Use Cortex Agentic Assistant chat in an investigation - Learn how to use the Agentic Assistant chat. - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Learn how to use the Agentic Assistant chat.

The Cortex Agentic Assistant chat provides an interactive and intelligent way to simplify and streamline complex security operations. Enter a prompt using natural language, and your agent plans and executes the most relevant actions to fulfill your request.

Note

The Cortex Agentic Assistant is currently available in limited regions. For more information see Cortex Agentic Assistant If your tenant is not within one of those regions, you have access to the Cortex Assistant.Cortex Agentic AssistantCortex Assistant

To enable the Cortex Agentic Assistant, go to SettingsConfigurationsGeneralServer SettingsAgentic Assistant.

The chat leverages your personal context (such as your name, email, and roles), the agent’s description, available actions, and conversation context to enable highly informed and personalized interactions. You can manage multiple chats simultaneously and easily switch between the agents you have access to. Before acting, the agent generates a plan, verifying each step while executing the sequence of actions that fulfill your request.

Accessing and exiting the Agentic Assistant chat is designed to be quick and seamless, allowing you to jump into your investigations or step away with ease.

Access the chat

To access the chat, you must have the correct permissions. For more information, see Agentic Assistant role-based access control.

Exit the chat

To close the chat window, click anywhere outside the chat window's boundaries or in the side menu click Agentic Assistant.

Choose an agent

Before you dive into your investigation, select the most relevant AI agent for the job. Each agent is designed with specific goals and functions to help you address different aspects of security operations.

Within the chat prompt, click the agent icon; a list of available agents appears. As you hover over each agent, a brief description pops up explaining what that agent does and its primary focus. Select the agent that best suits your current task or investigation.

You can choose from system agents, public agents other users have created, or agents you have personally built and configured.

agent-drop-down.png
Safeguards for chat security and control

Cortex Agentic Assistant implements the following safeguards to ensure agent plans and executions are secure, approved, and maintains your control over critical system changes.

  • Agents are designed to intelligently validate their proposed plans, ensuring that all necessary permissions are in place before any action is taken.

  • Cortex Agentic Assistant clarifies ambiguous prompt intentions and blocks requests that may be exploitative or harmful, for example, to perform a malicious operation.

  • For any sensitive actions, agents will always require your explicit approval.

  • Cortex Agentic Assistant clarifies ambiguous prompt intentions to verify the intention.

Engage with your agent

After choosing an agent, in the chat prompt, type a request using natural language. Be as clear and specific as possible. Submit your request by pressing Enter or clicking the submit arrow. Some agents provide relevant chat conversation starters under the chat prompt.

During a conversation, when an agent is formulating a plan or executing steps, clicking the agent will show which actions it is using. You can scroll between the actions or close the panel.

Tip

If you need to quickly access various product pages within Cortex XDR, type / in the prompt.

Chat history

Cortex Agentic Assistant helps you keep track of your investigations by organizing your chat history for easy review and continuity.

Your chat history is listed to the left of the prompt, making it simple to navigate past conversations. The chat history is organized by periods: Chats from today, yesterday, the last seven days, and older. To continue a previous investigation or review a past conversation, scroll through the list and click on the chat you wish to resume.

Manage your chats

By default, the first prompt you enter in a new chat becomes its title in the history. To edit the chat title or delete a chat that is no longer relevant, click three-dots.png and select Edit or Delete.