Zscaler Blog
Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang
Operate Zscaler Zero Trust Exchange with the Agentic AI tool of Your Choice
Introducing Zero Trust Exchange Agentic Operations, which enables customers to use their preferred AI agents to interact with Zscaler through a secure, governed, and auditable operational layer.
Enterprise teams are rapidly moving from experimenting with AI to putting it to work. AI assistants are already helping administrators find information, summarize incidents, and answer operational questions about their various solutions. The graphical interface will remain important. APIs, SDKs, and infrastructure-as-code will continue to be essential.
The next step is agentic: enabling AI not only to provide an answer, but to help carry a task through to completion.
There is a growing demand for these agent-driven use cases. Practitioners of all stripes want agents that can investigate why a user cannot access an application, retrieve relevant configuration details, recommend remediation tactics, and, when authorized, take action. And they want all of this functionality to be available for the specific AI assistants, models, and development frameworks that best fit their organizations.
AI agents are emerging as another operational interface—one that allows admins to express desired outcomes in natural language and have agents achieve them.
Zscaler is evolving to support this shift.

From predefined automation to agent-driven operations
Traditional automation works best when the process is known in advance. A team defines a sequence of API calls, encodes the logic in a script or workflow, and runs it when a specific event occurs.
Agents introduce a more flexible model. An admin can describe the intended outcome, and an agent can interpret the request, determine which tools are relevant, identify the steps it should take, and perform the relevant action(s).
For example, “Why can’t this user reach our finance application?” is not a single API request. Answering it may require gathering context, checking multiple signals, evaluating configuration, and determining whether the issue is caused by policy, identity, device posture, connectivity, or the application itself. An agent can help coordinate that investigation rather than requiring an administrator to manually navigate every step.
As customers explore agentic workflows in a platform, they need a consistent way for agents to interact with the different services within that platform. Giving an agent access to a collection of raw administrative APIs is not enough. The platform needs to expose useful operational capabilities while still controlling how each agent connects, what it can discover, which actions it can perform, and how those actions are recorded.
That is the role of Zero Trust Exchange Agentic Operations.
Introducing Zero Trust Exchange Agentic Operations
Agentic Operations enables first-party and third-party AI agents to securely perform supported Zscaler operations.
Customers can access these capabilities directly through ZAgent, Zscaler’s native agentic experience within the Experience Center. An administrator can describe an objective in natural language, and ZAgent interprets the request, engages the appropriate specialized Zscaler agents and skills, and returns a coordinated response. This gives customers an integrated way to investigate issues, obtain insights, and perform supported administrative tasks without navigating multiple products or manually coordinating each step.
Zero Trust Exchange Agentic Operations extends these capabilities beyond the Experience Center through the Agentic Operations Gateway and its hosted Model Context Protocol (MCP) server. MCP is an open standard that gives AI applications a consistent way to discover and use tools provided by external systems. Through the hosted MCP server, commercial AI clients such as Claude and ChatGPT, as well as agents built by customers, can access supported Zscaler capabilities without requiring customers to deploy and maintain their own Zscaler MCP server.
Rather than simply exposing individual APIs as tools, the Agentic Operations MCP server is designed around operational intents. An intent represents the outcome a user wants to achieve, such as investigating an access issue, validating a policy, or resolving a connectivity problem. Zscaler coordinates the underlying tools, API calls, validation, and sequencing needed to fulfill that intent.
This makes agentic workflows easier and more reliable because the agent does not need to understand every Zscaler product or independently assemble a complex sequence of low-level API calls.Throughout the interaction, the Agentic Operations Gateway provides the routing, identity, authorization, approval controls, and auditing required for enterprise operations. Customers retain the flexibility to choose where their agents and reasoning models run, while Zscaler manages and governs the connection to its services.
Meeting customers where they are
We recognize that different teams will adopt different assistants, models, orchestration frameworks, and deployment patterns. Some customers will use commercial AI experiences. Others will build specialized agents for their own service desk, security operations, or administrative workflows. Many will use both.
Zscaler’s Agentic Operations is designed for that reality.
Use the agent experience that fits the organization. Customers can connect supported Zscaler capabilities to the AI clients their teams already use rather than moving every workflow into another interface.

Make Zscaler capabilities understandable to agents. Raw APIs are optimized for developers, not necessarily for models interpreting human intent. Governed tools and Zscaler-authored skills can give agents clearer, task-oriented ways to retrieve information and perform supported operations.
Support commercial and customer-built agents. Customers can connect approved commercial AI clients such as Claude and ChatGPT, as well as their own custom agents, through an OAuth 2.1 authorization flow. After signing in, users review and choose which of their assigned administrative roles to grant to the client, and can later revoke that access.
The goal is not to prescribe how customers adopt AI. It is to make Zscaler ready to participate securely in the agentic ecosystems they choose.
Governance built into the operational path
As agents take on more operational work, the actions they perform must remain subject to the same enterprise controls that customers expect elsewhere in their environment. The Agentic Operations Gateway is designed to provide those controls as part of the interaction itself:
Customer-controlled client authorization: Administrators control which AI clients can connect to their Zscaler tenant, including predefined clients such as ChatGPT and Claude. Zscaler’s authentication service (formerly ZIdentity) uses standards-based client metadata to establish the client’s identity and configuration.
User authentication and consent: When an admin connects to an approved AI client, the authentication service authenticates the admin through the customer’s existing sign-in process and presents the administrative roles available to that admin. The admin can choose which roles to authorize for the client, ensuring that access is both user-bound and explicitly granted.
Visible and revocable access: Admins can review the applications they have authorized and revoke access when it is no longer needed. Super Administrators can review and revoke authorization grants across the organization.
Auditable authorization lifecycle: Client registration, authorization requests, grants, denials, token refreshes, and revocations are recorded in Zscaler audit logs.
These controls allow customers to expand the scope of their agentic use cases without creating an unmanaged path that circumvents established operational safeguards.
What agentic operations can look like
Consider a user who reports that a business-critical application is not working.
Today, a support or security team member may need to move between a ticket, multiple consoles, logs, policy configuration, and documentation to diagnose the issue. Even when the remediation is straightforward, collecting the context and determining the correct action can take time.
With Agentic Operations, the customer’s preferred agent could invoke an intent to investigate the access issue. The hosted MCP server could route the request to the appropriate Zscaler capabilities, gather the relevant context, and return a likely cause and recommended remediation. If the proposed action requires approval, the agent could pause for confirmation. Once approved, the supported operation could be executed and the workflow recorded for auditing.


The agent provides the experience and coordinates the interaction with the admin. Zscaler provides the trusted operational capabilities and governs how they are used.
This model can extend across a growing range of use cases: retrieving configuration and posture information, investigating incidents, validating policy, responding to service desk requests, coordinating change workflows, and carrying out approved remediation.
The value is a more intuitive and governed path from intent to operational outcome.
Building the next interface to Zscaler
The move toward agent-driven operations will not replace existing consoles or automation tools. It simply expands the ways customers can work with Zscaler.
Just as APIs enabled developers to build integrations, agents create a new interaction model for operational work. Customers can begin with simple tasks like using natural language to obtain information about their policies and gradually adopt more advanced workflows as their needs and governance models mature.
Zero Trust Exchange Agentic Operations provides the foundation for that evolution: a hosted service, intent-based tools and skills, standards-based connectivity, intelligent routing, strong identity, least-privileged authorization, approval controls, and end-to-end auditability.
Here's an example demo of how it works:

By providing this foundation, Zscaler can continue supporting new agentic use cases while giving customers a consistent and controlled way to adopt them.
Join the Early Access Program
Zero Trust Exchange Agentic Operations is opening for early access, and we are inviting customers and partners to help shape what comes next.
Early access participants will be able to explore agent-driven Zscaler operations, validate priority use cases, and provide direct input into the intents, tools, skills, workflows, and governance capabilities we develop.
We are particularly interested in hearing from organizations that are already using commercial AI assistants, building their own enterprise agents, or identifying operational workflows that could benefit from a more natural, agent-driven experience.
AI agents are becoming a new interface for enterprise operations. Our goal is to make Zscaler capabilities available through that interface while preserving the control, visibility, and trust our customers require.
Talk to your Zscaler representative to learn more and request participation in the Zero Trust Exchange Agentic Operations Early Access Program.
War dieser Beitrag nützlich?
Haftungsausschluss: Dieser Blog-Beitrag wurde von Zscaler ausschließlich zu Informationszwecken erstellt und wird ohne jegliche Garantie für Richtigkeit, Vollständigkeit oder Zuverlässigkeit zur Verfügung gestellt. Zscaler übernimmt keine Verantwortung für etwaige Fehler oder Auslassungen oder für Handlungen, die auf der Grundlage der bereitgestellten Informationen vorgenommen werden. Alle in diesem Blog-Beitrag verlinkten Websites oder Ressourcen Dritter werden nur zu Ihrer Information zur Verfügung gestellt, und Zscaler ist nicht für deren Inhalte oder Datenschutzmaßnahmen verantwortlich. Alle Inhalte können ohne vorherige Ankündigung geändert werden. Mit dem Zugriff auf diesen Blog-Beitrag erklären Sie sich mit diesen Bedingungen einverstanden und nehmen zur Kenntnis, dass es in Ihrer Verantwortung liegt, die Informationen zu überprüfen und in einer Ihren Bedürfnissen angemessenen Weise zu nutzen.
Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang
Mit dem Absenden des Formulars stimmen Sie unserer Datenschutzrichtlinie zu.



