SASE Copilot

SASE Copilot provides AI-assisted search and contextual help within Orchestrator, enabling users to understand their SD-WAN and SASE environment, interpret system state, and navigate product documentation. The capability is designed to augment, not replace, existing Orchestrator workflows.

NOTE: SASE Copilot is delivered as a cloud service and is available only on cloud-hosted Orchestrator. It is not available on on-premises (self-hosted) Orchestrator deployments.

IMPORTANT: SASE Copilot answers only from its indexed knowledge base. If information is not available, it may be unable to provide a complete answer or may return a partial response. SASE Copilot is powered by AI, so mistakes are possible. Review all output carefully before use.

When using SASE Copilot:

  • Expect strong results for documentation-backed “what is” and “explain” questions, and for the curated workflows described in Curated Workflows.
  • Open-ended operational questions may be answered only in part, because the curated workflows and prompts cover a subset of everything the system can do. This coverage continues to expand over time.
  • Do not rely on it as a replacement for advanced operational runbooks.
  • Treat answers as contextual assistance, validated against official documentation when performing changes.

Availability

SASE Copilot is delivered as a cloud service and is updated on its own cadence, separate from the Orchestrator software release cycle. New SASE Copilot capabilities can become available between Orchestrator releases. The documentation is also updated regularly.

To discover the current capabilities at any time, open the SASE Copilot panel and ask a general question, such as:

What are your capabilities?

SASE Copilot responds with a summary of what it can currently help you do, reflecting the most recent updates to the service.

Curated Workflows

SASE Copilot uses a set of curated internal workflows to interpret and respond to user questions. Each workflow is optimized for a specific class of questions and determines how the system retrieves information and generates responses.

For most questions, workflow selection is handled automatically. However, there are two exceptions: hop-by-hop path analysis and tunnel troubleshooting. These workflows are not launched from the SASE Copilot panel; instead, you launch them from a specific Orchestrator page by clicking the SASE Copilot icon (SASE Copilot icon). See How Do I Launch SASE Copilot?

Workflow Categories

Examples of curated workflow categories include the following:

  • Documentation workflow—Answers questions that map directly to published SD-WAN and Orchestrator documentation.
  • Network health workflow—Addresses questions related to the interpretation of network state, health indicators, and system behavior as reported by Orchestrator.
  • License summary workflow—Provides structured, summary-style responses related to licensing information.
  • Path or hop-by-hop analysis workflow—Supports structured visualization and analysis of traffic paths, including LAN and WAN routing, overlays, security, and per-hop performance details. This workflow is launched from the Flows page by clicking the SASE Copilot icon. See How Do I Launch SASE Copilot?
  • Tunnel troubleshooting workflow—Supports structured diagnostic analysis of tunnel state, errors, and performance. This workflow is launched from the Tunnels page by clicking the SASE Copilot icon. See How Do I Launch SASE Copilot?

How Do I Launch SASE Copilot?

You can access the SASE Copilot icon (SASE Copilot icon) from two places in the Orchestrator interface:

  • To the right of the search box at the top of the screen, where it opens the SASE Copilot panel.

  • Within specific monitoring and configuration grids, where it launches a workflow scoped to the row you select.

The hop-by-hop path analysis and tunnel troubleshooting workflows are launched only from this icon on their respective pages. They are not available from the Copilot panel prompt suggestions and cannot be initiated as free-text questions.

Workflow Where to find the icon How to launch
Hop-by-hop path analysis Flows tab, in the AI Insights column Select the flow you want to analyze, then click the SASE Copilot icon in that row.
Tunnel troubleshooting Tunnels tab, in the Troubleshooting column of the underlay tunnels grid Select the underlay tunnel you want to troubleshoot, then click the SASE Copilot icon in that row.

NOTE: The SASE Copilot icon appears in these tables only when SASE Copilot is enabled, and you are signed in with Read & Write permissions or as an administrator.

Enable SASE Copilot

SASE Copilot is disabled by default. An administrator must explicitly enable the feature before it can be used. Enabling SASE Copilot allows Orchestrator to send user queries and related context to an AI service to generate responses within Orchestrator.

Before You Begin

  • You must be signed in to Orchestrator with Read & Write permissions or as an administrator.
  • You must review and accept the SASE Copilot Terms of Use during the enablement process.

Launch SASE Copilot

  1. Sign in to Orchestrator with Read & Write permissions or as an administrator.

  2. Click the SASE Copilot icon (SASE Copilot icon) to the right of the search box at the top of the screen.

    The SASE Copilot panel opens.

    NOTE: The Copilot interface may be visible even when the feature is disabled, but access is restricted until enablement is complete.

  3. When prompted, review the Terms of Use.

    The Terms of Use covers five sections: Scope and Acceptance, Use of AI Technology, User Responsibilities, Safety and Security, and Modification and Termination. A View Data Privacy Policy link is provided. You must review the entire document before the accept button becomes available.

  4. Click Accept Terms and Enable SASE Copilot.

    This action accepts the Terms of Use and enables SASE Copilot for all authorized users on this Orchestrator instance.

After you accept the Terms of Use, SASE Copilot becomes available to authorized users.

NOTE: If you choose not to enable SASE Copilot at this time, the feature remains disabled, and no AI queries are processed.

Re-enable SASE Copilot

Disabling SASE Copilot does not prevent it from being re-enabled later. Only users with Read & Write permissions or an administrator can enable or disable SASE Copilot. If SASE Copilot is disabled or was not accepted during the initial prompt, you can re-enable it using the procedure below.

To re-enable SASE Copilot:

  1. Sign in to Orchestrator with Read & Write permissions or as an administrator.

  2. Navigate to Orchestration > SASE Copilot.

  3. On the SASE Copilot page, locate the Enable SASE Copilot toggle switch.

  4. Set the toggle to ON.

After enabling, SASE Copilot is available for use by authorized users.

Permissions and Roles

Access to SASE Copilot is controlled by Orchestrator roles. Only users with Read & Write permissions or administrators can use SASE Copilot. Read-only users cannot access SASE Copilot.

Read & Write and Administrator Roles

Users with Read & Write permissions or administrators:

  • Can enable or disable SASE Copilot.
  • Can review and accept the Terms of Use during the enablement process.
  • Can use SASE Copilot after it is enabled.
  • Can access chat history, clear context, and submit response feedback.

Read-Only Roles

Users with a read-only role:

  • Cannot access SASE Copilot.
  • May see the SASE Copilot interface entry point, but all queries and chat history requests are blocked.
  • Receive a permissions error if they attempt to use the feature.

Operational and Important Behavior

  • SASE Copilot operates in read-only mode with respect to Orchestrator configuration.
  • The AI service does not make configuration changes or apply actions automatically.
  • Enabling SASE Copilot does not grant additional privileges beyond a user’s existing role.

Chat Management

When SASE Copilot is open, users with Read & Write permissions or administrators have access to the following controls in the Copilot panel header.

Display Mode

You can display SASE Copilot in two modes: docked and undocked.

  • Docked mode—SASE Copilot opens as a panel on the right side of the Orchestrator interface.
  • Undocked mode—SASE Copilot opens as a floating window. To switch to undocked mode, click the Undock icon in the panel header.

Orchestrator stores your display mode preference in the browser, allowing it to persist across sessions.

Clear Context

Click Clear context to close the current chat session and start a new one. Use this option to begin a fresh conversation without context carried over from previous questions.

Chat Refresh

Click Chat refresh to reload the conversation history from the server. Use this option if the conversation appears out of sync or to restore chat history after navigating away.

Response Feedback

After SASE Copilot returns a response, you can submit feedback using the thumbs-up or thumbs-down icons. You can add an optional text comment before submitting your feedback. Feedback is used to improve response quality.