Palo Alto Networks · agentic-soc-platform

Cortex AgentiX

XSOAR-derived agent platform with system and custom agents, actions, and MCP integration.

First observed 2025-10-28 · Last verified 2026-08-27 ·FRESH · ASI-1.0 · ASI-TAXONOMY-1.1

Deterministic executive summary

EARLYUNKNOWNAPPROVAL-GATED

Cortex AgentiX has 1 confirmed capability assertion(s) and 1 confirmed control assertion(s). Evidence maturity is EARLY; autonomy is UNKNOWN; action authority is APPROVAL-GATED. No qualifying independent validation is recorded.

What actually differs?

The documented boundary is APPROVAL-GATED with UNKNOWN operation. This describes authority and initiation, not effectiveness. No qualifying independent validation is recorded.

buyer

Treat missing independent validation as NONE_FOUND, not proof of ineffectiveness.

competitive

Compare documented action authority, trigger model, lifecycle, and evidence breadth; do not compare vendor outcome claims as equivalent measurements.

confidence

EARLY under ASI-1.0; No qualifying independent validation is recorded.

governance

Control evidence covers 1 scoped control assertion(s); verify local policy configuration before enabling write actions.

operational

Plan operating procedures around UNKNOWN initiation and APPROVAL-GATED action authority.

technical

Current evidence establishes 1 scoped capability assertion(s); undocumented capabilities remain UNKNOWN.

Derived under ASI-1.0; last verified 2026-08-27.

Lifecycle

GA · 2026-02-01

Evidence EV-PAN-MULTISTEP

Agents

UNKNOWN — no named agent is established by current evidence.

Autonomy and control

Derived autonomy UNKNOWN

Trigger
UNKNOWN · LOW · UNKNOWN
Persistence
UNKNOWN · LOW · UNKNOWN
Permission scope
SCOPED_WRITE · HIGH · FRESH
Human gate
PRE_ACTION · HIGH · FRESH

Each facet is separately evidence-backed; the A-label is derived.

Sensitive AgentiX actions require manual approval and executed actions are logged.

AFFIRMED

Architecture

UNKNOWN — no architecture assertion is established.

Capabilities

Autonomous investigation

Cortex AgentiX agents can investigate threats and execute multi-step security tasks.

AFFIRMED

Capability evidence

Vendor documentation
HIGH
Public demonstration
NONE_FOUND
Independent validation
NONE_FOUND
Production effectiveness
UNKNOWN

ASI-1.0: Rows represent evidence categories; assertion support confidence is intentionally not rendered beside the capability name.

Assertion support

HIGH under ASI-1.0:Recomputed at publication semantic_as_of with current freshness and unresolved-contradiction state.

Evidence and provenance

VENDOR DOCUMENTATION EV-PAN-MULTISTEP · E1

Cortex Agentic Assistant uses AI agents to investigate threats and execute multi-step security tasks in Cortex XSIAM.
Canonical source →

Evidence conflicts

No human-confirmed conflict is published for this system.

Recent changes

NO_MATERIAL_CHANGE is recorded for this profile.

Unknowns

Any evidence-panel row marked UNKNOWN is not a negative capability claim. Any NONE_FOUND row means the current governed corpus contains no qualifying evidence.

Sources

Compare claims with evidence categories