Back to vendors
I

Idira

Also known as: CyberArk Software, CyberArk Secure AI Agents Solution, CyberArk Identity Security Platform, Palo Alto Networks Identity Security, CyberArk

Visit site
Entry priceContact salesFull pricing detail

Identity security platform (now Idira by Palo Alto Networks) extended to AI agents: agent discovery and posture, an AI Agent Gateway and identity broker with just-in-time access, per-tool-call identity audit, admin approval of MCP servers and a kill switch.

CyberArk, now marketed by Palo Alto Networks as Idira, is an identity security platform spanning privileged access management, secrets management and machine identity, extended to AI agents through Secure AI Agents. The product discovers agents across SaaS, cloud and developer environments and enriches each with its owner, purpose, status and permissions.

An AI Agent Gateway and identity broker sit between agents and the MCP servers and systems they use: the broker can hold the MCP server's OAuth application and obtain tokens on the agent's behalf, grants just-in-time access for the duration of a task with zero standing privileges, and records the agent and user identity for every tool call. Security admins review and enable each newly registered MCP server before agents can connect, and an Agent Kill Switch denies access when an agent behaves abnormally. It supports agents on AWS, Azure, Copilot, Claude and custom builds. The platform runs as shared services in a named list of AWS regions, with Secure AI Agents available in US East, Canada and Mumbai, and holds SOC 2 Type II, ISO 27001, ISO 42001 and FedRAMP High among other attestations.

Vendor details

Canonical URL

https://www.paloaltonetworks.com/idira

Category

Security / SOC agent

Subcategory

Privileged access management for agent identities

Funding status

Acquired by Palo Alto Networks (closed 11 February 2026); the identity platform is now marketed as Idira by Palo Alto Networks. Previously listed as NASDAQ: CYBR.

Company status

acquired

Use cases & customers

Primary use cases

privileged access control for AI agents and non human identitiessecrets management so agent credentials are brokered rather than embeddedaudit trails attributing every agent action to an authenticated identitymachine identity lifecycle managementprivileged access management for human administrators

Target customers

large enterpriseregulated industriessecurity and identity teamsorganizations with large machine identity estates

Deployment options

SaaS on the Identity Security Platform Shared Services in named AWS regionsSecure AI Agents in us-east-1, ca-central-1 and ap-south-1

Integrations

The AI Agent Gateway brokers agents' connections to any remote MCP server, managing OAuth tokens on their behalf, for agents built on AWS, Azure, Copilot, Claude and custom stacks, and extends secure access to organizational databases. Discovery covers SaaS, cloud and developer environments, a native Prisma AIRS integration is announced, and an SCA MCP Server is listed on AWS Marketplace. Public APIs are documented at api-docs.cyberark.com.

In practice

An agent needs database access, so CyberArk brokers the connection and holds the credential rather than the agent storing it, meaning a compromised agent yields no reusable secret.

A security team reconstructs exactly what an agent did and under whose authority, because every privileged action is tied to an authenticated identity rather than a shared service account.

An enterprise with far more machine identities than human ones brings agent credentials under the same privileged access controls it already applies to administrators.

Agentic Index coverage score

8.0 / 14 capabilities · 57%

Integrations & Tool Calling Full

An AI Agent Gateway and identity broker sit between agents and any remote MCP server, and they manage that server's OAuth application and tokens on the agents' behalf. Agents built on AWS, Azure or Claude are covered, along with Copilot and custom builds. Discovery scans SaaS, cloud and developer environments, and secure access extends to the organization's databases.

Sourcedocs.cyberark.com/manage/latest/en/content/secureai/architecture.htmread 2026-09-28

Workflow Orchestration Partial

The product runs a fixed identity control pipeline over the customer's agents: it finds them, enriches the record and brokers their access, then revokes access and watches for threats. It does not orchestrate agent work, and it has no agents of its own.

Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28

Knowledge Grounding & RAG Partial

Discovered agents are kept in an inventory, enriched with ownership, purpose and permissions, and MCP servers are listed with their usage and when they last made contact. It is an inventory, not a retrieval layer that grounds agents.

Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28

Human Oversight & Guardrails Partial

Control comes from policy and configuration. Access policies are dynamic, access is granted just in time with no standing privileges, and an Agent Kill Switch denies access when an agent goes rogue. An admin must also enable each newly registered MCP server before agents can connect to it. Nothing asks a person to approve an individual agent action before it commits.

Sourcepaloaltonetworks.com/blog/identity-security/secure-ai-agents-controls-visibility-mcp-data-accessread 2026-09-28

Security, Identity & Governance Full

Attestations on trust.cyberark.com include SOC 2 Type II and SOC 3, ISO/IEC 27001:2022 and 42001:2023, and FedRAMP High, among others. The same page names SSO, MFA and role based access control as controls. These are the company's own certifications, separate from the identity product it sells.

Sourcetrust.cyberark.comread 2026-09-28

Observability & Auditability Full

With OAuth kept in the platform, "agent and user identity are captured for every tool call," and audit trails show which MCP server was reached and which tools were invoked for each interaction through the broker. The customer gets a record of every tool call its agents make.

Sourcedocs.cyberark.com/manage/latest/en/content/secureai/architecture.htmread 2026-09-28

Memory & State Persistence Not documented

The product holds credential and identity state and an inventory of agents, but no memory for the agents themselves is documented.

Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28

Deployment & Data Residency Full

The Identity Security Platform Shared Services run in a named list of AWS regions across the Americas, EMEA and APAC, including a FedRAMP GovCloud region, and the region is chosen per service. Secure AI Agents itself is available in only three: us-east-1, ca-central-1 and ap-south-1.

Sourcedocs.cyberark.com/setup/latest/en/content/ispss-deployment/getstarted/issp-data-centers.htmread 2026-09-28

Prebuilt Agents, Templates & Packs Partial

Two open source modules are published, Agent Watch for monitoring and Agent Guard for secrets provisioning, along with an SCA MCP Server on AWS Marketplace. These are packaged tooling; there are no prebuilt agents, policy templates or packs for agent governance.

Sourcecyberark.com/solutions/secure-agentic-airead 2026-09-28

Triggers & Channel Coverage Full

The identity broker checks each agent request as it arrives and enforces dynamic access policy inline. Permissions are revoked the moment a job completes, and threat detection flags abnormal agent behavior for suspension. All of it runs on events, with no user launching it.

Sourcedocs.cyberark.com/manage/latest/en/content/secureai/architecture.htmread 2026-09-28

Model Flexibility & Routing Not documented

No model is run, routed or selected by the product, which brokers agents' access to tools. It covers agents built on many models without choosing among them.

Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28

APIs, SDKs & MCP Extensibility Full

A public API portal at api-docs.cyberark.com carries the Identity API Reference, including authentication and OAuth 2 token operations. It also documents API token authentication for the Identity Security Platform, with service API URLs, and has REST API pages for Privilege Cloud. Its public pages show endpoints as titles and docs listings rather than full detail.

Sourceapi-docs.cyberark.com/identity-docs-api/docs/identity-apisread 2026-09-28

Testing, Debugging & Optimization Not documented

No testing, red teaming or evaluation of the customer's agents is documented. The product governs what they can access.

Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28

Browser & Computer Use Not documented

The product brokers credentials and tool access for other agents and does no browser or computer use of its own.

Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-09-27·Agent capabilityVerified

Endpoint Privilege Manager is now wired into CORA AI, the assistant on Idira's identity security platform. Admins can ask in plain language about live tenant data, get a summary of endpoint and agent versions, and upgrade selected endpoints to a chosen version straight from the chat.

Bears on: Agent capability

View source
View all 1 change for Idira →Tracked since Sep 2026 · Verified from public vendor sources

Pricing

Contact sales

not disclosed

What is public

Nothing on price.

Billing mechanics

Not publicly disclosed; enterprise sales and partners. The platform is now marketed as Idira by Palo Alto Networks.

Cost watchouts

Inference, not stated by the vendor: if agent identities are licensed like managed identities, cost rises with the number of agents brought under governance.

Variable cost rationale

Inference, not stated by the vendor: the licensing unit for agent identities is not published, so exposure depends on how agents are counted.

Additional watchouts

Ask how an agent identity is counted before modeling cost, and how Idira platform agreements interact with existing CyberArk licensing.

Sales call required

Yes, required for paid access

Free / trial

None retrieved

Commercial notes

Now part of Palo Alto Networks and marketed as Idira.

Key ambiguities

How an AI agent identity is counted and priced, and whether Secure AI Agents is a separate SKU, are not published.

Missing data

All pricing and the agent identity unit of account.

Agentic Index verified 2026-09-28

Alternatives to Idira

The closest documented capability profiles to Idira among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Horizon3.ai8.5 / 14Adds documented Memory & State Persistence
  • Okta8.5 / 14Fuller documented coverage on Human Oversight & Guardrails
  • Operant AI7.5 / 14A lighter documented profile than Idira
  • Qevlar AI8.5 / 14Adds documented Memory & State Persistence
  • HiddenLayer9.0 / 14Adds documented Testing, Debugging & Optimization
  • XBOW9.0 / 14Adds documented Browser & Computer Use

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.