I’ve been reading through the Cisco Live 2026 deck for session BRKOPS-2279, “AgenticOps in Action: AI-Driven NOC and SOC Operations with Cisco Cloud Control”, presented by Saurav Prasad, a Principal Technical Marketing Engineer at Cisco. Before anything else: this post reflects what the deck shows, not me sitting in the room for the session.
Cisco Cloud Control is pitched as the unified operations platform for agentic IT, with AI Canvas as its agentic workspace. That’s a big claim to put on a slide, so I want to work through what’s actually underneath it before I decide how much of it I believe.
The problem it’s aimed at
IT operations are fragmented. When you see a symptom, the cause could be anywhere. Cisco frames this with a question I’ve muttered under my breath more than once: “Why is my application so slow?” The answer might be networking, security, compute, observability, collaboration, or your third-party ecosystem. Diagnosing it means logging into multiple tools, manually correlating signals across timestamps, escalating through layers. That friction is what Cloud Control is meant to address.
What the platform actually is
Strip away the framing and here’s what I find underneath it: Cloud Control pulls together Meraki, Catalyst Center, Intersight, Nexus Dashboard, Nexus Hyperfabric, Security Cloud Control, ThousandEyes, Splunk, Catalyst SD-WAN, Collaboration Control Hub, and IQ into a single login experience backed by shared platform services. Those services are Identity, Inventory, Topology, Alerts and Actions, and Licensing.
The positioning rests on five “power of one” pillars: one login (sign in once, see everything), one inventory and topology (every asset, how it connects, in real time), one view for alerts (correlated across every product), one assistant (quick answers via conversational AI), and one agentic workspace (investigate, execute and resolve with AI Canvas).

Figure 1 – Cloud Control as presented in the deck: integrated products, the AI workspace, and shared platform services over the product controllers, with Cisco Unified Identity binding user and product identity.
Identity and access underneath it
I always want to know what’s holding a “one login” claim up, because it only works if identity and access control make sense underneath it. Users are mapped to a tenant at sign-in (tenant binding), sessions continue across products without re-authenticating, and Day 0 flexibility lets you add or remove products under one tenancy.
Access control uses three platform roles: Full Tenant Admin (full CRUD across the platform), Read Only Admin (tenant-wide view), and Integration Admin (manage integrations). Members keep product-native access automatically. The platform never escalates access beyond what the source product allows. New product admins gain platform admin rights automatically. Every login, role change, integration action, and alert state is captured in centralised audit logs.
The four operational pillars
I’ll take these one at a time, since each carries a different amount of weight.
Global Inventory normalises every asset into one searchable view, refreshing every 24 hours and on change. You can filter by risk – PSIRT, End of Support, version drift, ownership, compliance. AI-powered Inventory Insights work with plain-language search and surface compliance signals, configuration changes, asset class and ownership. Crucially, these insights are rules-based, not LLM-guessed.
Unified Topology shows physical (Layer 1), logical (Layer 2/3), and overlay views (the overlay layer is caveated in the deck). Three zoom levels let you move from global overview to mid-level to controller deep-dive. Updates arrive in real time via push APIs and pub-sub, so state changes show in seconds, not polling cycles.
Alerts and Actions correlate signals across domains with recommended next steps. Alerts can be assigned. Lifecycle states are the same everywhere: New, Read, Active, Snoozed, Dismissed, Resolved. Correlation works by IP, site, MAC, time, device serial, and CVE or PSIRT ID.
Unified Licensing gives you one pane across every Cisco licence – SaaS subscriptions, Meraki co-term, and on-premises Smart Licensing. The platform auto-classifies posture as Underused, Fully Used, Overused, or Unknown. Filter by expiry windows (30, 60, 90 days) and drill into entitled versus consumed quantities.
AI Canvas
AI Canvas is described as the industry’s first multiplayer workspace for cross-domain agentic operations. I’ll get to what I make of that framing shortly; first, how it’s built. Cisco products feed Product MCP and Agents into Canvas Supervisor Agents, which correlate, reason, plan, and act. You ask anything in natural language; agents pull data, execute, and resolve end-to-end. A shared session means multiple operators see the same view, with context preserved across shift changes and escalations.
The workspace includes a conversational interface, agentic modes (Default for fast answers, Reasoning for deep investigation), and interactive widgets (topologies, charts, summaries, reports), plus activity timelines. Multi-modal reasoning lets you upload documents and attach images. Colour-coded board organisation helps scale. Cisco ships pre-built quick-start boards – Health & Availability, Wireless, WAN Health & Performance, Data Center & Compute Operations, Security Policy & Access, Discovery & Inventory. Custom boards are coming soon.
The distinction: Canvas is for investigation and exploration, minutes to hours, interactive and visual. AI Assistant is for quick conversational answers, seconds to minutes, text-based.
A “day in the NOC” scenario shows the practical flow. Before Cloud Control, poor call quality means logging into collaboration, observability, and networking tools separately, manually correlating timestamps, escalating to a war room. Hours pass. With Cloud Control, a related alert surfaces as one correlated incident. Canvas launches an investigation across domains. Canvas suggests a fix. The operator approves. Agents execute and confirm. Minutes instead of hours. Note the model: the operator approves before agents act. Agentic, not autonomous.

Figure 2 – The Canvas flow from the deck’s NOC scenario: supervisor agents correlate, reason and plan across domains, but execution waits for operator approval.
What’s actually interesting
Rules-based Inventory Insights rather than LLM-guessed ones is the bit I keep coming back to. I’d call that a deliberate trust choice: Cisco surfaces facts and leaves the judgement calls to the person doing the job, which is exactly how I want a NOC tool to behave. The human-approval step in the NOC flow runs on the same instinct. Canvas suggests a fix, the operator approves, agents execute and confirm, and nothing moves until a person says go. Agentic, in Cisco’s telling, still answers to a human.
Real-time topology via push and pub-sub, rather than polling, is a genuine engineering claim. Topology stays current without hammering APIs with constant requests, which matters more than it sounds once you’ve worked a topology view that was twenty minutes stale during an actual outage.
Then there are the caveats, and I’d rather deal with them plainly than skate past them. Cloud Control is US-hosted at launch, with other regions only on the roadmap, and if I were speccing this for a UK or EU estate, that’s the first thing I’d flag before I got excited about anything else, because data residency expectations don’t bend for a roadmap slide. Custom Canvas boards are coming soon rather than shipped, so for now you get Cisco’s curated set or nothing, and a handful of the integrations are indirect too: Catalyst Center arrives via Meraki Global Overview, Catalyst SD-WAN via Security Cloud Control, Nexus Dashboard via Intersight. None of that is disqualifying, but it matters if you go looking for a native pane that isn’t there. The overlay topology carries its own asterisk in the deck, and third-party reach beyond Splunk rests on an “and beyond”/MCP framing the deck doesn’t flesh out, so I wouldn’t count either of those as fully solved yet.
My honest read is that this is consolidation of Cisco’s own portfolio under one identity and data plane, described in agentic language. I don’t think that’s a criticism. It’s a fair thing to be, and it doesn’t need dressing up as more than that.
Would I use it?
The deck’s framing suggests value should appear the same day you connect. Whether that claim holds depends on your portfolio depth and the gaps you’re trying to close. It’s a unified starting point for the Cisco estate, with deep links into source products when needed.