Today we're introducing Cortex XCOR Real User Monitoring (RUM). It brings real user monitoring for web and mobile apps, along with synthetic monitoring, into Cortex XCOR, where it connects directly to the metrics, logs, and traces your teams already depend on. For the first time at Cortex XCOR, what a customer experiences on their phone or in their browser and what the services behind it are doing live in the same place.
These capabilities come from Embrace, which built its platform on a simple idea: observability should start with the user. That idea matters more every month. Software is being written faster than ever, by more authors than ever, some of them human and some of them AI. It is being used by a wider range of users than ever, and some of those aren't human either. Each of those shifts raises the same question: who is your software for, and how well is it working for them?
The answer always shows up in the same place: the moment someone (or something) tries to get something done in your application. That moment is what Cortex XCOR RUM is built to see.
Healthy services, unhappy users.
Seeing that moment starts with a strong foundation. Infrastructure and backend observability tells you whether your systems are healthy: which services are slow, which are throwing errors, where capacity is running thin.
Foundations exist to hold something up, though, and for most businesses what they hold up is a customer experience. That experience depends on your backend and on everything your backend can't see: the device in the customer's hand, the network they're on, their browser and OS version, the third-party scripts on the page, the memory pressure on a three-year-old phone. The front end carries more surface area and more variability than any service in your cluster.
That's how a team can watch a wall of green dashboards while a release adds 800 milliseconds to Android app startup in one region, or a third-party tag stalls checkout on Safari. Every service met its SLO. Customers still abandoned.
Aggregates can widen the gap because they flatten people. A p95 latency tells you how a service performed. It says very little about which customers gave up, what they were trying to do, or why.
Backend telemetry answers whether your systems are healthy. Experience data answers whether your users succeeded. Businesses that run on digital revenue need both answers, connected. That's the idea behind user-focused observability: start from a real user's session and trace back to the cause, across front end and back end, in one place.
Where milliseconds turn into revenue.
The cost of that gap shows up fastest wherever customers transact. For retailers, travel companies, banks, and media businesses, the digital experience is the storefront, and its speed has a price. In a study of 37 brands and more than 30 million sessions, Google, 55, and Deloitte found that a 0.1 second improvement in mobile site speed lifted retail conversion by 8.4% and travel conversion by 10.1%.1 In competitive markets, the distance between leaders and everyone else is often measured in fractions of a second, and those fractions compound across millions of sessions.
Capturing that value takes more than knowing a problem exists. Teams have to get from symptom to cause to fix quickly, with evidence the business trusts. Here's what that looks like in Cortex XCOR, using a familiar scenario: mobile checkout conversion dips the morning after a release.
Spot it. RUM shows the drop and where it's concentrated, by app version, device, OS, region, and network type, alongside app startup time, ANRs, and crash rates (and for web, Core Web Vitals like LCP and INP). Because the data is both high cardinality and high fidelity, you can slice by the dimensions that matter to this incident, instead of the ones someone chose to pre-aggregate months ago.
Isolate it. Open an affected user session and see the exact sequence that led to abandonment: taps, screen loads, network calls, logs, spans, and errors on a single timeline.
Trace it. The slow network call in that session links to its backend trace in Cortex XCOR, down to the service or dependency responsible. Front-end and back-end teams work from the same evidence.
Prevent it. Synthetic tests on your critical journeys, from uptime and API checks to full web performance tests, catch the next regression before customers do. We're continuing to invest here to build the next generation of synthetic testing.
Prove it. Tie the fix back to the conversion rate that started the investigation, so the business can see what the work was worth.
Every release is a hypothesis about your users, and real user data is how you learn whether it held. When issues do arise, teams need practitioner-grade tools with deep diagnostic capabilities to fix problems, ship optimizations, and continue the cycle of innovation. That discipline has always mattered, but it matters even more now because of who is writing the code.
Software written by machines, experienced by people.
As we’re all aware by now, code is increasingly written by AI. Developers say about 42% of the code they commit is now generated or assisted by AI, and they expect that share to reach roughly 65% by 2027.2 The same survey found that 96% of developers don't fully trust that code, and fewer than half always verify it before committing.2
Put those numbers side by side and a tension surfaces. Release velocity is rising while the number of people who deeply understand any given code path is falling. Tests can confirm that code does what it was asked to do. They can't show how it behaves on a mid-range Android phone on a crowded train, or inside a checkout carrying a dozen third-party scripts.
For a growing share of code, the first real review happens in production. That makes the real user's experience the most reliable quality signal an engineering organization has, and it means observability has to meet software where it lands: with the people using it. But who those users are is changing, too.
The definition of a user is expanding.
AI agents now browse, compare prices, fill carts, and complete transactions on people's behalf. Some act for your customers. Some scrape your content. Some are hostile. Many never execute JavaScript, so client-side tools miss them entirely, and traditional analytics file whatever traces they leave as noise.
That leaves every digital business with three new questions. How is this agent experiencing my application? Is it succeeding? Should it be here at all?
The first two are observability questions. The third is a security question. Answering all three will take front-end and back-end visibility working together, and that is exactly the intersection where observability and security now meet at Palo Alto Networks.
The stakes run in both directions. If an agent is choosing where to buy on someone's behalf, speed, reliability, and even accessibility may start to work like ranking factors, in ways that are much harder to notice than a customer's frustrated exit. And because every agent ultimately acts for a person, a failed agent transaction is still a failed human outcome.
What user-focused means from here.
So who is your software for? The answer has grown to include the people you serve, the agents acting for them, and the business that depends on both. Where success gets decided has stayed the same: at the point of use, in the experience.
That's why digital experience monitoring is part of Cortex XCOR. The user layer joins a cloud-native foundation built to handle metrics, logs, and traces at scale, so teams can follow a single interaction from a customer's tap to the service that answered it and back again. The result is end-to-end visibility.
It's also why this work belongs at Palo Alto Networks. AI is changing how software is built and used faster than any shift most of us have seen, and people still need to be safe and well served while it happens. Seeing the experience clearly is how you deliver both.
See Cortex XCOR Digital Experience Monitoring in action. Request a demo.
Appendix: Sources
- Google, 55, and Deloitte, “Milliseconds Make Millions,” case study on web.dev. https://web.dev/case-studies/milliseconds-make-millions
- Sonar, “State of Code Developer Survey report: The current reality of AI coding,” January 2026. https://www.sonarsource.com/blog/state-of-code-developer-survey-report-the-current-reality-of-ai-coding/