Oak's Head of Research: Some Orgs Discover They Have 10,000 AI Agents for Every 200 Employees

Oak's Head of Research: Some Orgs Discover They Have 10,000 AI Agents for Every 200 Employees

BackerLeader 43 231 395
calendar_today agoschedule3 min read

When Oak's enterprise customers first load their own identity graph inside the platform, the most common reaction isn't about a specific vulnerability. It's shock at scale. "Even now, when you talk to security leaders, they'll tell you, 'My organization is 200 people,'" said Oryan Perlmutter, Oak's Head of Research. "But it's not the case anymore. It's 200 people, but 10,000 agents on top." Oak, which emerged from stealth in July with a $60 million seed round led by Accel, Greylock, and CRV, is building a single identity platform that treats human employees, service accounts, and AI agents as different categories of the same underlying problem, rather than three separate products bolted together.

Oak's founders, CEO Shai Morag and co-founder Tal Marom, have both been through this cycle before. Morag previously built and sold Secdo to Palo Alto Networks and Ermetic to Tenable; Marom led product at Tenable and Salesforce. According to Perlmutter, what convinced them Oak needed to be built from scratch rather than extended from existing cloud identity tooling was watching how badly that older generation of tools broke down once AI entered the picture. Cloud identity management was already fragmented and hard to manage before agents, Perlmutter said. Once AI started generating roles, permissions, and policies by the minute, on-prem and hybrid environments, which often lacked even basic logging of roles and permissions to begin with, got worse, not better. Existing non-human identity tools, built as an add-on for long-lived, mostly static credentials, simply weren't built for identities that spin up, act, and disappear within minutes, or spawn their own sub-agents mid-task.

Oak's core technical bet is what it calls a live identity graph, built by connecting to a company's identity provider and HR system where APIs exist, and by running lightweight agents directly inside a customer's environment, reading databases and log files, where they don't. That graph updates continuously and links every identity, human or otherwise, back to who's accountable for it, a detail Perlmutter said is consistently the second most surprising thing customers encounter, right after the raw scale of their own agent population. "That's an agent, that's an action, is this a good action? I don't know. If it's a bad action, who's responsible? Who are you going to call?" is the flow he described seeing repeatedly. Being able to trace an action back to the human who actually owns that agent, rather than treating the agent as a dead end, is what Perlmutter says relieves security teams most once they see it work.

Distinguishing a human identity from an agent identity, in Oak's model, comes down to behavior rather than any fixed label. A service account or API key shows recurring, predictable behavior, which makes it straightforward to scope down to a narrow, fixed set of permissions. An agent is different: it's pursuing a goal, and if blocked, it will look for another way to get there, potentially expanding its own scope of action in the process. That means governance has to be reactive and just-in-time rather than fixed at setup, according to Perlmutter, because scoping an agent too tightly from the start effectively turns it into a rigid script incapable of doing the job it was actually built for. To manage unused-access risk without triggering false positives, Oak maps every available action inside a connected app or vendor system, builds a usage histogram for each one, and lets customers set their own thresholds for what counts as rarely used, whether that's five times a month or once a year, with built-in defaults and AI-generated recommendations layered on top for context Oak doesn't have out of the box.

Deployment speed is where Oak is making its most concrete claim. Perlmutter said the company can typically build a new connector for a homegrown or first-party app in about 24 hours, using a mix of an AI-driven acceleration engine and a white-glove implementation team, compared with an industry norm that often runs closer to a month once a request clears an internal prioritization queue. Overall implementation time for Oak, he said, is typically under two weeks, against a year or more for many legacy identity governance platforms, a gap Perlmutter attributes largely to Oak's ability to handle hybrid, multi-cloud, and pre-cloud on-prem environments out of the box rather than addressing only one layer of a customer's stack at a time. Oak itself remains a small team, 16 people as of Black Hat, and uses its own internal agents, which it calls Acorns, to handle monitoring, reporting, and governance actions at a scale the company says its human staff alone couldn't sustain.

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

AI Agents Don't Have Identities. That's Everyone's Problem.

Tom Smithverified - Mar 13

Cyera: Non-Human Identities Grew 480% in Six Months. Most Companies Have No Idea What They're Doing.

Tom Smithverified - Aug 3

Sovereign Intelligence: The Complete 25,000 Word Blueprint (Download)

Pocket Portfolio - Apr 1

️ Agent Action Guard: Framework for Safer AI Agents

praneeth - Apr 1

From Prompts to Goals: The Rise of Outcome-Driven Development

Tom Smithverified - Apr 11
chevron_left
15.9k Points669 Badges
202Posts
119Comments
81Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

2 comments
1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!