CyberArk
Also known as: CYBR, CyberArk Software, CyberArk Secure AI Agents Solution, CyberArk Identity Security Platform, Palo Alto Networks Identity Security
Privileged access leader extended to agents: the Secure AI Agents Solution brokers every agent connection so credentials are never held by the agent, with a complete audit trail per action. Acquired by Palo Alto Networks Feb 2026.
CyberArk is the privileged access management leader, and in December 2025 it shipped what it described as the first identity security solution purpose built to protect AI agents with privilege controls. The CyberArk Secure AI Agents Solution extends privileged access management, secrets management and machine identity capabilities to the new class of agent identities, with further releases planned through 2026.
The operating model is a broker. CyberArk sits as the control point between an agent and the systems it wants to reach, handling authentication so credentials are never loose in the agent itself, brokering secure connections to databases and custom applications, and producing a complete audit trail for every action the agent takes. Privileged actions are associated with authenticated identities rather than shared service accounts, which is what makes agent activity attributable after the fact.
In February 2026 Palo Alto Networks closed a roughly 25 billion dollar acquisition of CyberArk, the largest in its history, and established identity security as a core pillar of its platform strategy. CyberArk Identity Security solutions continue to be available as a standalone platform, which is why this record exists in its own right rather than as an alias.
As with other vendors in this pocket, CyberArk governs agents rather than being one. It does not orchestrate agent work, hold agent memory, route models or evaluate agent output, and the grid reflects that. Independent commentary also notes the setup process is heavy for smaller teams, requiring time to register custom servers correctly.
Vendor details
Canonical URL
https://www.cyberark.com
Category
Security / SOC agent
Subcategory
Privileged access management for agent identities
Funding status
Acquired by Palo Alto Networks (NASDAQ: PANW) in a deal that closed 11 February 2026, valued at roughly 25 billion USD and the largest acquisition in Palo Alto Networks history. CyberArk shareholders received 45.00 USD in cash plus 2.2005 PANW shares per share, a reported premium of around 26 percent. Previously listed as NASDAQ: CYBR.
Company status
acquired
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Acts as the control point between agents or bots and the systems they call, brokering authenticated connections to databases and custom applications across hybrid environments. Provides centralised visibility into privileged accounts, machine identities and managed credentials wherever they live. Integration into the wider Palo Alto Networks security ecosystem is underway following the acquisition.
In practice
An agent needs database access, so CyberArk brokers the connection and holds the credential rather than the agent storing it, meaning a compromised agent yields no reusable secret.
A security team reconstructs exactly what an agent did and under whose authority, because every privileged action is tied to an authenticated identity rather than a shared service account.
An enterprise with far more machine identities than human ones brings agent credentials under the same privileged access controls it already applies to administrators.
Sources & related URLs
Research sources
Agentic Index coverage score
7.0 / 14 capabilities · 50%
| Integrations & Tool CallingActs as the main control point between agents and the servers, databases and custom applications they need to reach, brokering secure connections across hybrid environments, with integration into the wider Palo Alto Networks security ecosystem underway following the February 2026 acquisition. CyberArk platform description and Palo Alto acquisition release 2026-08-07 | Full |
|---|---|
| Workflow OrchestrationOperates as an identity broker sitting between agents and the systems they call, orchestrating authentication and connection flows across the identity lifecycle, but it does not orchestrate agent work itself. It governs how agents connect rather than what they do. CyberArk Secure AI Agents announcement and platform description 2026-08-07 | Partial |
| Knowledge Grounding & RAGMaintains centralised visibility into privileged accounts, machine identities and managed credentials across hybrid environments, showing ownership and current activity, but this is an identity and credential inventory rather than a knowledge or retrieval layer for grounding agent reasoning. CyberArk platform analysis 2026-08-07 | Partial |
| Human Oversight & GuardrailsIntelligent privilege controls are applied to every identity including agents, with continuous threat prevention, detection and response across the identity lifecycle, and credentials brokered rather than held by the agent so a compromised agent yields no reusable secret. Privilege boundaries are the guardrail. CyberArk Secure AI Agents announcement 2026-08-07 | Full |
| Security, Identity & GovernancePrivilege security IS the product: privileged access management, secrets management, machine identity, an identity broker handling authentication so credentials are never loose, centralised visibility across hybrid environments, and privileged actions associated with authenticated identities. VERIFICATION FLAG: CyberArk's own corporate attestations were not retrieved in this pass, so confirm the certification list before citing it. CyberArk platform and Secure AI Agents documentation 2026-08-07 | Full |
| Observability & AuditabilityProvides a COMPLETE AUDIT TRAIL FOR EVERY ACTION A BOT TAKES, with privileged actions associated with authenticated identities rather than shared service accounts, plus centralised visibility showing who owns each privileged account and machine identity and what it is currently doing. Attribution after the fact is the core value. CyberArk platform analysis 2026-08-07 | Full |
| Memory & State PersistenceCredential and identity state persists, but that is not agent memory and no conversation or task context store exists. Architecturally expected for a privileged access platform. CyberArk product documentation 2026-08-07 | Unable to verify |
| Deployment & Data ResidencyOperates across hybrid environments spanning cloud and on premise estates, which implies deployment flexibility, but no specific self hosted, VPC or regional residency options were retrieved in this pass. CyberArk platform description 2026-08-07 | Partial |
| Prebuilt Agents, Templates & PacksThe Secure AI Agents Solution is packaged as a named solution rather than assembled from parts, and the platform ships ready made privilege control patterns, but no library of templates, policy packs or prebuilt configurations was documented. Independent commentary notes custom servers must be registered individually, which suggests limited out of the box coverage. CyberArk platform analysis 2026-08-07 | Partial |
| Triggers & Channel CoverageThe platform applies continuous threat prevention, detection and response across the identity lifecycle, which is event driven by nature, but no documented trigger, schedule or channel inventory was retrieved. CyberArk platform description 2026-08-07 | Partial |
| Model Flexibility & RoutingCyberArk does not run, route or select models. It secures the identities and credentials of agents that call them. Honest absence and architecturally expected. CyberArk product documentation 2026-08-07 | Unable to verify |
| APIs, SDKs & MCP ExtensibilityThe identity broker model requires integration with arbitrary databases and custom applications, implying a programmable interface, but no public API reference, SDK family or MCP support was retrieved, and independent commentary describes registering custom servers as a manual setup burden. CyberArk platform analysis 2026-08-07 | Partial |
| Testing, Debugging & OptimizationNo agent evaluation, testing or debugging capability exists or would be expected; CyberArk does not run the agents whose credentials it brokers. Honest absence. CyberArk product documentation 2026-08-07 | Unable to verify |
| Browser & Computer UseCyberArk operates on credentials, authentication and privileged sessions; no browser control, page navigation or computer use capability exists or would be architecturally expected. CyberArk product documentation 2026-08-07 | Unable to verify |
The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Contact sales
per managed identity, agent identity counting not disclosed
Included quota
Not disclosed.
What is public
Nothing on price. The acquisition terms are public because both companies were listed.
Billing mechanics
Not publicly disclosed. Enterprise sales led with channel partners. Following the February 2026 Palo Alto Networks acquisition, CyberArk remains available as a standalone platform, but platform bundling is a likely direction given the stated platformisation strategy.
Cost watchouts
**THE UNIT IS THE RISK, AND IT IS SHARPER HERE THAN FOR OKTA. Machine identities are reported to outnumber human identities by roughly 80 to 1, and agent adoption pushes that ratio further. If agent identities are licensed like privileged human accounts, cost scales with the fastest growing population in the estate.** Independent commentary also flags that setup is heavy for smaller teams and that custom servers must be registered individually, so implementation effort is a real line item rather than a rounding error. Post acquisition, watch for bundling into Palo Alto platform agreements changing the commercial shape.
Variable cost rationale
Nothing commercial is published and the unit of account is unknown, while the population being licensed is the fastest growing one in the enterprise: machine identities already outnumber human identities by an estimated 80 to 1 before agent adoption accelerates. Implementation effort is additionally flagged as heavy by independent commentary. A buyer cannot forecast either the licence or the deployment cost from public sources.
Additional watchouts
Ask explicitly how an agent identity is counted before modelling cost, and ask how the Palo Alto platform agreement interacts with standalone CyberArk licensing now that both are available.
Overage / add-ons
Not retrieved.
Sales call required
Yes, required for paid access
Free / trial
None retrieved
Commercial notes
Formerly NASDAQ: CYBR, now part of Palo Alto Networks (NASDAQ: PANW) following a roughly 25 billion USD acquisition that closed 11 February 2026. Palo Alto states CyberArk solutions continue standalone with no customer disruption and an accelerated roadmap.
Key ambiguities
How an AI agent identity is counted and priced relative to a human privileged account, and whether the Secure AI Agents Solution is a separate SKU or an extension of existing licensing. Neither was retrievable.
Missing data
All pricing, the agent identity unit of account, and whether the Secure AI Agents Solution is separately licensed.
Related vendors
- 7AI — Swarming agentic SOC from the Cybereason founders: sixty plus domain…
- Abnormal AI — Behavioural AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR built around a Virtual Analyst that triages 95% of…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Bionic SOC: a human-AI collaboration platform that automates triage,…
- Anvilogic — Agentic security operations platform that decouples detection from…
Alternatives to CyberArk
The closest documented capability profiles to CyberArk among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Okta7.5 / 14Fuller documented coverage on APIs, SDKs & MCP Extensibility
- Portal267.0 / 14Adds documented Testing, Debugging & Optimization
- Capsule Security7.5 / 14Adds documented Testing, Debugging & Optimization
- Clutch Security6.5 / 14Fuller documented coverage on Triggers & Channel Coverage
- Dropzone AI7.5 / 14Adds documented Memory & State Persistence
- XBOW8.0 / 14Adds documented Memory & State Persistence
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded