> ## Documentation Index
> Fetch the complete documentation index at: https://docs.inviolet.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Palo Alto Prisma Access

> Connect Palo Alto Prisma Access to Inviolet — observe LLM bypass volume (CASB) today; network enforcement (SWG) on request.

Palo Alto Prisma Access integrates with Inviolet in the two directions described in the
[network enforcement overview](/integrations/network/overview): **observe**
(read the vendor's egress logs into Inviolet) and **enforce** (block direct LLM
access).

## Observe (CASB) — available today

Inviolet's `casb-prisma` connector pulls Palo Alto Prisma Access egress events and ingests the ones
bound for LLM providers, so bypass volume and attribution show up in the
[Shadow IT analytics](https://app.inviolet.ai/analytics/shadow-it) view.

**Set it up:** Inviolet → **Settings → Data Sources → Admin Connectors → New →
Palo Alto Prisma Access**, then paste your credentials.

**Credentials:** Prisma Access — a Cortex Data Lake API key + tenant id + region.

## Enforce (SWG) — on request

Network enforcement packs for Palo Alto Prisma Access (block direct LLM API + consumer UIs, forcing
traffic through Inviolet) are delivered per engagement. Unlike Cloudflare — which
matches at the DNS layer natively — Palo Alto Prisma Access enforcement is scoped to your tenant's
capabilities. [Contact us](mailto:support@inviolet.ai) to scope a deployment.

<Note>
  **Cloudflare is the reference vendor**, validated end to end (enforcement +
  observability). See the [Cloudflare guide](/integrations/network/cloudflare) for
  the full pattern; the same shape applies here once your enforcement pack is built.
</Note>
