By NHI Mgmt Group Editorial TeamDomain: AI SecuritySource: Palo Alto NetworksPublished September 1, 2026

TL;DR: Agentic workflows are becoming a category-defining security and governance issue, and Palo Alto Networks says it has acquired Console to extend Cortex across enterprise agentic transformation, while also flagging AI agents as a new class of identity. That shift pushes identity, privilege, and workflow controls closer together than most programmes are ready for.


At a glance

What this is: Palo Alto Networks says it acquired Console to extend Cortex into agentic workflows, framing AI agents as a new class of identity and a governance problem, not just a tooling problem.

Why it matters: IAM, PAM, and security architecture teams need to treat agentic workflows as identity-bearing systems because privilege, delegation, and runtime control are now converging.

By the numbers:

👉 Read Palo Alto Networks' fiscal 2026 results and Console acquisition note


Context

Agentic workflows create a governance gap because systems that can select actions, call tools, and time execution start to behave like identity-bearing entities. That changes the control problem from static application access to runtime delegation, privilege scope, and auditability, which is why AI agent security is increasingly intersecting with IAM and PAM.

Palo Alto Networks' acquisition of Console is best read as a sign that the market is pulling AI workflow security toward platform consolidation. For practitioners, the question is not whether agentic AI exists in the enterprise, but whether current identity controls can explain, approve, and revoke what these workflows do.

The starting position in most organisations is still fragmented, which is typical for emerging control domains. The challenge is that agentic systems do not stay neatly inside model governance or application security, so the identity layer becomes part of the attack surface.


Key questions

Q: What breaks when agentic workflows are not scoped tightly enough?

A: Outputs become inconsistent, users receive different recommendations for the same problem, and the organisation loses confidence in the agent’s reasoning. Broad agents also increase governance risk because it becomes unclear what they are allowed to see or do. Narrow scope is what makes the workflow repeatable, auditable, and safe to operationalise.

Q: Why do delegated credentials increase risk when AI agents and users are not clearly separated?

A: Delegated credentials can blur the boundary between user intent and agent autonomy. If the agent inherits the user’s identity, it may execute actions that are technically authorized but operationally unsafe, such as deleting production resources or exposing sensitive data. Clear identity separation allows additional policy checks, runtime controls, and confirmation steps before high-risk actions proceed.

Q: How should security teams implement task-scoped access for multi-agent systems?

A: Start by mapping each sensitive agent action to a specific resource, approval condition, and expiry rule. Then remove persistent permissions wherever the task can be completed with just-in-time elevation. The goal is to make access disappear when the work is done so the agent cannot reuse it for unrelated actions.

Q: How do organisations know if agentic AI governance is actually working?

A: Look for three signals: access decisions tied to task context, complete audit records linking agents to datasets, and rapid revocation when scope changes. If reviewers still need manual reconstruction after an incident, the programme is not mature. Effective governance produces explainable access, not just allowed or denied results.


Technical breakdown

Agentic workflows and identity boundaries

Agentic workflows differ from ordinary automation because they can decide which tool to call, when to call it, and how to chain actions across systems. That means the runtime needs identity context, authorisation scope, and logging that can explain why one action followed another. Without that, the organisation cannot distinguish a legitimate task from privilege misuse. In practice, the identity boundary shifts from a human user or service account to the workflow itself, which is why agentic AI governance and IAM now overlap.

Practical implication: Map every agentic workflow to a unique identity, a bounded action set, and a revocation path.

Why agentic AI creates a privilege problem

Agentic systems complicate least privilege because they often need temporary access to multiple tools, datasets, and APIs within a single task. Traditional IAM assumes access can be assigned to a stable principal and reviewed later, but agentic behaviour is session-based and context-sensitive. That creates a need for delegated authorisation, short-lived credentials, and policy enforcement at runtime rather than after the fact. PAM and NHI controls become relevant because the agent may operate with effective privilege even when no human is present.

Practical implication: Use runtime policy, task-scoped delegation, and short-lived credentials instead of persistent access grants.

Control-plane consolidation in AI security

The acquisition signals that AI workflow security is moving into broader security platforms rather than remaining a niche capability. That matters because organisations will increasingly evaluate agentic controls alongside cloud, data, and identity tooling instead of as a separate AI-only project. The architectural question becomes whether the platform can enforce identity, policy, and observability across tool use, not just detect model misuse. This is where governance evidence, audit trails, and access boundaries need to meet one another.

Practical implication: Assess whether your current stack can enforce and evidence policy across agent-to-tool interactions.


NHI Mgmt Group analysis

AI agents are becoming identity-bearing systems, not just application features. Once a workflow can choose actions and invoke tools at runtime, it creates an access problem that conventional application security does not fully describe. The governance model has to cover delegation, scope, and revocation as first-class identity concerns. Practitioners should treat agentic AI as part of the identity plane, not an adjacent automation layer.

Agentic AI security is converging with NHI governance. AI agents often rely on credentials, service accounts, tokens, or delegated API access, which places them inside the same control failure modes as other NHIs. That means lifecycle management, secret handling, and privilege boundaries matter even when the workload is

software rather than infrastructure. The practical conclusion is that AI governance and NHI governance now share the same control surface.

Privilege scope, not model capability, will define the next control gap. The hard problem is not whether an agent can reason, but whether it can do too much once connected to enterprise systems. If policy is vague, the workflow inherits the broadest effective access available to it. Organisations should expect the next wave of incidents to come from over-broad delegation rather than from the model alone.

Platform consolidation will force teams to re-evaluate where agent controls live. As agentic security capabilities move into broader security platforms, buyers will need to decide whether they want a point solution, a control layer inside a larger suite, or a model that spans identity, telemetry, and enforcement. That evaluation should focus on evidence of runtime control, not on feature breadth. The field is moving toward operational governance of agents, and practitioners need a control model that survives that shift.

What this signals

Agentic AI will force identity programmes to account for systems that act before a human review cycle can intervene. That means current access review cadences will increasingly look too slow for the decision speed of AI workflows. Teams should expect stronger demand for runtime enforcement, policy evidence, and revocation paths that operate in minutes rather than review windows.

Agent-to-tool delegation will become a standard control question in IAM and PAM roadmaps. The practical issue is not whether an agent uses credentials, but whether those credentials can be explained, bounded, and withdrawn without disrupting the wider platform. Programmes that already manage NHIs should extend those patterns to agentic workloads now, before agent sprawl turns into governance debt.


For practitioners

  • Define a unique identity for every agentic workflow Assign each agent a distinct principal, separate from the human owner and from shared service accounts. Tie that principal to approved tools, data sets, and APIs so you can revoke one workflow without breaking others.
  • Move from static access to task-scoped delegation Replace standing credentials with short-lived, task-scoped authorisation that expires when the workflow completes. Require re-approval only for new tools, new data classes, or expanded privilege scope.
  • Log the full agent-to-tool decision chain Capture which prompt, policy, tool call, token, and downstream action occurred in sequence so investigators can reconstruct why the workflow acted. Without that chain, audit evidence will be too weak for incident review or governance sign-off.
  • Review NHI controls for AI workflow reuse Check whether existing secret rotation, token scope, and offboarding processes apply to agents that can be cloned, retrained, or repurposed across environments. If they do not, treat the workflow as a separate identity lifecycle.

Key takeaways

  • Agentic workflows now create identity and privilege problems that sit directly inside IAM and PAM scope.
  • The most important control question is whether every agent action can be traced back to a bounded delegation decision.
  • Organisations should treat agentic AI as a separate identity lifecycle with runtime policy, short-lived access, and complete audit evidence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10The article centers on AI agents, delegation, and tool-use governance.
OWASP Non-Human Identity Top 10NHI-03Console-style agent workflows depend on credential lifecycle and secret governance.
NIST AI RMFGOVERNAgentic AI governance requires clear ownership and accountability.
NIST Zero Trust (SP 800-207)Runtime delegation and continuous verification align with zero trust principles.
NIST SP 800-53 Rev 5AC-6Least privilege is central when agents can call multiple enterprise tools.

Treat AI agents as NHIs and enforce rotation, revocation, and lifecycle control on their credentials.


Key terms

  • Agentic workflow: An agentic workflow is a sequence of tasks executed by an AI agent with some level of tool access and decision authority. In security terms, the workflow matters because it can span multiple systems, identities, and permissions, which makes attribution and revocation harder than with ordinary automation.
  • Agent-to-Agent Delegation: Agent-to-agent delegation is the handoff of work from one AI agent to another, often across different tools or identity contexts. It expands the governance boundary because the original actor no longer controls every action, and inherited permissions can create risk that the first approval never covered.
  • Task-Scoped Access: Task-scoped access is permission granted for one defined purpose and removed once the task is complete or the session expires. For non-human identities, it reduces standing privilege and limits how long an attacker can exploit a stolen credential.
  • Identity Lifecycle Governance: Identity lifecycle governance is the set of processes that create, change, review, rotate, and revoke access across human and non-human identities. It matters because access risk usually increases when lifecycle events are slow, incomplete, or disconnected from the systems that rely on them.

What's in the full analysis

Palo Alto Networks' full press release covers the financial detail this post intentionally leaves to the source:

  • Quarterly and annual revenue, ARR, cash flow, and margin tables for the fiscal fourth quarter and full year 2026
  • Management guidance for fiscal first quarter and full year 2027, including revenue, ARR, and margin outlook
  • A breakdown of adjusted free cash flow, reconciliation tables, and balance sheet detail
  • The acquisition disclosure for Console and the company’s own framing of how it expands Cortex across agentic workflows

👉 The full Palo Alto Networks press release includes the financial tables, guidance, and acquisition detail behind the headline.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity lifecycle control to emerging AI and automation risks.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org