CyberArk, now Idira by Palo Alto Networks, applies dynamic privilege and agent identity controls to AI-driven customer journeys, but buyers still need to prove they can revoke access, preserve attribution, and work cleanly across customer engagement systems.
Unified communications and customer engagement teams are giving more authority to software identities. AI assistants retrieve documents in collaboration tools, contact center agents move between CRM and billing, service accounts connect platforms, and administrators change routing, recording, or access policies that can affect every conversation.
That creates a real workplace identity problem. Authentication confirms that an agent got through the door, but not who confirmed the task, which actions were allowed, or whether the business had the ability to stop the agent when the risk level changed.
Plenty of companies are already responding to this, from Microsoft, Okta, and SailPoint, all releasing their own AI-agent identity controls in 2026. CyberArk, now part of Palo Alto Networks and branded as Idira, is making its own argument: communications security increasingly depends on controlling privilege after login across human, machine, and agentic identities.
Related Articles
TL;DR: Is CyberArk Idira Ready for Modern Communications?
- The market problem: Modern communications now depend on employees, administrators, service accounts, APIs, bots, and AI agents, so a valid login canβt prove that every later action is appropriate.
- CyberArkβs position: Idira applies CyberArkβs privilege model to human, machine, and agentic identities, with discovery, temporary authority, MCP controls, and audit evidence.
- The buyer test: Demand live revocation, full attribution, safe failure, low latency, coverage across UC, contact center, collaboration, and custom agent paths, plus usable evidence outside the Palo Alto Networks ecosystem.
- The verdict: Idira has the right thesis for communications identity security, but its leadership depends on delivered cross-product integration and production proof.
Why Are Customer Journeys Becoming an Identity Security Problem?
Communications identity security is becoming harder because employees, administrators, service accounts, bots, APIs, and AI agents all act across workflow systems. Each handoff creates a new authorization decision. A valid login wonβt prove that every later tool call, data request, policy change, or customer action is appropriate.
An AI assistant is preparing a renewal, using a service account to reach the CRM, contracts, email, and contact center. Across the business, an administrator updates routing or recording settings for several thousand users. Both workflows need strong identity controls, but the access involved and the fallout from a mistake are nowhere near the same. More companies are finally treating that as a real problem.
Companies are waking up to the issue. According to the OWASP Top 10 for Agentic Applications 2026, tool misuse and identity & privilege abuse are some of the top risks for autonomous systems. Palo Alto Networksβ vendor-sponsored 2026 Identity Security Landscape found that 99% of surveyed organizations had adopted AI agents and 40% let them access organizational data. Only 37% could revoke agent credentials, while 30% maintained immutable audit logs. Deployment is outrunning control.
The response window is shrinking too. Unit 42βs June 2026 analysis reported that 65% of initial access was driven by identity-based techniques and that the fastest attackers moved from initial access to confirmed data exfiltration in 72 minutes. The race for stronger identity security is on.
Key Takeaways
- Communications security needs to check permissions for each task, not wave everything through because the identity passed login.
- The dangerous gap is operational: many businesses can deploy an agent or service identity faster than they can stop, trace, or reconstruct it.
What Is CyberArk Idira, and What Does It Secure?
CyberArk Idira identity security is the privilege and identity layer Palo Alto Networks is building for human, machine, and AI identities. Palo Alto Networks acquired CyberArk on February 11, 2026, and introduced Idira in May.
Idira gives organizations a complete platform that can discover identities and risky access, apply dynamic privilege, and govern access through the identity lifecycle. There are also Secure AI Agent capabilities that add agent discovery, ownership, MCP controls, temporary privilege, and audit evidence.
For communications leaders, Idira isnβt running meetings, routing calls, or even replacing native UC and contact center tools, but it does control the identity, credential, and privilege behind the person, service, or agent performing the work.
| Communications layer | Idiraβs role | Not Idiraβs role |
|---|---|---|
| UC and contact center administration | Limits privileged access and records changes | Runs calling, routing, or recording |
| Collaboration and customer workflows | Protects the acting user or agent and its access | Chooses journey steps or content |
| MCP, APIs, and tools | Brokers credentials and authorizes access | Builds the agent workflow |
| Machine-to-machine communication | Governs identities, credentials, and privileges | Replaces network or application security |
| Incident response | Supports revocation and identity evidence | Replaces every security control |
Key Takeaways
- Idira protects the people, software, and machine identities working behind communications systems. It doesnβt provide UCaaS, CCaaS, journey orchestration, or content security.
- The useful test is whether identity context changes what an actor can do before and during a communications workflow.
Learn more about identity assurance for AI in this guide.
How Does Idira Protect Human, Machine, and AI Identities?
Idira applies one privilege model to three different groups: people administering or using platforms, machine identities connecting services, and AI agents acting with delegated authority. The idea is to replace permanent access with discoverable ownership, task-specific privilege, protected credentials, plus evidence that survives handoffs between systems.
For human identities, UC and contact center administrators can change routing, recording, integrations, retention, or access policies, so standing rights create a large blast radius. Just-in-time authority and session evidence can narrow who made a sensitive change and why.
Machine identities include service accounts, certificates, secrets, and workload identities that connect communications platforms to CRM, workforce, analytics, and automation tools. AI agents add another layer because they select tools and act on someone elseβs behalf.
Palo Alto Networks launched Idira in May 2026 with Zero Standing Privilege as its stated starting point. Buyers should put that promise through its paces. The real trouble will sit in outside SaaS apps, communications APIs, and custom connectors that donβt live neatly inside Palo Alto Networksβ stack.
Key Takeaways
- A person, machine, and AI agent may have different owners and offboarding rules. All three should receive only the access required for the job.
- Static access is the wrong benchmark; buyers should test whether authority shrinks, expires, and can be removed live.
How Do Secure AI Agents Control MCP and Delegated Access?
Secure AI Agents were already a part of the CyberArk platform before the acquisition. They place an identity broker between an AI agent and the remote MCP server or tool it wants to use. The broker can authorize the connection and proxy the request without exposing the underlying credential. That creates a control point for ownership, permission, session evidence, as well as revocation.
MCP gives agents a common way to reach CRM records, knowledge, databases, collaboration platforms, and workflow tools. It also concentrates risk. Palo Alto Networks cited Bloomberry research in May 2026 finding that 38% of analyzed MCP servers had no authentication.
OAuth canβt solve every part of the problem. A token might identify the employee who approved access while hiding the agent acting on that personβs behalf. Long-lived tokens can survive after the task, and an approved server can change after an update.
Palo Alto Networks says Secure AI Agents can find remote servers, spot missing owners, block new connections until someone approves them, and log every tool and action used. Buyers should check whether a developer can route around the broker. A checkpoint doesnβt protect much when the road beside it remains wide open.
Key Takeaways
- MCP turns one communications task into several authorization decisions across different systems.
- The brokerβs value depends on coverage. Every route around it becomes an ungoverned path to enterprise data and actions.
Where Can Idira Reduce Risk Across UC and Customer Engagement?
Idira can reduce communications risk where a trusted identity has enough access to change service behavior, expose sensitive data, or act across several platforms. It enables smaller standing privileges, protected credentials, stronger attribution, and targeted containment.
On the UC side, a compromised administrator or service account could alter call routing, recording, or integrations. Idira would help with limiting elevation to the approved task, recording the session, and removing the privilege without disabling the whole communications environment.
In a collaboration platform, an AI assistant might pull files, recap a meeting, or kick off a workflow. Put that agent in customer service, and it may open a case, adjust a bill, write an email, or start a refund. Idira is meant to decide whatβs allowed each time.
Still, Idira doesnβt analyze whether a conversation is fraudulent, enforce recording law, moderate content, secure the network, or replace platform-native roles. Buyers need to map which identity decisions Idira can actually enforce and where another control remains responsible.
Key Takeaways
- Idiraβs greatest value is controlling the authority behind sensitive communications activity, not managing the communication itself.
- Customer journeys are a high-risk example of the problem, not the full communications identity use case.
Where Does Idira Fit, and When Does Platform Consolidation Create Lock-In?
Idira fits most naturally as a privileged identity layer around communications, not as a replacement for every IAM, IGA, CIAM, UC, or contact center control. Platform consolidation becomes lock-in when useful enforcement or evidence requires several Palo Alto Networks products, separate licenses, or proprietary workflows that cannot be reproduced or exported elsewhere.
PAM consolidation might be an option when a company has several vaults, permanent administrator rights, and disconnected session records. IAM replacement is riskier because it touches employee login, application access, recovery, and thousands of integrations. IGA sits between them, with governance value from access reviews and entitlement context.
Idira doesnβt replace CIAM. It secures the human and nonhuman identities operating behind the customer experience, not the customerβs registration, consent, profile, or login. Native roles, recording policies, fraud controls, and communications compliance remain part of the stack too.
Key Takeaways
- PAM may move under one Idira roof. IAM, IGA, CIAM, and native communications controls still need to earn their place application by application.
- Buyers should price portability and cross-product dependencies, not only the Idira subscription.
What Should Communications Buyers Test in an Idira Proof of Concept?
An Idira proof of concept should use the communications environment you actually run. Bring in real employees, service accounts, AI agents, working permissions, and at least one unfamiliar tool. Then test whether Idira can discover access, trim privileges, revoke them immediately, identify every action, enforce controls without noticeable lag, and fail safely across UC, collaboration, contact center, and customer engagement.
| Test | Communications scenario | Pass condition |
|---|---|---|
| Discovery | Add an unsanctioned bot or CRM agent | Idira finds it, its owner, and reachable systems |
| Least privilege | Ask an assistant to alter routing or billing | The action is denied or requires approval |
| Live revocation | Stop an identity mid-workflow | Tokens and downstream sessions close quickly |
| Attribution | Trace a policy change or refund | Evidence links sponsor, identity, permission, and action |
| Performance | Apply policy during a live workflow | No unacceptable delay or false denial |
| Resilience | Disable the broker or connector | The workflow fails safely without credential leakage |
| Portability | Send evidence to a third-party SIEM | Context remains complete outside Palo Alto products |
When testing UC security, measure what the tool finds, how long approval takes, how long privilege remains active, and how quickly it can be revoked. Track false denials, missing audit records, added latency, extra consoles, and every manual handoff. Run administrators, service accounts, custom agents, local MCP servers, and outside connectors through the test. Then make Palo Alto Networks separate whatβs included from what costs extra, requires another product, or hasnβt shipped yet.
Key Takeaways
- The decisive test is live revocation across every session the identity opened, timed rather than demonstrated.
- A unified platform has missed its point if investigators still need several consoles and manual handoffs, or if policy adds unacceptable delay to a live interaction.
Is CyberArk Ahead of the Identity Security Shift in Communications?
CyberArk is ahead in one important respect: it starts with privilege after authentication, rather than treating agent registration as the finish line. Idiraβs CyberArk foundation, MCP broker, dynamic privilege model, and links into runtime security make it a credible example of how identity security can protect modern communications. Leadership still depends on delivered integration and production evidence.
The competition is heating up, too. Microsoft Entra Agent ID reached general availability in May 2026. Okta for AI Agents became generally available on April 30, and SailPoint launched Agentic Fabric in May. Agent identity is becoming a competitive platform category of its own.
Idiraβs distinction is the weight it gives to privileged action. Its weakness is architectural sprawl: the full story can cross Idira, Cortex, Prisma AIRS, and separate entitlements. Communications buyers should credit the direction, then score only the controls that work in their environment today.
FAQs
Is CyberArk now called Idira?
Idira is the new umbrella brand for Palo Alto Networksβ identity security platform following the CyberArk acquisition, which closed on February 11, 2026. The underlying CyberArk product names remain active across documentation, agreements, and customer deployments. In practice, buyers will run into both names.
What is communications identity security?
It controls who and what can reach UC, collaboration, contact center, CRM, and connected communications workflows. That includes employees, administrators, service accounts, machines, bots, and AI agents. The focus is ownership, credentials, permissions, authorization, evidence, and fast revocation. It works beside network security, fraud controls, compliance tools, content protection, and native platform security rather than taking their place.
Does Idira replace UCaaS or contact center security controls?
No. Idira doesnβt run calling or meetings, configure every platform role, inspect conversation content, enforce recording law, or replace fraud and network defenses. It can add identity discovery, privileged access, credential protection, attribution, and revocation around sensitive communications activity. Buyers still need the native security and compliance controls built into their UC, collaboration, and contact center platforms.
Can Idira secure AI agents in UC, CRM, and contact center workflows?
Yes, where Idira can discover the agent, see the relevant identity and permissions, and enforce access through supported integrations or its MCP control point. Buyers should test custom agents, local MCP servers, SaaS connectors, mid-workflow revocation, audit export, and latency rather than assuming every UC, CRM, or contact center path receives the same coverage.
How does Idira protect machine identities?
Idiraβs broader platform is designed to discover and govern machine identities such as service accounts, workload identities, certificates, and secrets, then connect them to ownership and privilege controls. Communications buyers should test whether it can find identities across cloud and on-premises systems, rotate or protect credentials, revoke access quickly, and preserve evidence when services communicate without a person present.