Tufin has announced its strategy for Agentic Network Security, establishing itself as the foundational control layer for governing connectivity risk in an increasingly AI-driven enterprise landscape. By leveraging its unique Dynamic Network Connectivity Graph—the most accurate digital twin of multi-vendor, multi-technology networks—and decades of proven automation playbooks, Tufin enables security teams to deploy autonomous AI agents that handle routine network security tasks with human-defined policy and oversight.
Enterprise networks are evolving rapidly with AI-embedded applications, infrastructure, and operations driving machine-initiated changes at unprecedented scale and speed. This introduces new risks around connectivity governance—who or what (including agents) can communicate—and amplifies challenges from AI-assisted threats that exploit drift, map attack paths, and expand surfaces autonomously.
Legacy processes reliant on manual change requests and delayed reviews cannot scale in this reality. Security posture must be assessed and enforced continuously to maintain alignment with policy and intent.
Tufin’s four new agents operate on the Dynamic Network Connectivity Graph and automation playbooks:
The Compliance Agent continuously monitors and validates segmentation and access rules against regulatory and internal requirements, immediately flagging violations and initiating remediation workflows.
The Network Security Posture Agent analyzes real connectivity exposure, attack paths, and critical asset dependencies to prioritize vulnerabilities and recommend compensating controls.
The Application Deployment Agent translates application connectivity needs into policy-compliant rules, validates them against existing controls, and supports secure deployment.
The Policy Recertification Agent automates rule-to-owner mapping, approval requests, and revocation of unnecessary access to reduce risk from outdated permissions.
These agents integrate with Tufin’s expanding TufinAI suite, including upcoming Segmentation Intelligence to verify posture matches intent, MCP server for agent and copilot connectivity, the TufinMate self-service chatbot, customizable Executive Dashboards, and natural-language assistants for querying network data and triggering workflows.
“As AI accelerates change across enterprise infrastructure, networks are changing at a pace that makes manual security virtually impossible,” said Raymond Brancato, CEO of Tufin. “Security teams need a precise, trusted understanding of enterprise connectivity, with continuous insights into exposure, proof of segmentation, and validation that the network remains aligned with policy and security intent. There is only one solution that makes organizations confident in their network security posture in an agent-rich world – and that’s Tufin.”
Tufin will demonstrate these agents and its vision for Multi-Vendor Agentic Network Security at RSA Conference 2026 (March 23–26, San Francisco) in Booth #4528, North Hall. Erez Tadmor, Field CTO, will present “Why Network Security Posture Is Foundational to Modern Security” on March 25 at 11:10 am PDT in the South Hall Briefing Center.
About Tufin
Tufin helps enterprises govern and secure connectivity across today’s complex multi-vendor networks. As the leader in network security posture management, Tufin provides the trusted control layer organizations need to understand exposure, automate policy changes safely, and maintain continuous security posture across on-premises, cloud, SASE, microsegmentation, and hybrid environments. Built on customer-proven network automation playbooks and the industry’s only Dynamic Network Connectivity Graph, Tufin is bringing Multi-Vendor Agentic Network Security to the enterprise — helping organizations move from visibility to governed, AI-driven action.