Skip to main content
Palo Alto Prisma Access integrates with Inviolet in the two directions described in the network enforcement overview: observe (read the vendor’s egress logs into Inviolet) and enforce (block direct LLM access).

Observe (CASB) — available today

Inviolet’s casb-prisma connector pulls Palo Alto Prisma Access egress events and ingests the ones bound for LLM providers, so bypass volume and attribution show up in the Shadow IT analytics view. Set it up: Inviolet → Settings → Data Sources → Admin Connectors → New → Palo Alto Prisma Access, then paste your credentials. Credentials: Prisma Access — a Cortex Data Lake API key + tenant id + region.

Enforce (SWG) — on request

Network enforcement packs for Palo Alto Prisma Access (block direct LLM API + consumer UIs, forcing traffic through Inviolet) are delivered per engagement. Unlike Cloudflare — which matches at the DNS layer natively — Palo Alto Prisma Access enforcement is scoped to your tenant’s capabilities. Contact us to scope a deployment.
Cloudflare is the reference vendor, validated end to end (enforcement + observability). See the Cloudflare guide for the full pattern; the same shape applies here once your enforcement pack is built.