# The Race to Own the AI Agent Identity Stack Just Got Serious
When Cyera announced its acquisition of Oasis Security, the press release talked about "holistic data security" and "the agentic era." What it didn't say plainly: enterprises are deploying AI agents that can read files, query databases, and call APIs autonomously — and most of them have no idea what credentials those agents are using, who issued them, or whether they've been compromised.
That's the actual problem Cyera just paid to solve.
## Machine Identities Were Already a Mess Before AI
Security teams have been losing ground on non-human identities (NHI) for years. Service accounts, API keys, OAuth tokens, CI/CD pipeline credentials — the average enterprise environment has somewhere between 10 and 50 machine identities for every human identity. They're provisioned fast, rarely rotated, almost never audited, and frequently over-privileged.
The traditional response was to bolt NHI management onto Privileged Access Management (PAM) tools — products designed in an era when a machine identity meant a Windows service account. That worked well enough when the machines were servers running predictable workloads. It doesn't work when the "machine" is an LLM-backed agent that dynamically decides to query a Snowflake warehouse, write to a SharePoint document, or call a Stripe API endpoint based on a user's request.
Oasis Security built specifically for this gap. Their platform discovers NHIs across cloud environments, tracks usage, flags orphaned credentials, and integrates with the identity providers enterprises already use. The company had been one of the better-funded bets in the NHI space — a category that's attracted serious venture money from firms who recognized that machine identity would become an attack surface before defenders were ready.
## What Cyera Brings to the Table
Cyera's core product is data security posture management (DSPM): they scan cloud environments to find where sensitive data lives — PII in S3 buckets, credit card data in databases, credentials in config files — and map who and what has access to it.
That's a fundamentally complementary problem to what Oasis solves. DSPM tells you what data an identity *can* reach. NHI security tells you whether that identity is properly controlled, rotated, and monitored. In isolation, each is useful. Together, they answer the question defenders actually care about: does this AI agent have access to sensitive customer data, and is that agent's identity secured?
The acquisition makes the merged entity one of the few players capable of offering that end-to-end answer. Right now, most security teams are operating in silos — their DSPM tool doesn't talk to their secrets manager, which doesn't talk to their identity governance system, which doesn't have any concept of an AI agent at all.
## The Agentic Timing Isn't Accidental
This deal lands at a specific inflection point. Enterprise AI deployments shifted meaningfully in the past 18 months from "AI that answers questions" to "AI that takes actions." Salesforce Agentforce, Microsoft Copilot with autonomous capabilities, dozens of custom LangChain and AutoGen deployments — these systems aren't just reading data, they're writing to it, moving it, sharing it.
Each of those agents needs a credential to do its work. Those credentials are being issued faster than security teams can track them. When an agent needs to access a CRM, it gets a service account. When it needs to call an external API, it gets a key. When it needs to write to a document store, it gets a token. In a large enterprise running dozens of AI workflows, you can accumulate hundreds of these identities in weeks — most of them with more access than they actually need, because it's easier to provision broad permissions than to scope them carefully.
The supply-side pressure is real. Oasis competitors — Entro, Astrix, Clutch, Silverfort on the broader identity side — have all been either raising rounds or rumored as acquisition targets. Every major security platform wants to own the NHI layer before it becomes the dominant attack vector of the next five years.
Cyera moving now, before the market fully consolidates, is the right call.
---
## HackWire Analysis
The story other coverage is missing here is about what this acquisition signals for the rest of the DSPM market — and it's not flattering for the incumbents.
For years, data security posture management was sold as a standalone capability. Find your sensitive data, map access paths, generate compliance reports. That was enough when the access paths were humans with browser sessions or scheduled ETL jobs. The moment agentic AI enters the picture, "map access paths" becomes substantially harder: the access paths are now dynamic, short-lived, created by systems that can spin up new credentials without human approval, and executed by agents that may chain multiple actions in a single workflow.
Cyera acquiring Oasis is essentially an admission that DSPM without NHI security is incomplete — you can't know whether your data is protected if you don't understand the full population of machine identities that can reach it. That's a gap that puts every standalone DSPM vendor in a difficult position: either make similar acquisitions quickly, or cede the enterprise market to platforms that can answer the complete question.
For defenders, the immediate priority isn't waiting for the combined Cyera/Oasis platform to ship. The gap is now. Audit what credentials your AI deployments are using today. Check whether they're rotated on any schedule. Verify the scope of access each one has — my guess is most teams will find service accounts with permissions that made sense during development and were never tightened for production. Before your next agentic AI rollout, that cleanup isn't optional.
The broader pattern: identity has always been the front door for attackers. For two decades, the fight was over human identity. The next decade will be fought over machine identity, and the orgs that treat it as an afterthought are going to provide very good case studies for everyone else.
— HackWire Editorial
---
## Related Coverage