It's a fair question. The box *could* manage itself. Your toaster doesn't need a separate toaster management console.
But then you'd have just another box. The point of separating the management plane is to make the firewall itself a dumb, hardened packet processor. You manage *policies*, not devices. Push a policy from a central brain to a fleet of enforcement points.
The real reason? It's a classic vendor lock-in architecture. You now need to license, maintain, and secure their proprietary management server, which only talks to their firewalls. It's a whole extra VM, with its own database and upgrade headaches. Suddenly migrating away isn't about swapping a box; it's about rebuilding your entire policy and management workflow from scratch.
Ask what happens if the management server goes down. The firewalls keep running with the last policy. Then ask what happens when you want to use a different vendor's analyzer or a custom orchestrator. You can't.
Your vendor is not your friend.