Observability — Digital Experience Monitoring
Embrace
User-Focused Observability
The acquisition was announced Jul 21, 2026 and closed Thursday, Aug 27, 2026; deal value was not disclosed. Embrace brings high-fidelity Real User Monitoring for mobile and web, built on OpenTelemetry. Paired with the organically built Synthetics capability, it extends the Palo Alto Networks Observability platform into Digital Experience Monitoring.
Acquisition
The Acquisition — What Actually Closed
Announced Jul 21, 2026. Closed Aug 27, 2026. Value undisclosed. The site's earlier "not yet closed" guidance is retired — you can talk about this as part of the platform now.
Palo Alto Networks announced its intent to acquire Embrace — legally Embrace Mobile, Inc. — on Jul 21, 2026, describing it as a leading provider of user-focused observability. The deal was subject to customary closing conditions and guided to close in fiscal Q1 2027. It closed early, on Thursday, Aug 27, 2026. No purchase price or financial terms were disclosed — and unlike Koi, there is no credible press-reported number to fall back on, so do not offer one.
Two things were announced together, and they are different in kind. Embrace is the acquired Real User Monitoring (RUM) technology for mobile and web. Synthetics is a new capability Palo Alto Networks built organically with the Autonomous Digital Experience Management (ADEM) team, using the company's globally distributed infrastructure to proactively validate application availability and performance from strategic locations worldwide. Together — real users plus synthetic probes — they extend the Observability platform from infrastructure and backend monitoring into Digital Experience Monitoring.
This is the second observability acquisition in eight months, following Chronosphere ($3.35B, closed Jan 29, 2026). The Observability business surpassed $300M ARR in Q3 FY26, and Palo Alto Networks was named a Leader in the Gartner Magic Quadrant for Observability Platforms for the third consecutive year, with the top ranking for Observability Cost Control in the 2026 Gartner Critical Capabilities report (Palo Alto Networks press release).
“To truly understand how their applications are performing, organizations need to see the whole picture — from the moment a user taps or clicks to what exactly happens on the backend. By combining Palo Alto Networks' leading Observability platform with Embrace's innovative Real User Monitoring and the organically developed Synthetic Monitoring capabilities, we'll deliver exactly that. And we're taking it a step further — by linking these capabilities with Cortex AgentiX, organizations will be able to both see and automatically fix issues across their ecosystem. This is what true platformization looks like in practice.”
Lee Klarich — Chief Product & Technology Officer, Palo Alto Networks
Mechanics
How Embrace Works
Auto-instrument the client, capture every session, emit it as OpenTelemetry, and stitch it to the backend trace. That chain is the whole product.
Auto-instrument the client
An SDK drops into the app — iOS, Android, React Native, Unity, Flutter for mobile, and a browser agent for web. Instrumentation is automatic: no hand-written spans required to start collecting crashes, ANRs, network calls and performance metrics.
Capture 100% of sessions
Not sampled. Every mobile user session is recorded as a session timeline — taps, swipes, clicks, view transitions, network requests, custom events and errors, in order, with full technical context to reproduce the issue.
Detect what users feel
Crashes with full user context, ANR detection starting at 1 second, network failures on every API call, JavaScript errors on web, and Core Web Vitals with session context — scored by user and revenue impact rather than raw technical thresholds.
Emit as OpenTelemetry
Telemetry leaves the client in OTel format, not a proprietary wire protocol. Embrace is the only frontend-focused vendor in the CNCF. Customers own the data and can route it where they want.
Stitch to the backend
Network Spans Forwarding connects a client-side network request to the backend trace in one click — into Chronosphere, Grafana, Honeycomb, Elastic or Datadog. The tap and the failing service call land in the same trace.
Alert, dashboard, and query with AI
Impact-based alerting, custom dashboards that mix technical metrics with business KPIs, natural-language filtering in the UI, and an Embrace MCP Server (GA) so agents and LLM workflows can query the data directly.
Capability detail
Background
Company Snapshot
Useful for the "who are these people" question from a technical evaluator. Funding and headcount figures are third-party profile data, not Palo Alto Networks disclosures.
Platform Story
How It Fits the Palo Alto Networks Story
Read the stack top to bottom: the user's finger at the top, infrastructure at the bottom, autonomous action at the end. Embrace is the layer that was missing.
Why Palo Alto Networks is buying observability at all
The strategic logic is the same one behind the Chronosphere deal, extended one layer outward. Security operations and IT operations consume overlapping telemetry, buy from overlapping budgets, and are both being reorganized around AI agents. Owning observability gives Palo Alto Networks the "what is happening" data plane next to its existing "is it safe" data plane — and a second, non-security reason to be in the ITOps buying conversation.
Embrace specifically fixes a gap that was awkward to defend in a competitive evaluation: Chronosphere is excellent from the load balancer inward, but a customer whose complaint is "our app feels slow and we don't know why" was a Datadog or Dynatrace conversation. RUM plus Synthetics closes it, and the DEM framing is what makes the platform comparable to full-suite incumbents rather than a best-of-breed backend tool.
The platformization argument, in one line
Most enterprises pay separately for mobile crash reporting, web performance monitoring, synthetic checks, APM, log analytics and a SIEM — six tools, six contracts, six data silos, and still nobody can trace a customer's abandoned checkout to the service that failed. The Observability platform now covers user experience, proactive validation, backend software and infrastructure in one place, on open standards, with cost control ranked first by Gartner. That is the whole pitch. Fund the move with the consolidation savings, not with a new budget line.
Credibility Check
Shipping vs Roadmap
Say the boundary out loud. The deal closed four days ago as of the start of September — nobody expects a finished merged product, and pretending otherwise is the fastest way to lose a technical evaluator.
Embrace, as Embrace
The product is real, GA, and buyable — Mobile RUM, Web RUM, session timelines, crash and ANR detection, network monitoring, alerting, dashboards, the MCP Server and SpeedCurve's synthetics. It works standalone and integrates with Chronosphere, Grafana, Honeycomb, Elastic and Datadog via OpenTelemetry.
Merged console, packaging and SKUs
Palo Alto Networks has not published a unified Observability + Embrace console experience, a combined SKU structure, migration path for existing Embrace contracts, or a date for either. Treat pricing, bundling and single-pane-of-glass questions as open and route them through your Palo Alto contact.
Cortex AgentiX auto-remediation
The "see it and automatically fix it" story is a stated direction in the announcement, and the deep Chronosphere–AgentiX integration was already flagged as planned rather than GA. The working agent paths today are the read-only Chronosphere MCP Server and the Embrace MCP Server.
No "Cortex Observability"
The umbrella is the Palo Alto Networks Observability platform. Chronosphere retains its brand, Embrace retains its brand, and Synthetics is an ADEM-built capability. Digital Experience Monitoring (DEM) is the category label for RUM plus Synthetics — do not turn it into a product name either.
Competitive Positioning
Compete — What to Know
RUM is a mature market with entrenched incumbents. Embrace wins on mobile depth, open standards and cost — not on breadth of a single suite. Full domain detail on the ITOps & Observability page.
vs. Datadog RUM & Synthetics
Where we win: Mobile depth — 100% session capture rather than sampling, ANR detection from 1 second, and instrumentation built by and for mobile engineers rather than bolted onto an APM suite. OpenTelemetry-native with customer-owned data, against a proprietary agent estate. And the cost argument is the strongest card in the whole deck: Gartner ranked the platform first for Observability Cost Control in 2026, with customers averaging 89% data-volume optimization.
Where to be careful: Datadog ships one console covering RUM, synthetics, APM, logs and security today. Our equivalent single-pane experience is not published yet. If the customer's primary criterion is "one UI this quarter," concede it and fight on cost trajectory and lock-in instead.
vs. Dynatrace / New Relic
Where we win: Both are strong in enterprise APM and weaker in modern mobile-native experience data. Embrace's frontend-first design plus Chronosphere's schema-agnostic Temporal Knowledge Graph handles heavily custom instrumentation that assumes-a-schema tooling struggles with. Consumption-model transparency is also a live grievance in both installed bases.
Where to be careful: Deep mainframe, .NET and legacy Java estates favour Dynatrace's agent maturity. Do not position DEM as a replacement for that footprint — position it as the customer-experience layer on top.
vs. Sentry, Firebase Crashlytics and other crash tools
Where we win: A crash tool tells you the app died. It does not tell you the user rage-tapped a frozen checkout for eight seconds, watched two API calls time out, and abandoned the cart without ever crashing. Full-session context, ANR-class detection and backend trace linkage are the difference, and Crashlytics is free precisely because it stops there.
Where to be careful: "We already have Crashlytics and it's free" is the most common objection. Do not argue features — ask what percentage of their user-reported issues ever produced a crash report. The gap between that number and 100% is the deal.
vs. doing nothing
The most common real competitor. Mobile and web experience quality is usually owned by an engineering team with no observability budget, measured only by app-store reviews and support tickets. The opening is not a product comparison — it is asking who currently owns the answer when a revenue-generating app is slow, and how long it takes them to get it. In many accounts the honest answer is nobody and days.
Buyer Profile
Who Buys It, and When
Note the buying centre shift: this is usually not the CISO. Expect VP Engineering, Head of Mobile, SRE or platform leadership, with digital or e-commerce leadership as the economic sponsor when revenue is tied to the app.
- Revenue runs through a mobile app or transactional website — retail, travel, food delivery, fintech, mobile gaming, ticketing. A bad session is a lost order.
- The customer already has Chronosphere and someone asks "what about the frontend?" — this is the natural expansion motion inside the installed base.
- Engineering is spending days chasing an issue that reproduces only on certain devices, OS versions or networks, with no session-level evidence to work from.
- App-store ratings or support-ticket volume are moving in the wrong direction and nobody can attribute the cause to a release, commit or backend service.
- A Datadog, Dynatrace or New Relic renewal is approaching and the consumption bill has become a board-level line item.
- The team is standardizing on OpenTelemetry and wants to avoid another proprietary agent estate.
- Mobile and backend teams are blaming each other with no shared data — Network Spans Forwarding is the specific fix for that political problem.
- A high-stakes event is coming — Black Friday, a launch, a live sports or ticketing window — and the current answer to "will it hold" is a guess.
Pre-Sales
Scoping Checklist
Collect these before asking for pricing guidance. Packaging under Palo Alto Networks is not published yet, so the sizing conversation runs through your Palo Alto contact.
Customer Conversation
Discovery Questions
Open with experience and revenue, not with telemetry. The person who owns the app cares about users abandoning, not about spans.
When a customer says your app is slow or broken, how do you find out — and how long does it take you to see what they actually experienced?
What percentage of your user-reported issues ever produced a crash report? Everything in the gap is invisible to a crash tool.
Do you measure app freezes and ANRs, or only hard crashes? What threshold are you catching them at?
Are you sampling sessions or capturing all of them? When the incident is intermittent, which sessions did you not keep?
When a mobile issue traces back to a backend service, how do your mobile and platform teams share evidence today?
Can you tie a performance regression to a specific release, commit or app version — and how fast did you do it the last time it mattered?
Who owns the number that connects app performance to conversion or revenue? Does anyone report it to the business?
Have you standardized on OpenTelemetry? How much of your current observability spend is locked into proprietary agents?
What is your observability bill this year versus last, and did anyone forecast that increase?
Do you validate critical user journeys proactively from outside your network, or do you learn about outages from users?
You already run Chronosphere for the backend — who is answering the same questions for the frontend?
When a root cause is identified, who fixes it and how long does the handoff take? That is where the AgentiX direction becomes relevant.
Verify It
Sources
Everything on this page traces to one of these. Funding and headcount figures come from third-party profile data, not company disclosures.
Primary source. Announcement of intent, strategic rationale, Synthetics as organic ADEM work, the Lee Klarich quote, the $300M+ Observability ARR and Gartner positions, and the update confirming the deal closed Thursday, Aug 27, 2026.
Investor-relations copy carrying the close-date update. Use this version when an evaluator wants an IR-hosted source.
Capability detail: 100% session capture, automatic instrumentation, ANR detection from 1 second, session replay and timelines, network monitoring, Web RUM and Core Web Vitals, platform support, and Network Spans Forwarding.
OpenTelemetry and CNCF positioning, the open/composable observability stance, MCP Server GA, natural-language filtering, and customer testimonials.
The SpeedCurve tuck-in: web performance analytics, synthetics, WebPageTest, Core Web Vitals lineage, and named SpeedCurve customers.
Investor list including NEA, Greycroft, AV8 and Eniac, the 100+ organizations figure, and named customers Hyatt, GOAT, Depop, Dave, ChowNow, TextNow, Cameo, Glo and Apprentice.
Third-party profile data: founded 2016, Culver City HQ, ~$79.5M total funding across five rounds, 51–200 employees. Not a company disclosure — attribute it if challenged.
Confirms the legal entity name, Embrace Mobile, Inc., and the fiscal Q1 2027 close guidance the deal beat.