> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1.md).

# Configure the Cortex Agentic Assistant

Configure the Cortex XSIAM Agentic Assistant for AI-powered SOC investigations, response, agents, actions, knowledge sources, and access.

The Cortex XSIAM Agentic Assistant helps SOC teams investigate, triage, and respond through AI agents. Agents turn security operations requests into plans and execute approved actions within each user's permissions.

#### How the components work together

An **agent** is a specialized virtual persona for a security operations domain or workflow. It selects from its assigned **actions** to build and run an investigation or response plan.

Actions wrap capabilities such as Cortex XSIAM playbooks, scripts, AI prompts, and commands. Add only the actions each agent needs.

**Knowledge** gives AI agents business-specific context and Cortex XSIAM product expertise. Knowledge sources and MCP integrations can extend an agent's context and capabilities.

**Role-based access control (RBAC)** defines who can use Agentic Assistant chat, manage actions, and manage agents. Agents never exceed the permissions of the user running them.

### Configure your agent workforce in Cortex XSIAM

1. Review [Agentic Assistant components and concepts](/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agentic-assistant-components-and-concepts.md) before designing an agent.
2. Use the [Agentic Assistant Hub](/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agents-hub.md) to register security automation actions, build AI agents, and assign actions.
3. Add knowledge sources or MCP integrations when the AI agent needs more context or capabilities.
4. Configure [role-based access control](/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1/agentic-assistant-role-based-access-control.md) before giving users access.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
