progress. Stop the plan immediately if needed.
CompletedThe plan reached a terminal state: Success (all tasks completed), Cancelled (you stopped it), Failed (an unrecoverable error occurred), or Expired (exceeded the max lifetime for a plan).Review the Completion Debrief. Submit follow-up queries. Roll back write tasks. Download an execution report. Cancelled and failed plans do not count toward your licensed plan usage.
You can search and filter plans by keyword, Expert Agent, creator, or time range. You can also configure plan visibility to control which RBAC groups can view and interact with a plan.

Proactive Plans

Proactive Plans enable the Network Security Agent to act autonomously in response to incidents, schedules, or events without requiring you to submit a query. Only Superusers (Agent Administrators) can enable, disable, and configure proactive plans.
Unlike reactive queries (where a user types a question and the agent responds), proactive plans fire automatically when their associated trigger condition occurs. The agent executes the plan using the Virtual Assistant identity (service account) you assign, which determines the RBAC scope for the execution.

Control Center

Control Center is the administration hub where Superusers configure agent behavior, permissions, and governance policies for the entire tenant. Only Superusers (Agent Administrators) can access Control Center.
If you are a Network Administrator or Security Administrator: the settings your Superuser configures in Control Center directly affect what agents and tasks are available to you, which workflows can execute autonomously, and which pre-built proactive plans are active. If an agent, task, or plan is unavailable to you, contact your Superuser to review the current permissions configuration.
Control Center contains Agent Permissions where you can enable or disable the Planner agent and individual Expert Agents or their product capabilities. Set the permission mode at the Planner, Expert Agent, or product capability level. Use the Emergency Disable (Red Button) for immediate full shutdown of ALL agents.

Context Library

Context Library lets you save reusable query augmentations called saved contexts and apply them to any agent conversation with a single click. A saved context bundles your agent selections, product scope, and uploaded reference files so you do not re-enter the same inputs every time you start a new query. You can use saved contexts to streamline daily workflows. With a Superuser role, you can share contexts across teams by setting public visibility, and edit or delete any context in the tenant.
A saved context requires a Virtual Identity, which set once at the RBAC scope for controlled and secure execution to take place. When you apply a context to a conversation, the agent uses that virtual identity to determine what actions are permitted during automated execution.
What a saved context contains:
FieldDescription
Name and descriptionA human-readable label and optional description so you and your team can identify the context quickly.
Agent selectionsWhich Expert Agents to route queries to when this context is active. You can select one or more agents, or leave the root agent selected to let it route automatically.
Product scopeWhich managed products (for example, Prisma Access only, or all managed NGFWs) the agent considers when generating plans. Narrowing scope reduces noise in results.
Uploaded filesReference documents or configuration exports the agent uses as additional context when generating plans. Up to 100 MB per file.
Virtual IdentityThe Virtual Assistant identity (Network Admin, Security Admin, or Superuser) that determines the RBAC scope when this context is used with proactive or autonomous plan execution.
VisibilityPrivate (only you and Superusers) or Public (selected RBAC groups can view, apply, and edit).

Expert Agents

The Network Security Agent coordinates six Expert Agents, each specialized in a functional domain of network security operations. When you submit a query, the Planner agent routes your request to the appropriate Expert Agent. You can also invoke one directly using the alias in Strata Copilot.
Expert AgentAliasWhat It Does
Deployment@agent/deploymentAutomates infrastructure provisioning, device onboarding, and network service adoption workflows across your managed security estate.
Troubleshooting@agent/troubleshootingDiagnoses connectivity failures, device health anomalies, and performance issues by correlating telemetry, logs, and network data to identify root causes and generate remediation steps.
Configuration@agent/configManages the configuration lifecycle across your security estate, including change validation, conflict detection, drift tracking, and rollback verification.
Threat@agent/threatAssesses threat exposure by correlating global threat intelligence with your active security configuration, identifies coverage gaps, and generates targeted remediation.
Posture@agent/postureAnalyzes your security configuration to identify posture gaps, unused objects, and deviations from best practices, and generates remediation plans to close compliance gaps.
Data Protection@agent/dataMonitors and enforces data loss prevention policies across your network security infrastructure, identifying sensitive data exposure risks and validating DLP enforcement.
Each Expert Agent operates within the permissions configured in Control Center. If you disable an Expert Agent in Agent Permissions, the Planner agent cannot route work to that domain.