Palo Alto Networks Unveils ‘Idara’ Following CyberArk Integration — Identity Management Extends to AI Agents
Palo Alto Networks’ Idara announcement highlights how identity management is expanding beyond human users and traditional privileged accounts. Following the CyberArk integration, the strategic direction is clear: AI agents increasingly need identities, permissions and controls that resemble privileged access management, but operate at machine speed.
AI agents can create tickets, change cloud configurations, query sensitive data and call other systems. Their access is often assembled from tokens, service accounts and delegated permissions, making it difficult to determine who authorised an action and whether the agent still needs the privilege. Conventional PAM controls built around a named administrator and a fixed session do not fully address this model.
Privilege must be tied to action
An agent should not receive broad standing access simply because it may need to complete a future task. A stronger pattern is runtime authorisation: evaluate the requested action, target, data sensitivity and current risk before allowing execution. This extends least privilege from an account-level setting into a decision made for each meaningful operation.
Context needs to follow the agent
Identity security platforms can help correlate the human sponsor, agent identity, tool invocation and target resource. For PAM teams, this creates a chain of accountability that should appear in session management and audit records. Without that chain, an approved human request can become a blind spot once an autonomous system begins making downstream calls.
AI agents need lifecycle governance
Provisioning is only the first step. Security teams need ownership records, expiry dates, approval boundaries, credential rotation and rapid revocation for every agent with privileged capability. Dormant agents and abandoned integrations should be treated like orphaned administrator accounts, with periodic recertification and evidence that access remains justified.
Integration is not the same as control
Connecting identity, endpoint, cloud and security platforms can improve visibility, but buyers should test whether policies are actually enforced at execution time. The practical PAM questions remain familiar: can privilege be minimised, can sessions be monitored, can dangerous actions be stopped, and can investigators reconstruct what happened? Idara’s significance will be measured by how convincingly it answers those questions for autonomous actors.