top of page

The Enterprise Identity Paradigm Shift: How Five Transactions in Seven Days Priced AI Agent Governance

  • Writer: Nelson Advisors
    Nelson Advisors
  • 1 day ago
  • 12 min read
The Enterprise Identity Paradigm Shift: How Five Transactions in Seven Days Priced AI Agent Governance
The Enterprise Identity Paradigm Shift: How Five Transactions in Seven Days Priced AI Agent Governance


The enterprise security landscape experienced an unprecedented structural realignment during the week of July 27th, 2026. While public market attention was dominated by high profile investments in foundational model developers, such as Nvidia's $5 Billion commitment to Safe Superintelligence, a quieter, far more consequential capital allocation unfolded across the enterprise software ecosystem. Within a 72-hour window, major security acquirers and venture capital syndicates deployed over $1.37 Billion across five distinct transactions, all addressing a singular, emerging failure point: the security, identity governance, and runtime control of autonomous AI agents operating within enterprise networks.


This cluster of transactions occurred before the market had established a standardised nomenclature for the category. The exits of Oasis Security and Permiso Security to market incumbents, alongside massive private capital injections into Onyx Security, Inforcer, and Cantina, signal an industry-wide realisation that existing Identity and Access Management (IAM) and Data Security Posture Management (DSPM) architectures are structurally incapable of governing autonomous non-human actors.

Strategic Overview of the Late July 2026 Transactions


The five transactions executed between July 27th and July 31st, 2026, represent an uncoordinated yet unified bet by corporate acquirers and tier-one venture investors. Buyers and investors operated independently, yet arrived at identical conclusions regarding the urgency of non-human identity (NHI) governance and agentic control planes.


Target / Company

Acquiring Buyer / Lead Investor

Deal Type

Deal Valuation / Funding Amount

Core Technical Specialisation

Source

Oasis Security

Cyera

Acquisition (LOI)

$1.0 Billion (~$700M Cash + Stock)

Non-Human Identity (NHI) & Agentic Access Governance

Various

Permiso Security

Okta

Acquisition

~$200 Million (Mostly Cash)

Multi-Cloud Identity Threat Detection & Response (ITDR)

Various

Onyx Security

Bessemer Venture Partners

Series B

$113 Million ($640M Post-Money Val)

Enterprise AI Control Plane & Runtime Agent Monitoring

Various

Inforcer

Undisclosed (Series C Syndicate)

Series C

$50 Million

Microsoft Security & AI Management for MSPs

Various

Cantina

Framework Ventures

Stealth Launch / Seed

$8 Million ($16.5M Total Raised)

Automated Agentic Remediation & Post-Triage Fixes

Various


Detailed Deconstruction of the Five Capital Allocations


Cyera Acquires Oasis Security ($1.0 Billion)


Data security platform Cyera executed a letter of intent to acquire Israel-based Oasis Security for approximately $1 Billion, consisting of roughly $700 Million in cash and the remaining balance in Cyera equity. Founded in 2022 by Danny Brickman and Amit Zimerman, veterans of Israel’s elite military intelligence units (Talpiot and Unit 81), Oasis had previously raised $195 Million, including a $120 Million Series B led by Craft Ventures in early 2026.


The acquisition represents the first billion-dollar valuation assigned specifically to the non-human identity governance category. Cyera, which raised $600 Million at a $12 Billion valuation in June 2026 and generates over $200 Million in Annual Recurring Revenue (ARR), deployed its balance sheet to bridge data security with machine identity. Oasis provides real-time discovery, context assignment, and lifecycle governance for service accounts, API keys, OAuth tokens, and autonomous AI agents across IaaS, PaaS, SaaS and on-premises infrastructure.


Under the integrated architecture, Cyera’s core data classification engine pairs directly with Oasis’s identity governance layer. While Cyera determines the sensitivity and location of enterprise data, Oasis establishes the identity context, permissions, and behavioral parameters of the software entities attempting to reach that data. Merging these capabilities creates a single control system that decides what every human, machine, and autonomous agent can see and execute across the enterprise.


Okta Acquires Permiso Security (~$200 Million)


Within 48 hours of the Cyera-Oasis agreement, market-dominant enterprise identity vendor Okta announced a definitive agreement to acquire Permiso Security for approximately $200 Million in an all-cash transaction. Permiso, co-founded by former FireEye executives Paul Nguyen and Jason Martin, built an Identity Threat Detection and Response (ITDR) engine that monitors runtime behaviors across multi-cloud environments.


The acquisition integrates Permiso's 2,500+ research-driven identity risk signals and its specialized runtime capabilities into Okta’s core platform. Crucially, Okta acquired Permiso’s dynamic "SandyClaw" sandbox. SandyClaw isolates and evaluates AI agent skill sets, Model Context Protocol (MCP) servers, prompts, and external plugins prior to runtime execution, preventing malicious payloads or untrusted supply chain dependencies from compromising the agent's identity context.


Onyx Security Raises $113 Million Series B ($640 Million Valuation)


Led by Bessemer Venture Partners, with participation from Cyberstarts, TCV, Conviction, FirstMark, Vintage, QuantumLight, and G Squared, Onyx Security closed a $113 Million Series B funding round. The round valued the two-year-old startup at $640 Million, just four months after it emerged from stealth with a fourfold increase in revenue.


Co-founded by Maxim Bar Kogan (former Unit 8200 officer) and Gil Elbaz, Onyx operates as a real-time AI control plane. Unlike passive governance tools, Onyx uses proprietary models to evaluate an AI agent's reasoning chain step-by-step. If an agent attempts an unauthorized action, exhibits non-deterministic drift, or experiences prompt injection or memory poisoning, Onyx’s "Guardian Agent" intervenes at runtime to block, correct, or escalate the action.


Inforcer Raises $50 Million Series C


London-based Inforcer secured $50 Million in Series C financing to scale its automated Microsoft security and AI management platform. Coming 12 months after a $35 Million Series B, Inforcer’s rapid capital expansion targets Managed Service Providers (MSPs). As small- and medium-sized businesses (SMBs) rapidly turn on native AI agents within their Microsoft 365 and Azure environments, they lack in-house security teams to configure governance policies. Inforcer automates the policy enforcement and configuration baseline layer across multi-tenant MSP environments, preventing misconfigured AI agents from inheriting tenant-wide admin rights.


Cantina Emerges from Stealth with $8 Million ($16.5 Million Total Raised)


Cybersecurity startup Cantina launched from stealth with an $8 Million round led by Framework Ventures, bringing its total capitalisation to $16.5 Million. Founded by security researchers with experience at Coinbase, Mastercard, and UBS, Cantina addresses the post-discovery vulnerability bottleneck. Recognizing that AI capabilities are accelerating vulnerability discovery beyond human patching capacity, Cantina deploys autonomous AI agents to triage, prioritise, generate code fixes and verify remediation steps across complex codebases at machine speed.


Structural Drivers: The Proliferation of Non-Human Identities


The simultaneous capital deployments in late July 2026 stem from a systemic breakdown in modern network architecture: the ratio of human to non-human entities operating inside enterprise environments has inverted beyond the capacity of legacy identity systems.


Historically, enterprise Identity and Access Management (IAM) was architected around human employees authenticating through Single Sign-On (SSO), multi-factor authentication (MFA), and static role-based access control (RBAC). Modern cloud-native adoption, microservices, and autonomous software agents have rendered this human-centric perimeter obsolete.


Data from the Cloud Security Alliance (CSA) indicates that non-human identities outnumber human identities by an average ratio of 45:1 across global enterprises. In cloud-native environments, this ratio climbs to 144:1, and in the densest microservice deployment architectures, it exceeds 500:1. Institutional audits demonstrate the scale of this disparity; for example, an audit of a Fortune 500 financial institution logged over 4.2 million non-human identities against a human workforce of 50,000. Furthermore, non-human identities associated with AI agents expanded by nearly 500% within Fortune 500 environments over the six months preceding mid-2026, making them the fastest-growing account category in enterprise computing.


Over 28.65 Million hardcoded secrets were exposed in public code repositories in 2025 alone, a 34% single-year increase. Within this set, secrets tied to AI infrastructure, such as API tokens, vector database keys, and LLM service credentials, grew by 81% year-over-year to 1.27 Million exposed credentials. Legacy identity tools assume human interaction patterns characterized by deterministic access paths, predictable working hours, manual approval tickets, and long-lived sessions. AI agents, by contrast, execute thousands of non-deterministic actions per minute, perform dynamic tool integrations, and initiate cross-domain data retrievals, leaving traditional security teams blind to their operation.


Metric / Governance Dimension

Industry Benchmark / Empirical Data

Operational Implication

Source

CISO NHI Defense Confidence

15% express high confidence

85% of security leaders admit vulnerability to non-human identity exploits.

Various

Legacy IAM Adequacy for AI

8% express high confidence

92% view existing identity architectures as incapable of governing AI agents.

Various

Shadow AI & Breach Correlation

Shadow AI present in 43% of breaches

Ungoverned AI adoption adds over $1M in average incident cost.

Various

Gartner AI Breach Forecast

25% of enterprise breaches by 2028

One in four security incidents will originate from compromised or rogue agents.

Various

Macro Venture Capital Shift

$8.1B in 2026 YTD vs $324M in 2025

A 25-fold year-over-year surge in agentic AI governance capital allocations.

Various


Technical Architecture of Agentic Governance and Control Planes


Securing an enterprise environment populated by autonomous agents requires shifting from static credential management to dynamic, runtime access control. The technologies acquired or funded during the week of July 27th, 2026, illustrate an emerging five-layer technical stack designed for agentic AI security.

The foundational layer consists of Data and Identity Discovery, exemplified by Cyera and Oasis, which establishes real-time visibility over non-human identity sprawl, uncovers hidden secrets, assigns ownership, and correlates credentials with underlying data sensitivity. Operating directly above discovery is Dynamic Provisioning and Least-Agency Brokering, which replaces permanent static service accounts with task-bounded, short-lived tokens and Zero-Standing Privilege (ZSP) frameworks.


The third layer introduces Runtime Threat Detection and Sandboxing, pioneered by Permiso and Okta, which isolates agent skill sets, Model Context Protocol (MCP) servers, and external plugins in secure sandboxes to analyse execution paths before deployment.


The fourth layer is the Inline Reasoning Control Plane, spearheaded by Onyx Security, which uses proprietary supervisory models to monitor an agent's step-by-step reasoning chain, intervening instantly if prompt injection, memory poisoning, or policy drift occurs.


Finally, the stack closes with Automated Remediation, represented by Cantina, which uses autonomous agents to triage, generate verified code patches and resolve security vulnerabilities at machine speed.


Architectural Dimension

Legacy Identity & Access Management (IAM)

Agentic Access Management (AAM) & Runtime Control

Source

Principal Type

Human employees, deterministic service accounts

Autonomous AI agents, sub-agents, dynamic workloads

Various

Authentication Vector

Usernames, passwords, hardware MFA, static API keys

Ephemeral tokens, cryptographic workload attestation

Various

Authorization Granularity

Static Role-Based Access Control (RBAC)

Dynamic Attribute-Based & Reasoning-Aware Control

Various

Session Lifetime

Hours, days, or permanent static credentials

Task-bound, ephemeral (expires instantly post-execution)

Various

Behavioral Expectation

Deterministic (predictable, repeatable paths)

Non-deterministic (probabilistic model reasoning)

Various

Inspection Plane

Boundary ingress/egress, authentication logs

Runtime evaluation of reasoning steps, prompts, MCP tools

Various

Threat Vectors

Phishing, credential stuffing, session hijacking

Prompt injection, memory poisoning, sub-agent delegation drift

Various


Key Technical Mechanisms


Zero-Standing Privilege (ZSP) and Ephemeral Credential Brokering


Standard service accounts frequently operate with permanent, high-privilege credentials embedded in code or configuration files. Agentic Access Management enforces a Zero-Standing Privilege architecture. When an AI agent is invoked to complete an operational workflow, such as compiling a quarterly financial report, a centralised identity broker issues a temporary, scoped token. This token grants access restricted exclusively to the specific database tables required for that exact task. The moment the task completes, or if a short timeout threshold is reached, the token is automatically revoked across all touched environments, returning the agent's baseline standing privilege to zero.


Runtime Reasoning Inspection and Step-Level Enforcement


Pioneered by control plane platforms like Onyx Security, runtime inspection introduces inline proxying of LLM inference chains. As an agent plans its execution path, decomposing a high-level goal into sequential API calls, the control plane evaluates each reasoning step against organisational security policies. If an agent experiences a prompt injection attack or operational drift and attempts to exfiltrate customer data to an unapproved external endpoint via Model Context Protocol (MCP), the control plane detects the unauthorised step. A specialised Guardian Agent intercepts the call in real time, blocking the specific exfiltration attempt and correcting the agent's execution path without crashing the surrounding application workflow.


Dynamic Tool Chain Sandboxing


Okta’s acquisition of Permiso’s SandyClaw sandbox specifically targets the security vulnerabilities inherent in dynamic skill integration. Modern AI agents dynamically load third-party tools, prompt templates, and execution plugins at runtime to fulfill complex user instructions. SandyClaw executes these external inputs inside an isolated sandbox environment prior to runtime integration. By evaluating the tool's underlying code paths, API requests and dependency calls for hidden exfiltration routines or prompt injection payloads, the sandbox verifies the safety of the tool chain before granting the agent access to operational enterprise systems.


Strategic Market Dynamics and Emergent Insights


The concentration of acquisition capital and venture funding during late July 2026 highlights broader market shifts across the enterprise software and security landscape.


The Data-Identity Convergence Paradigm

Cyera’s acquisition of Oasis Security demonstrates a shift in cybersecurity market strategy: data security platforms cannot protect sensitive data without controlling the non-human identities accessing it. Historically, Data Security Posture Management (DSPM) operated separately from Identity Governance and Administration (IGA). DSPM identified where sensitive information resided, while IGA managed human access rights.


However, in an agentic enterprise, non-human software entities create, duplicate, relocate and transform data autonomously. By integrating Oasis’s agentic identity management into Cyera’s data classification engine, Cyera established a unified control system. This combined architecture evaluates access requests based on real-time data classification, agent intent, and credential risk posture simultaneously.


The Attribution Gap and Delegation Chain Risk


A major security risk driving capital into non-human identity governance is the Attribution Gap in multi-agent workflows. When a human employee authorises a primary AI agent to execute a task, that primary agent frequently delegates sub-tasks to downstream, specialised sub-agents. For example, an executive assistant agent might task a scheduling agent, a data scraping agent and a financial modelling agent to complete a project.


Without agentic identity governance, downstream sub-agents execute API calls using either a shared, highly privileged service account or the inherited identity context of the original human user. If a sub-agent suffers a prompt injection attack or makes an unauthorised data modification, traditional audit logs attribute the action entirely to the human user or the broad service account.

This creates an attribution gap that makes post-incident investigation impossible. Governance platforms address this vulnerability by requiring context propagation across the entire delegation chain, ensuring every sub-agent action is cryptographically signed and tied back to both the parent agent and the originating user request.


Vulnerability Inflation vs. Agentic Remediation


The $8 Million seed funding for Cantina points to a critical operational imbalance: AI models are discovering software vulnerabilities faster than human engineering teams can patch them.


Anthropic's "Project Glasswing," utilising advanced Claude models, identified over 1,596 critical vulnerabilities across major operating systems and web browsers, generating 9 zero-day CVEs entirely through automated analysis.

Furthermore, Anthropic's designation as a CVE Numbering Authority (CNA) in late July 2026 highlights the industrial scale of AI-driven bug discovery. Conversely, the 2026 Verizon Data Breach Investigations Report revealed that enterprise remediation of known critical vulnerabilities dropped from 38% to 26% year-over-year, driven by human developer burnout and overwhelming alert backlogs.


This divergence produces Vulnerability Inflation, where the window between flaw discovery and active exploitation collapses to hours. Because human security teams cannot keep pace with AI-generated discovery volume, defense must also become agentic. Cantina’s model demonstrates that autonomous remediation agents are now required to triage, generate synthetic code patches, and verify fixes at machine speed to close exposure windows before attackers exploit them.


Strategic Recommendations for Enterprise Security Leaders


The capital movements of late July 2026 demonstrate that securing AI adoption requires immediate changes to enterprise security strategy. Chief Information Security Officers (CISOs) and enterprise architects must transition from human-centric security postures to unified identity and runtime control frameworks.


First, organisations must perform an immediate non-human identity audit across all cloud environments, SaaS applications, and on-premises infrastructure. Security teams should deploy automated discovery tools to locate all unrotated service accounts, hardcoded API keys, and unmapped OAuth tokens. Every non-human identity must be mapped to an explicit human sponsor, business owner, and workload context, while removing all orphaned credentials and shadow AI deployments.


Second, enterprise identity architectures must deprecate standing privileges for software accounts, shifting entirely to ephemeral, task-scoped access controls. Security teams should enforce Zero-Standing Privilege (ZSP) frameworks supported by dynamic credential brokers. Credentials issued to AI agents must be restricted to the exact resources required for the active task and set to expire automatically upon task completion. Furthermore, explicit human-in-the-loop (HITL) authorization steps must be enforced for high-risk operations, such as wire transfers, bulk data exports, or production infrastructure changes.


Third, security architectures must deploy inline runtime control planes and tool chain sandboxing for all generative AI and agentic deployments. Implementing dynamic sandboxing allows organizations to isolate third-party agent skills, prompts, and Model Context Protocol (MCP) integrations, inspecting their execution paths prior to operational integration. Simultaneously, step-level reasoning controls should be deployed to monitor agent inference chains inline, detecting and neutralising prompt injection attempts, memory poisoning, or behavioural drift at runtime.


Fourth, enterprise architects must enforce cryptographic delegation chain tracing across all multi-agent framework deployments. Orchestration systems must be configured to pass the originating principal’s identity context through every downstream sub-agent delegation step. Organisations should mandate structured, immutable audit logging that captures the originating user, intermediate sub-agent identities, invoked tools, passed parameters, and execution outcomes, ensuring complete visibility and auditability across complex agentic workflows.


Nelson Advisors > European HealthTech, MedTech, Digital Health Investment Banking

 

Nelson Advisors specialise in Mergers and Acquisitions, Partnerships and Investments for Digital Health, HealthTech, MedTech, Health IT, Consumer HealthTech, Healthcare Cybersecurity, Healthcare AI companies.www.nelsonadvisors.co.uk


Nelson Advisors regularly publish Thought Leadership articles covering market insights, industry trends, deal commentary, market analysis & predictions @ https://www.healthcare.digital 


Nelson Advisors publish Europe's Leading Healthcare Technology Investment Banking Newsletter every week, join 5000+ HealthTech and MedTech subscribers today! https://lnkd.in/e5hTp_xb 


Nelson Advisors pride ourselves on our DNA as ‘Founders advising Founders.’ We partner with entrepreneurs, boards, corporates, venture capital and private investors to maximise shareholder value and investment returns.www.nelsonadvisors.co.uk



Nelson Advisors LLP

 

Hale House, 76-78 Portland Place, Marylebone, London, W1B 1NT




Meet Nelson Advisors @ 2026 Events

 

Digital Health Rewired > March 2026 > Birmingham, UK 

 

NHS ConfedExpo  > June 2026 > Manchester, UK 

 

HLTH Europe > June 2026, Amsterdam, Netherlands

 

HIMSS AI in Healthcare > July 2026, New York, USA

 

Bits & Pretzels > September 2026, Munich, Germany  

 

World Health Summit 2026 > October 2026, Berlin, Germany

 

HealthInvestor Healthcare Summit > October 2026, London, UK 


HLTH USA 2026 > October 2026, USA

 

Barclays Health Elevate > October 2026, London, UK 

 

Web Summit 2026 > November 2026, Lisbon, Portugal  

 

MEDICA 2026 > November 2026, Düsseldorf, Germany

 

Venture Capital World Summit > December 2026 Toronto, Canada


Nelson Advisors specialise in Mergers and Acquisitions, Partnerships and Investments for Digital Health, HealthTech, MedTech, Health IT, Consumer HealthTech, Healthcare Cybersecurity, Healthcare AI companies.www.nelsonadvisors.co.uk
Nelson Advisors specialise in Mergers and Acquisitions, Partnerships and Investments for Digital Health, HealthTech, MedTech, Health IT, Consumer HealthTech, Healthcare Cybersecurity, Healthcare AI companies.www.nelsonadvisors.co.uk

bottom of page