Scale Network Security beyond Human Limits: Introducing Network Security Agents in PAN-OS 12.2

Aug 20, 2026
8 minutes

Built into Strata Cloud Manager, Network Security Agents help teams investigate, plan and execute complex security work—starting with human oversight and progressing toward controlled autonomy.

Every day, administrators must keep users connected, applications available, policies compliant and infrastructure protected across increasingly complex environments. Yet much of their time is consumed by troubleshooting access issues, investigating connectivity failures, collecting logs, validating policy changes, cleaning up configurations and preparing for audits.

The problem is not that administrators are inefficient. It is that the network security operating model has exceeded human scale.

For network security leaders, this is more than a productivity challenge. When skilled professionals spend most of their day on repetitive, context-heavy operational work, less time remains for architecture, modernization, resilience and strategic risk reduction.

To address this head on, our PAN-OS 12.2 Ceres release introduces Network Security Agents in Strata Cloud Manager—AI-powered teammates designed to transform operational intent into governed, trusted action.

When used reactively,Network Security Agents interpret what a user is trying to accomplish, gather relevant context, reason through changing conditions, develop an explainable plan and coordinate the recommended actions to achieve the desired outcome. They do not simply answer questions. They create a governed path from intent to action.

Network Security Agents can also operate proactively—initiating governed action on a schedule, in response to changing conditions or the moment an incident occurs.

Reshaping the network security administrator’s day

A typical network security administrator’s workload spans three areas.

The first is operational overhead: troubleshooting application access, resolving tunnel and device issues, analyzing logs, responding to tickets and diagnosing policy problems.

The second is essential security, policy and compliance work: reviewing rules, validating configurations, investigating misconfigurations, assessing exposure and preparing for audits.

The third is strategic decision-making: strengthening security architecture, advancing Zero Trust and SASE initiatives, improving resilience and aligning security investments with business priorities.

Too often, operational and compliance demands consume the day, leaving too little time for strategic work.

Network Security Agents help shift that balance by addressing work across two dimensions. First, the repetitive and routine—the hundreds of tasks that consume time, create fatigue and keep administrators in reactive mode. Second, the complex and error-prone—the investigations, configuration changes and policy decisions where missing context or a single misstep can introduce risk.

By helping teams execute both types of work more consistently and efficiently, Network Security Agents expand what every person on the team can accomplish while preserving human judgment for the decisions that matter most. The goal is to expand what every person on the team can accomplish.

From a question to an actionable plan

An agentic workflow can begin when an administrator asks a question in natural language, selects an action within Strata Cloud Manager, an incident is detected or a scheduled activity begins.

The Network Security Agent then follows a structured process:

Interpret intent. Gather context. Reason. Build a plan. Obtain approval. Act and verify.

It first determines the intended outcome. It then gathers relevant information across users, applications, policies, logs, devices, incidents and network state. Based on that context, it develops a multi-step plan and explains the evidence, rationale and expected impact behind its recommendation.

Depending on the organization’s controls, a human can review and approve the plan before the agent executes it.

Consider an employee who suddenly loses access to a business-critical application. The issue could originate from identity, endpoint posture, an application policy, a tunnel, routing or device health.

A traditional playbook might run a fixed sequence of checks. The Network Security Agent can instead correlate available signals, adapt the investigation as new evidence emerges, identify the likely root cause and recommend the next best action. After approval, it can coordinate the required steps and verify whether access has been restored.

That is the difference between executing a predefined task and driving an operational outcome.

Crucially, these capabilities are designed to continuously adapt rather than remain static. The Network Security Agents learn through every conversation, observing the complete journey from initial intent to final outcome. With every execution along the way, they actively tune their parameters based on real-world use. This constant refinement means they become progressively more efficient within a given environment. As a result, the more an organization relies on them, the faster and more precise they become at resolving complex challenges.

Specialized expertise across network security

Network security is too broad for a single general-purpose assistant. Network Security Agents therefore bring together specialized expertise across major areas of network and security operations.

A Deployment Agent can help securely onboard users, applications, branches, firewalls, Prisma Access and SD-WAN environments.

A Troubleshooting Agent can investigate connectivity failures, outages, application-access issues, performance degradation and device-health anomalies.

A Configuration Agent can generate, validate and coordinate policy changes while helping confirm proposed configurations are consistent, conflict-free and ready for production.

A Posture and Compliance Agent can identify configuration drift, unused objects, overly permissive policies and opportunities to improve security hygiene and audit readiness.

A Threat Agent can evaluate threat coverage, analyze new intelligence and determine whether emerging threats create exposure within the organization.

A Data Protection Agent can help investigate DLP violations, AI-related data leakage, shadow SaaS usage and data-classification enforcement.

The Network Security Agent serves as the coordination layer across these capabilities. Administrators can begin with the outcome they need, while the agent determines which expertise and actions are required to achieve it.

Automation executes tasks. Agents drive outcomes.

Many organizations already use automation. So what is different about agents?

Traditional automation works well when the trigger, sequence and required actions are known in advance. It can run scripts and execute repeatable workflows quickly and consistently.

But automation typically struggles when conditions change or a problem falls outside predefined logic. A human must then interpret the situation, gather additional context and determine what to do next.

Agents add a reasoning and planning layer above automation. They can understand an objective, evaluate live context, develop a multi-step plan, adapt as conditions change and coordinate existing automations as part of a broader workflow.

Put simply:

Automation follows a path that has already been defined. An agent determines the path required to achieve the outcome. Agents learn from every conversation from the intent to outcomes and with every user interaction. 

Network Security Agents complement existing automation investments rather than replace them. They help determine when and how those automations should be used, moving security operations from isolated task execution toward coordinated, outcome-driven workflows.

A controlled path toward autonomy

The future of network security operations will become increasingly autonomous. But autonomy cannot come at the expense of enterprise control.

Organizations have different risk tolerances and different levels of readiness for AI-driven execution. Network Security Agents are therefore designed to support a deliberate progression from human-in-the-loop operations to controlled autonomy.

Teams can begin with supervised workflows. The agent investigates, reasons and prepares an explainable plan, while a human reviews and approves any changes before execution.

As confidence grows, administrators can allow specific, well-understood activities to operate autonomously within clearly defined boundaries. Read-only investigations, routine health checks or selected low-risk remediations may be appropriate starting points, while sensitive configuration changes continue to require approval.

Over time, organizations can expand autonomous execution based on demonstrated reliability, measurable outcomes and their own risk tolerance.

Governance remains central throughout this progression. When used reactively, Network Security Agents inherit the permissions of the human or role they represent. They cannot perform actions the user is not authorized to perform. Administrators can apply controls at the agent, task and plan levels, require additional approvals for sensitive actions and maintain traceability into decisions and execution.

Beyond role-based permissions, the Network Security Agent comes with precise usage controls to help govern enterprise scale. Administrators can easily configure these precise usage controls by setting specific rate limits across their operational environment. This capability ensures that agents always execute within preset usage limits, preventing resource exhaustion during complex or high-volume workflows. Furthermore, these controls ensure that usage is provided equitably across human users across various teams.

This allows autonomy to be earned—not assumed.

Why Palo Alto Networks

An AI agent is only as effective as the context it understands, the expertise it applies and the actions it can safely coordinate.

Network Security Agents are built into Strata Cloud Manager, where policy, operational telemetry, infrastructure state and enforcement come together. This platform-native context enables agents to reason across the environment rather than operate as disconnected assistants.

Combined with purpose-built network security expertise and governance by design, Network Security Agents provide a practical foundation for agentic operations at enterprise scale.The result is faster issue resolution, more consistent policy management, stronger security posture and more time for teams to focus on architecture, modernization and risk reduction.

The future of network security is not human expertise or AI agents. It is human expertise amplified by agents—working together to deliver outcomes at a scale neither could achieve alone.

Ready to see Network Security Agents in action and accelerate your team's speed-to-action? Reach out to your Palo Alto Networks account team for a comprehensive, deep-dive walkthrough of the Network Security Agents and roadmap.

Explore Network Security Agents with our technical deep dive webinar: Scaling Network Security Operations Beyond Human Limits with Autonomous AI Agents


Subscribe to Network Security Blogs!

Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more.