Idira
Also known as: CyberArk Software, CyberArk Secure AI Agents Solution, CyberArk Identity Security Platform, Palo Alto Networks Identity Security, CyberArk
Identity security platform (now Idira by Palo Alto Networks) extended to AI agents: agent discovery and posture, an AI Agent Gateway and identity broker with just-in-time access, per-tool-call identity audit, admin approval of MCP servers and a kill switch.
CyberArk, now marketed by Palo Alto Networks as Idira, is an identity security platform spanning privileged access management, secrets management and machine identity, extended to AI agents through Secure AI Agents. The product discovers agents across SaaS, cloud and developer environments and enriches each with its owner, purpose, status and permissions.
An AI Agent Gateway and identity broker sit between agents and the MCP servers and systems they use: the broker can hold the MCP server's OAuth application and obtain tokens on the agent's behalf, grants just-in-time access for the duration of a task with zero standing privileges, and records the agent and user identity for every tool call. Security admins review and enable each newly registered MCP server before agents can connect, and an Agent Kill Switch denies access when an agent behaves abnormally. It supports agents on AWS, Azure, Copilot, Claude and custom builds. The platform runs as shared services in a named list of AWS regions, with Secure AI Agents available in US East, Canada and Mumbai, and holds SOC 2 Type II, ISO 27001, ISO 42001 and FedRAMP High among other attestations.
Vendor details
Canonical URL
https://www.paloaltonetworks.com/idira
Category
Security / SOC agent
Subcategory
Privileged access management for agent identities
Funding status
Acquired by Palo Alto Networks (closed 11 February 2026); the identity platform is now marketed as Idira by Palo Alto Networks. Previously listed as NASDAQ: CYBR.
Company status
acquired
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
The AI Agent Gateway brokers agents' connections to any remote MCP server, managing OAuth tokens on their behalf, for agents built on AWS, Azure, Copilot, Claude and custom stacks, and extends secure access to organizational databases. Discovery covers SaaS, cloud and developer environments, a native Prisma AIRS integration is announced, and an SCA MCP Server is listed on AWS Marketplace. Public APIs are documented at api-docs.cyberark.com.
In practice
An agent needs database access, so CyberArk brokers the connection and holds the credential rather than the agent storing it, meaning a compromised agent yields no reusable secret.
A security team reconstructs exactly what an agent did and under whose authority, because every privileged action is tied to an authenticated identity rather than a shared service account.
An enterprise with far more machine identities than human ones brings agent credentials under the same privileged access controls it already applies to administrators.
Sources & related URLs
Research sources
Agentic Index coverage score
8.0 / 14 capabilities · 57%
| Integrations & Tool Calling | Full |
|---|---|
|
An AI Agent Gateway and identity broker sit between agents and any remote MCP server, and they manage that server's OAuth application and tokens on the agents' behalf. Agents built on AWS, Azure or Claude are covered, along with Copilot and custom builds. Discovery scans SaaS, cloud and developer environments, and secure access extends to the organization's databases. Sourcedocs.cyberark.com/manage/latest/en/content/secureai/architecture.htmread 2026-09-28 |
|
| Workflow Orchestration | Partial |
|
The product runs a fixed identity control pipeline over the customer's agents: it finds them, enriches the record and brokers their access, then revokes access and watches for threats. It does not orchestrate agent work, and it has no agents of its own. Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28 |
|
| Knowledge Grounding & RAG | Partial |
|
Discovered agents are kept in an inventory, enriched with ownership, purpose and permissions, and MCP servers are listed with their usage and when they last made contact. It is an inventory, not a retrieval layer that grounds agents. Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28 |
|
| Human Oversight & Guardrails | Partial |
|
Control comes from policy and configuration. Access policies are dynamic, access is granted just in time with no standing privileges, and an Agent Kill Switch denies access when an agent goes rogue. An admin must also enable each newly registered MCP server before agents can connect to it. Nothing asks a person to approve an individual agent action before it commits. Sourcepaloaltonetworks.com/blog/identity-security/secure-ai-agents-controls-visibility-mcp-data-accessread 2026-09-28 |
|
| Security, Identity & Governance | Full |
|
Attestations on trust.cyberark.com include SOC 2 Type II and SOC 3, ISO/IEC 27001:2022 and 42001:2023, and FedRAMP High, among others. The same page names SSO, MFA and role based access control as controls. These are the company's own certifications, separate from the identity product it sells. Sourcetrust.cyberark.comread 2026-09-28 |
|
| Observability & Auditability | Full |
|
With OAuth kept in the platform, "agent and user identity are captured for every tool call," and audit trails show which MCP server was reached and which tools were invoked for each interaction through the broker. The customer gets a record of every tool call its agents make. Sourcedocs.cyberark.com/manage/latest/en/content/secureai/architecture.htmread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
The product holds credential and identity state and an inventory of agents, but no memory for the agents themselves is documented. Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
The Identity Security Platform Shared Services run in a named list of AWS regions across the Americas, EMEA and APAC, including a FedRAMP GovCloud region, and the region is chosen per service. Secure AI Agents itself is available in only three: us-east-1, ca-central-1 and ap-south-1. Sourcedocs.cyberark.com/setup/latest/en/content/ispss-deployment/getstarted/issp-data-centers.htmread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Two open source modules are published, Agent Watch for monitoring and Agent Guard for secrets provisioning, along with an SCA MCP Server on AWS Marketplace. These are packaged tooling; there are no prebuilt agents, policy templates or packs for agent governance. Sourcecyberark.com/solutions/secure-agentic-airead 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
The identity broker checks each agent request as it arrives and enforces dynamic access policy inline. Permissions are revoked the moment a job completes, and threat detection flags abnormal agent behavior for suspension. All of it runs on events, with no user launching it. Sourcedocs.cyberark.com/manage/latest/en/content/secureai/architecture.htmread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
No model is run, routed or selected by the product, which brokers agents' access to tools. It covers agents built on many models without choosing among them. Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
A public API portal at api-docs.cyberark.com carries the Identity API Reference, including authentication and OAuth 2 token operations. It also documents API token authentication for the Identity Security Platform, with service API URLs, and has REST API pages for Privilege Cloud. Its public pages show endpoints as titles and docs listings rather than full detail. Sourceapi-docs.cyberark.com/identity-docs-api/docs/identity-apisread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
No testing, red teaming or evaluation of the customer's agents is documented. The product governs what they can access. Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
The product brokers credentials and tool access for other agents and does no browser or computer use of its own. Sourcepaloaltonetworks.com/idira/agenticread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Endpoint Privilege Manager is now wired into CORA AI, the assistant on Idira's identity security platform. Admins can ask in plain language about live tenant data, get a summary of endpoint and agent versions, and upgrade selected endpoints to a chosen version straight from the chat.
Bears on: Agent capability
View sourcePricing
Contact sales
not disclosed
What is public
Nothing on price.
Billing mechanics
Not publicly disclosed; enterprise sales and partners. The platform is now marketed as Idira by Palo Alto Networks.
Cost watchouts
Inference, not stated by the vendor: if agent identities are licensed like managed identities, cost rises with the number of agents brought under governance.
Variable cost rationale
Inference, not stated by the vendor: the licensing unit for agent identities is not published, so exposure depends on how agents are counted.
Additional watchouts
Ask how an agent identity is counted before modeling cost, and how Idira platform agreements interact with existing CyberArk licensing.
Sales call required
Yes, required for paid access
Free / trial
None retrieved
Commercial notes
Now part of Palo Alto Networks and marketed as Idira.
Key ambiguities
How an AI agent identity is counted and priced, and whether Secure AI Agents is a separate SKU, are not published.
Missing data
All pricing and the agent identity unit of account.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Idira
The closest documented capability profiles to Idira among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Horizon3.ai8.5 / 14Adds documented Memory & State Persistence
- Okta8.5 / 14Fuller documented coverage on Human Oversight & Guardrails
- Operant AI7.5 / 14A lighter documented profile than Idira
- Qevlar AI8.5 / 14Adds documented Memory & State Persistence
- HiddenLayer9.0 / 14Adds documented Testing, Debugging & Optimization
- XBOW9.0 / 14Adds documented Browser & Computer Use
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded