Cortex AES (Koi) · Discovery
AES Conversation
Starters
Nineteen questions that open the agentic-endpoint conversation — each with what you’ll hear, how to read the answer, the response to give, and where it lands in the Palo Alto portfolio. Built for the ten seconds after the AES demo, when the customer asks: now what?
This is the endpoint-layer deep dive. If the meeting is a broader AI conversation — how the whole portfolio fits together, who is in the room, current evidence you can cite — start at The AI Conversation and come back here for depth. Ask five, not nineteen. Pick by the customer’s maturity, not by list order. The goal of every question is a specific next artifact — an inventory, an owner, or a decision — not a longer list of findings.
Framing
How to Use These
Discovery hands every customer a list of AI agents, MCP servers, browser extensions, and coding assistants they did not know were running. The list is not the product. The plan is.
Say this out loud
“You are going to run this discovery once and get a list of a few hundred things. About ten percent will be genuinely dangerous, thirty percent will be legitimate-but-non-compliant, and the rest is acceptable risk. The hard part is not finding them. The hard part is deciding, defending the decision, and proving it stayed decided next quarter.”
Lead with scale, not fear. The argument is arithmetic — every knowledge worker now installs software that acts on their behalf, and no existing control category owns the inventory. Palo Alto announced its intent to acquire Koi on Feb 17, 2026 to secure “a dangerous, unmanaged attack surface on every endpoint,” and AES now ships as an integral part of the Cortex XDR agent.
The non-negotiable boundary. The customer licenses the platform and holds their own keys. We sell the labour, judgment, automation, and reporting layer on top of that data source — never a resale of platform code or a way to avoid buying the licence. That collapses the margin story and the vendor relationship at the same time.
Sequence
The Six-Move Ladder
What a customer actually does about AI today, in this order. Anyone who starts at move five without doing move one is buying enforcement for a population they cannot describe.
Inventory
Agents, MCP servers, skills, extensions, packages, models — and the human accountable for each.
Published-format AI-BOM, not a spreadsheet that ages out in a month.
Classify
Autonomy tier and blast radius per agent.
Which actions are irreversible, and which currently have no gate.
Scope identity
Identity per agent, least privilege, time bounds, and a revocation owner.
Kill delegated human tokens for agent action — it destroys attribution.
Instrument
Token cost, evaluation scores, execution traces, tool-call reliability — on OpenTelemetry.
Thresholds and owners for each, or the telemetry is decoration.
Enforce
Runtime inspection of prompts and tool calls; version and publisher policy on artifacts.
Approval gates on sensitive and irreversible actions.
Validate & report
Adversarial testing on a cadence with a score that can move, then revalidate.
Report exposure reduced, mapped to a named framework.
Discovery
Nineteen Conversation Starters
Four tracks. Expand any question for what you’ll hear, how to read it, the answer to give, and where it lands in the portfolio.
A · Inventory and visibility
What you’ll hear: "Our CISO’s team could pull that." · "We’d have to ask each business unit." · "Probably a few weeks." · Silence, then a look between two people.
How to read it: Any answer over a few days means there is no inventory, only an assumption. The pause between two attendees is the buying signal — it tells you accountability is unassigned, which is a service problem before it is a product problem.
Your answer: “That is the normal answer, and it is not a criticism — none of the tools you bought were built to own that list. It matters because everything downstream, from access reviews to audit responses, quietly assumes the list exists. We can produce a defensible version in weeks, and more importantly keep it accurate after we leave.”
What you’ll hear: "EDR would catch anything bad." · "We block extension installs by policy." · "Developers have an exception."
How to read it: “EDR would catch it” is the answer to defend against, not argue with. “Developers have an exception” is a gift — the highest-privilege population just told you it has the weakest control.
Your answer: “EDR is genuinely good at malicious. The problem here is mostly not malicious — it is a real package from a real publisher, at a version with a known issue, holding a token that reaches production. That never looks like an attack, so it never fires. It is a software-supply-chain question wearing an endpoint costume.”
What you’ll hear: "Everyone uses Copilot." · "Engineering picks their own tools." · "We standardised on one, officially."
How to read it: “Officially” is the word to listen for. Standardisation on paper plus tool freedom in practice is the exact condition AES discovery is built to expose, and it produces the proof moment in week one.
Your answer: “We are not trying to take tools away from engineers — that fails. We inventory what is actually installed, at what version, from which publisher, with what permissions, then hand you a ranked list. Most of it you keep. A small slice you fix. That is a far easier internal conversation than a ban.”
What you’ll hear: "Joiner-mover-leaver handles that." · "We rotate credentials annually." · "That would be an identity problem."
How to read it: Dormant agents are the cleanest possible finding — no business owner will defend them, so remediation is politically free. If they say “identity problem,” they just named the internal team to recruit as your champion.
Your answer: “Agreed it is an identity problem — that is exactly why Palo Alto acquired CyberArk and rebuilt it as Idira. Prisma AIRS discovery is explicitly designed to find shadow and inactive agents that still hold access. We start there because it is the one category where nobody argues, so you get a fast uncontested win that funds the harder conversations.”
What you’ll hear: "A few pilots." · "Marketing built something in Salesforce." · "That’s the platform team’s problem."
How to read it: “A few pilots” is almost always an order of magnitude low. Citizen-built agents inherit the builder’s permissions, which are routinely broader than any application the security team has ever reviewed.
Your answer: “The pattern we keep seeing is a business user granting an agent their own access because that was the fastest way to make it work. SaaS agent security discovers and monitors agents, copilots, and plugins across more than ten platforms including Copilot Studio, ServiceNow, and Agentforce, and shows which touch sensitive data. The part we operate is the ownership question — every agent needs a named accountable human.”
B · Identity, privilege, and blast radius
What you’ll hear: "A service account." · "It uses the user’s token." · "I’d have to check with the dev team."
How to read it: “The user’s token” means every audit trail attributes agent actions to a human who did not perform them, which breaks incident investigation and, in regulated industries, breaks attestation. A shared service account means no per-agent revocation.
Your answer: “That single design choice determines whether you can ever investigate an agent incident. Idira’s premise is extending privilege controls past a narrow set of admins to every identity — human, machine, and agentic — with zero standing privilege and just-in-time enforcement. What we design is the authorization model underneath: identity per agent, scoped permissions, time bounds, and a revocation path someone owns.”
What you’ll hear: "Probably all of them." · "We scoped them at build time." · "It was easier to give broad access during the pilot."
How to read it: “Easier during the pilot” is the most common and most useful answer — pilot-era permissions almost never get walked back, and those pilots are now in production. This is your privilege-reduction business case, quantified.
Your answer: “Standing privilege is what turns a minor agent misbehaviour into a major incident. The measurable outcome is reducing the count of agents holding permanent broad access, and the report shows that number falling quarter over quarter. That is a metric a board understands without a security briefing.”
What you’ll hear: "Everything’s read-only right now." · "We’re enabling write actions next quarter." · "There’s an approval step in the workflow."
How to read it: “Read-only for now, write next quarter” is the best timing signal you will get. The governance design has to land before that switch flips, which gives your service a deadline the customer set themselves.
Your answer: “Then let’s build the gate before you need it. Cortex AgentiX is designed for exactly this — you define when agents act independently and when they require approval for high-impact actions, operating inside existing roles and permissions with full transparency into the reasoning. We classify which actions are sensitive and set the approval policy; blocklist and policy-changing actions always stay human-approved.”
What you’ll hear: "It’s containerised." · "It only has access to one system." · "We’d have to trace it."
How to read it: “Only one system” is almost always wrong once you follow the token. The value of this question is not the answer — it is watching the room realise nobody owns the answer.
Your answer: “This is why we correlate rather than just inventory. Endpoint artifacts alone tell you an agent exists; joining them to authorised external exposure intelligence tells you which reachable service the agent’s configuration points at, what credential scope it carries, and which host is exposed. That graph turns ‘we have an agent’ into ‘here is the path, ranked.’”
C · Runtime, supply chain, and cost
What you’ll hear: "The firewall sees the traffic." · "We have a system prompt with rules in it." · "The model provider handles safety."
How to read it: All three answers describe controls in the wrong place. A system prompt is guidance, not enforcement, and provider-side safety does not know your data classifications or tool permissions.
Your answer: “Prompt hardening helps, but it is guidance the model may ignore under adversarial pressure. Prisma AIRS provides inline decisioning on agent tool calls — redacting secrets, validating permissions, and blocking or modifying unsafe actions before execution — plus an AI runtime firewall against prompt injection, data leakage, and insecure output. Enforcement has to be a control plane, not an instruction.”
What you’ll hear: "What’s a skill?" · "That goes through the same review." · "Developers install those themselves."
How to read it: If they cannot name the review gate for a skill, there isn’t one. The install path is a file copy, the review step is optional, and the artifact can run code with a developer’s credentials.
Your answer: “A skill is functionally a package with none of the controls you spent twenty years building for packages — no signing requirement, no registry policy, no version pinning. AES treats those artifacts as first-class inventory: publisher, version, permission scope, and behaviour. We operate the policy and the exception register on top.”
What you’ll hear: "We use a commercial API." · "Data science pulls models from a hub." · "We scanned the container."
How to read it: “We scanned the container” is the tell — container scanning does not inspect model internals. If data science pulls from a public hub with no gate, security has never seen that supply chain.
Your answer: “A model file is executable content in practice. Prisma AIRS model security performs deep inspection for architectural backdoors, poisoning, and malicious code inside model components before deployment. Practically, we put a gate in front of the hub so inspection happens once, at intake, instead of never.”
What you’ll hear: "We did a pen test last year." · "The red team looked at it once." · "There was no retest."
How to read it: “No retest” is the whole opportunity. A one-time test is a document; a scored, repeated test is a trend line, and a trend line is what justifies a retainer instead of a project.
Your answer: “Prisma AIRS red teaming runs automated scans against a model, application, or agent using crafted attack prompts and returns a 0–100 risk score. Unit 42 Frontier AI Defense goes further — it validates whether an exposure is actually exploitable and connects weaknesses into attack paths. We own the cadence, triage the findings, drive the fixes, and show the same population scoring better next quarter.”
What you’ll hear: "Finance flagged a spike last month." · "That’s the platform team’s dashboard." · "We cap it at the provider."
How to read it: This is the question that gets a CFO into the room. Cost is the only agent-governance metric that is already someone’s job, so it opens budget doors pure risk framing cannot.
Your answer: “Runaway token spend and a compromised agent look identical from a distance — both are an agent doing far more work than its task requires. Chronosphere supports OpenTelemetry GenAI standards for real-time visibility into input, output, and total token spend by model, plus execution traces and tool-call reliability. We set the thresholds and own the alerts, so the same telemetry serves finance and security from one place.”
What you’ll hear: "Too much." · "We’re mid-renewal on the SIEM." · "Retention is a compliance requirement."
How to read it: “Mid-renewal on the SIEM” is the highest-value sentence on this page. It gives you a funded event, a deadline, and a comparison the customer is already making.
Your answer: “There is a lower-risk first move than replacing your SIEM. The Chronosphere Telemetry Pipeline is a Fluent Bit-based control plane that collects from hundreds of sources, then filters, normalises, enriches, and routes — with a Cortex XSIAM destination plugin shipping today. Security-relevant data lands in XSIAM while high-volume application logs stay queryable where they are. Fund the platform conversation with the savings.”
D · Governance, evidence, and accountability
What you’ll hear: "There’s an AI governance committee." · "It goes through architecture review." · "Six to eight weeks."
How to read it: A six-week approval cycle guarantees shadow adoption — people will not wait, so the committee’s existence actively creates the exposure it was formed to prevent. Sell speed, not control.
Your answer: “Then your governance process is generating the shadow AI you are worried about, because six weeks is longer than the problem the employee is trying to solve. What we operate is a triage and decision SLA measured in days, with a standing allow, deny, and exception register that has expiry dates. Faster decisions reduce shadow adoption more reliably than stricter policy.”
What you’ll hear: "Our AI policy." · "We’d pull screenshots." · "That question is already in vendor questionnaires."
How to read it: “Already in questionnaires” means the requirement is external and revenue-linked, which moves it out of the security budget queue. A policy PDF is an intention; an inventory with decisions and dates is evidence.
Your answer: “We deliver a CycloneDX AI/ML bill of materials plus exposure correlation and human-reviewed findings — a portable evidence object you own, reusable across audits, questionnaires, and board reporting, rather than another dashboard you log into to screenshot.”
What you’ll hear: "We’re still human-in-the-loop everywhere." · "Per program, not per agent." · "It was set during the pilot."
How to read it: Most customers can answer per program, not per agent. That gap is the finding. Autonomy set once during a pilot and never revisited when the agent moved to production is the most common governance failure in the category.
Your answer: “Autonomy is a per-agent setting with a per-agent blast radius, so it needs a per-agent review with a named owner. We classify each agent by autonomy tier and by whether its actions are reversible, then set the approval gate where irreversible meets unsupervised. AgentiX enforces that split without slowing the reversible work down.”
What you’ll hear: "We’d show the number of findings." · "We don’t have a baseline." · "We report incidents, not exposure."
How to read it: Reporting findings found is a growing number that looks like failure. Reporting exposure reduced on the same population is the only version a board rewards. If there is no baseline, the assessment is the baseline — and that is your entry offer.
Your answer: “The deliverable we build toward is a before-and-after on the same population, mapped to a named framework — NIST AI RMF or ISO/IEC 42001, whichever your auditors already speak. Findings found is a project metric. Exposure reduced is the one that renews.”
Compete
Control-Gap Truth Table
Give every incumbent control full credit first. A displacement-first pitch loses the room — walk the table left to right, agree about what already works, and let the last row make the argument for you.
| Existing control | What it genuinely does well | Where it stops | Verdict on AI artifacts |
|---|---|---|---|
| MDM / UEM | Device enrolment, OS posture, patch level, disk encryption, compliance attestation. | Checks the device, not the artifacts running inside a user’s tool chain. An enrolled laptop can host any extension or MCP server. | Blind |
| EDR / XDR | Malicious process behaviour, known threats, lateral movement, host response actions. | Agent-like activity that mimics legitimate user behaviour is not malicious by signature. A legitimate coding agent doing something unwise looks like the user typing. | Partial |
| DLP | Content inspection, sensitive-data patterns, egress blocking on known channels. | Does not enumerate which agent, plugin, or MCP server holds standing credentials and could reach the data legitimately. | Partial |
| CASB / SWG | Sanctioned versus unsanctioned app use, tenant controls, web and SaaS traffic policy. | Sees the destination, not the local artifact that calls it — and a locally installed MCP server may never traverse a proxy at all. | Partial |
| SCA / pipeline scanning | Dependency risk in code the organisation builds, in CI, before release. | Covers the build pipeline, not what a developer installed on the workstation outside it, and not non-developer AI tooling at all. | Partial |
| Endpoint AI artifact oversight | Inventory, publisher reputation, version policy, permission scope, and runtime behaviour for agents, MCP servers, extensions, and packages. | This row is why Cortex AES exists. Nobody else in the customer’s stack owns it today. | The opening |
Discipline
Boundaries to State First
Overclaiming a layer is the fastest way to lose a technical evaluator. Say these before the customer finds them.
Artifact vs. runtime
AES covers endpoint-side agents, extensions, packages, and MCP artifacts. Prompt injection at runtime, excessive agency inside an approved tool, RAG poisoning, token exhaustion, and unsafe output handling belong to Prisma AIRS and application controls.
Not a decryption product
AES observes artifacts, processes, destinations, and behaviour. Encrypted traffic inspection is NGFW and Prisma Access. Prompt, tool-call, and model-response control is AIRS.
No public credit ratio
Public material does not establish a Cortex credit-per-endpoint conversion for AES. Treat it as endpoint-priced standalone or Cortex-attached, and get deal-specific quantities from Palo Alto rather than inventing a ratio.
Do not aim it at CPS / OT / IoMT
The credible wedge is the engineering, clinical, biomedical, developer, and SOC workstations that hold trusted paths into those assets.
The category is not uncontested
CrowdStrike and SentinelOne have both entered agent-security and MCP-adjacent territory. The defensible differentiation is cross-platform coverage, coexistence alongside a third-party EDR rather than displacement, and the continuously maintained findings and reputation corpus.
If the customer is not a Cortex shop
Coexistence beats conversion. Keep the incumbent platform as the orchestration and case-management layer while AES supplies agentic-endpoint context and enforcement. Be honest that the integration path is engineering work — schema mappings, ingestion transport, noise controls, detections — not a connector download.
Go Deeper
Where Each Answer Lands
Sources: Unit 42 Frontier AI Defense with Claude Mythos 5 (Aug 21, 2026) · What’s New in Cortex (July ’26) · Cortex AgentiX · Cortex XSIAM & Chronosphere data control · Chronosphere MCP Server · OWASP GenAI / Agentic security projects · NIST AI RMF 1.0 · CycloneDX AI/ML-BOM. Adapted for PAN Portfolio from the Agentic AI Exposure Management field guide.