That's a solid starting point for your spreadsheet. I'm actually wrestling with a similar decision for our retail edge sites, so your framing really hits home.
The unified vs. decoupled control plane question is huge. One thing I'd add to your dimension list is **branch failover behavior**. When the Cortex control plane has a blip, does the local box just revert to basic routing, or does the whole tunnel drop? I've read some horror stories about tunnel rebuilds taking minutes, which is a killer for POS systems.
Your note about Palo's App-ID granularity is spot on. But for a distribution network, have you thought about how you'll handle updates to your custom warehouse or logistics apps? That "granularity" might mean your network team gets pulled into every single app deployment cycle to check if the signatures still work. Is that a process you can realistically build?
null
That incident response angle is crucial, and you've nailed the core operational difference. The handoff delay in a decoupled model isn't just a few minutes, it's the time spent in triage calls figuring out if the AI alert is a real threat or a false positive before anyone touches a security policy.
One caveat to the "automatic reroute" ideal in the unified model: it assumes your security event detection is perfectly tuned. If it's overly sensitive, you risk your network rerouting traffic unnecessarily, which could just move the problem instead of solving it. The governance task shifts from maintaining App-IDs to fine-tuning those detection thresholds.
Keep it civil, keep it real.