TL;DR: Agentic workflows are becoming a category-defining security and governance issue, and Palo Alto Networks says it has acquired Console to extend Cortex across enterprise agentic transformation, while also flagging AI agents as a new class of identity. That shift pushes identity, privilege, and workflow controls closer together than most programmes are ready for.
NHIMG editorial — based on content published by Palo Alto Networks: Palo Alto Networks reports fiscal fourth quarter and fiscal year 2026 financial results
By the numbers:
- Next-Generation Security ARR grew 63% year over year to $9.10 billion in fiscal fourth quarter 2026.
- Total revenue for fiscal fourth quarter 2026 grew 34% year over year to $3.41 billion.
Questions worth separating out
Q: What breaks when agentic workflows are not scoped tightly enough?
A: Outputs become inconsistent, users receive different recommendations for the same problem, and the organisation loses confidence in the agent’s reasoning.
Q: Why do delegated credentials increase risk when AI agents and users are not clearly separated?
A: Delegated credentials can blur the boundary between user intent and agent autonomy.
Q: How should security teams implement task-scoped access for multi-agent systems?
A: Start by mapping each sensitive agent action to a specific resource, approval condition, and expiry rule.
Practitioner guidance
- Define a unique identity for every agentic workflow Assign each agent a distinct principal, separate from the human owner and from shared service accounts.
- Move from static access to task-scoped delegation Replace standing credentials with short-lived, task-scoped authorisation that expires when the workflow completes.
- Log the full agent-to-tool decision chain Capture which prompt, policy, tool call, token, and downstream action occurred in sequence so investigators can reconstruct why the workflow acted.
What's in the full analysis
Palo Alto Networks' full press release covers the financial detail this post intentionally leaves to the source:
- Quarterly and annual revenue, ARR, cash flow, and margin tables for the fiscal fourth quarter and full year 2026
- Management guidance for fiscal first quarter and full year 2027, including revenue, ARR, and margin outlook
- A breakdown of adjusted free cash flow, reconciliation tables, and balance sheet detail
- The acquisition disclosure for Console and the company’s own framing of how it expands Cortex across agentic workflows
👉 Read Palo Alto Networks' fiscal 2026 results and Console acquisition note →
Console joining Palo Alto Networks: what changes for agentic workflows?
Explore further
AI agents are becoming identity-bearing systems, not just application features. Once a workflow can choose actions and invoke tools at runtime, it creates an access problem that conventional application security does not fully describe. The governance model has to cover delegation, scope, and revocation as first-class identity concerns. Practitioners should treat agentic AI as part of the identity plane, not an adjacent automation layer.
A question worth separating out:
Q: How do organisations know if agentic AI governance is actually working?
A: Look for three signals: access decisions tied to task context, complete audit records linking agents to datasets, and rapid revocation when scope changes. If reviewers still need manual reconstruction after an incident, the programme is not mature. Effective governance produces explainable access, not just allowed or denied results.
👉 Read our full editorial: Palo Alto Networks and Console: agentic workflow governance implications