Cyera: Non-Human Identities Grew 480% in Six Months. Most Companies Have No Idea What They're Doing.

Cyera: Non-Human Identities Grew 480% in Six Months. Most Companies Have No Idea What They're Doing.

BackerLeader 44 238 421
calendar_todayschedule5 min read

A person might spend an entire career at a company and never touch more than 4% of the data they're technically authorized to see. An AI agent inheriting that same person's permissions will use all of it, the first time a task calls for it.

That gap — between what an identity is allowed to access and what it actually does with that access — is the problem Cyera is going after with three moves ahead of Black Hat USA 2026: a letter of intent to acquire non-human identity provider Oasis Security, a new product called Agent Guardian, and an expanded endpoint security capability. Christy Hart Smith, Cyera's global director of analyst relations, framed the underlying question behind all three the same way: "Can this identity — whether it is human, machine, or AI agent — access this specific piece of data right now for this purpose? And should we let it?"

The number driving the urgency: non-human identities inside Fortune 500 companies grew 480% in the last six months alone. That's not security teams spinning up more service accounts, Hart Smith said — it's AI agents, coding assistants, copilots, and autonomous workflows, deployed faster than anyone can review them, each one inheriting a human's permissions the day it goes live.

Why data and identity have to be solved together

Cyera's pitch for the Oasis acquisition rests on a simple logic problem: "Identity without understanding data cannot determine risk, and data without understanding identity cannot determine trust," Hart Smith said. Cyera built its business on the data half — understanding what sensitive information exists and where. Oasis built its business on non-human identity at enterprise scale. Put together, the argument is a platform that can answer both halves of the access question at once, extended across the cloud, the browser, and now the device itself.

Yitzi Tanenbaum, Cyera's director of product marketing, said customers reaching for traditional security vendors to solve this haven't had much luck, for three reasons: platforms marketed as unified are often disjointed collections of separate acquisitions that don't actually talk to each other; vendors lack a real grip on what data agents are touching and whose identity is doing the touching; and most analysis today still leans on static permissions with little understanding of what's actually being accessed in the moment.

The four pillars of Agent Guardian

Agent Guardian is built around Discover, Govern, Protect, and Validate. Discover addresses what Tanenbaum called customers' number one complaint: shadow AI, meaning no clear picture of what agents and AI tools are even running in the environment. Once that inventory exists, Govern sets the guardrails — what's allowed, what isn't, and whether an agent is drifting from the purpose it was originally built for. Protect is the enforcement layer, blocking agents in real time from taking actions outside their intended scope — Tanenbaum's example was a calendar-and-inbox management agent suddenly reaching into HR systems, which gets stopped cold. Validate closes the loop with red-teaming, compliance checks, and a full audit trail of what an agent actually did.

That Protect layer includes what the team called an agent kill switch: the ability to quarantine an agent that's behaving unexpectedly, investigate, and release it once cleared — without waiting on a broader incident response process to catch up.

A unified policy engine, not a bolted-on one

Cyera's specific claim of differentiation is architectural. Hart Smith described looking at competitors who've tried to bridge posture management and runtime protection for AI, only to find that "the policy engine they're using for AI is separate from the policy engine they're using for other things" — built out using rigid, project-based logic with limited ability to actually understand the content it's evaluating. Cyera's alternative: the same policy engine drives Agent Guardian, its existing DSPM product, and Omni DLP, so a rule written once for data at rest also governs data in motion and in use, with no separate, more brittle system layered in for AI specifically.

The Robin Williams test

The clearest illustration of what that unified approach is supposed to buy came from a customer's own attempt to break the platform during a private preview. A security lead pasted a Social Security number into a chat to see what would happen — but instead of risking his own SSN, he used one he found publicly available online, which turned out to belong to the late Robin Williams. Cyera's platform flagged it, correctly, as a low-severity alert rather than a critical one, because the system recognized the number as already public rather than treating any SSN-shaped string as an automatic emergency. The customer initially took the low score as a failure; Cyera's read is closer to the opposite — a platform that understands content deeply enough to tell the difference isn't just pattern-matching against a regex. Hart Smith cited a false-positive reduction north of 98% as the payoff of that deeper understanding.

What the discovery layer actually surfaces

In a live walkthrough, Cyera product VP Maya Mandel showed the inventory pulling from browser activity, AI gateways, developer APIs, existing DLP providers, and more into a single view — not just which agents and AI apps exist, but which model infrastructure they're actually running on (a customer might permit Claude only through Bedrock rather than natively, for instance), who has access, what knowledge bases are connected, and a risk score built from the specific factors driving it. Discovery extends beyond agents themselves to the tools, skills, and MCP servers those agents call — visibility Mandel said customers have specifically asked for as MCP adoption spreads.

Each agent gets a graph showing exposure, data connections, and a full activity history — prompts, responses, tool calls, and token consumption — with the level of detail customers see configurable based on their own sensitivity requirements. Issues (posture-level, static findings) and alerts (real-time policy violations) are tracked separately, and policies can be set to block outright or simply flag for review, depending on how much autonomy a given customer wants to hand the system.

What's still ahead

Cyera's endpoint capability, announced at Black Hat, extends the same DSPM and DLP visibility to AI agents running locally on employee devices — outside corporate network controls, where Hart Smith noted some of the most sensitive agent activity increasingly happens. It's explicitly not a requirement for Agent Guardian to function; it's one more surface in what the team was clear is a multi-surface problem, alongside the company's existing Browser Shield extension and AI gateway integrations.

Asked how Cyera handles agents running on external platforms like Salesforce's Agentforce, ServiceNow, or Watson X, Tanenbaum pointed to the same Omni DLP orchestration model the company built out previously — connecting via API into whatever DLP and identity systems already exist in a customer's environment, rather than requiring a rip-and-replace.

For a category where "we do AI security too" has become a default claim for nearly every vendor heading into Black Hat this year, Cyera's own framing is a useful lens for evaluating any of them: the real test isn't whether a product can react to an agent doing something wrong, but whether the decision-making layer underneath actually understands the data and the identity well enough to make that call correctly in the first place.

1 Comment

2 votes
🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

AI Agents Don't Have Identities. That's Everyone's Problem.

Tom Smithverified - Mar 13

C1 CISO Kevin Paige: Human-to-AI-Agent Ratios Could Hit 1-to-150 Within a Year

Tom Smithverified - Aug 3

Your Backup Data Knows More Than You Think. HYCU aiR Is Finally Asking It the Right Questions.

Tom Smithverified - May 14

The AI Agent Found the MFA Backup Codes in a Downloads Folder.1Password Is Solving That Problem.

Tom Smithverified - Jul 29

Helping Clients Move from Pilot to Production: The Agentic AI Governance Playbook

Tom Smithverified - Jun 8
chevron_left
16.6k Points703 Badges
217Posts
124Comments
83Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

Commenters (This Week)

5 comments
1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!