We don't normally publish twice in a week. This week earned it. In the space of about seventy-two hours, the identity security market produced a $1 billion acquisition between two companies that share the same three investors, a $300M ARR announcement paired with a product launch that reads uncannily like a competitor's from ten weeks earlier, and enough M&A to make the second-largest security deal of the year feel almost routine. Any one of these would anchor a normal issue. Together they say something bigger: the money in identity has stopped waiting for the market to mature and started actively arranging it.
So this is a longer read than usual — roughly fourteen minutes, and worth it. Two deep dives. First, Cyera's $1B acquisition of Oasis Security: not just what it means for data-plus-identity convergence, but the venture mechanics underneath it, because when the acquirer and the target share Cyberstarts, Sequoia, and Accel at the top of both cap tables, you are watching portfolio orchestration as much as strategy. We'll also ask the obvious follow-on question — who's next? Second, Saviynt's big week: $300M ARR, a new platform called Zuma, and some uncomfortable arithmetic about what this company is actually worth at today's multiples. Then our usual vendor assessment, this time on the giant everyone already has: Microsoft Entra. Let's get into it.
seven days that reshaped the identity market
Announced Tuesday July 28: roughly $700M cash plus Cyera shares, making it the second-largest cybersecurity deal of 2026 behind Accenture's $4.175B Dragos/runZero/NetRise package. Oasis becomes a dedicated non-human-identity unit inside Cyera. Deep dive below — the deal mechanics are more interesting than the headline.
Also July 28: Saviynt reported crossing $300M in annual recurring revenue with bookings up more than 80% and 96% gross retention, and launched Zuma — an AI identity security platform built around Zuma Insights, Zuma Access, and Zuma Governance. Note this is an ARR milestone, not a funding round; several outlets blurred that line. Deep dive below.
SecurityWeek's M&A tracker has now catalogued 230 cybersecurity transactions in 2026. The identity cluster keeps compounding: Cisco bought Astrix (~$400M) then WideField; CrowdStrike took SGNL and then Seraphic; Check Point picked up Cyata, Cyclops and Rotate; Palo Alto acquired Koi; SailPoint closed Entro (~$200M); Barracuda bought Evo; 1Password bought Apono. Every one of those touches non-human or agent identity.
Following last issue's analysis: reporting suggests the models' actions likely violated the Computer Fraud and Abuse Act, a statute with no carve-out for an AI agent exceeding its authorized scope during sanctioned testing. Trend Micro's write-up added the operational lesson — an agent using its own legitimate credentials "does not resemble malware, because it is not malware," so telemetry has to focus on behavior rather than signature.
Crunchbase data shows startups at the AI/security intersection have raised $855M across more than 150 reported seed rounds in 2026 — with identity and agent governance the densest cluster. Israeli tech alone announced over $750M in new funding the week of July 27, concentrated in AI infrastructure, cyber, and agent governance.
A healthcare provider disclosed that attackers stole personal, financial, and medical records from its AWS environment back in March 2026 — a months-long detection gap. Separately, CISA urged water and wastewater utilities to lock down internet-exposed controllers after intrusions hit dozens of Minnesota systems.
Cyera buys Oasis for $1B — and the cap table tells the real story
On the surface: a data security leader buys a non-human identity leader to unify data and identity. Underneath: three investors who sit on both cap tables just engineered a nine-figure liquidity event without either company going public.
Start with the part that isn't financial engineering, because it's genuinely sound. Cyera knows where your sensitive data lives and how it's classified. Oasis knows which non-human identities — service accounts, tokens, API keys, AI agents — can reach it. As Cyera's Jason Clark put it, "Data and identity are two sides of the same coin. You cannot secure one without understanding the other." Cyera CEO Yotam Segev framed the ambition more plainly: unify data and identity into a single system "so every agent is trusted with exactly the data it should reach."
That's not a stretch. It's the same convergence thesis driving Cisco's Astrix and WideField buys, CrowdStrike's SGNL acquisition, SailPoint's Entro deal, and 1Password's Apono purchase. Every serious security platform has concluded that "who can access what data" is one question, not two. Oasis will run as a dedicated NHI unit inside Cyera, with the platforms integrating over time — a structure that suggests they intend to preserve the product rather than absorb and dissolve it.
And the timing is defensible. Cyera has tripled ARR three years running to an estimated $200M+, grown past 1,500 employees across 18 countries, and just raised $600M at a $12B valuation in June. This is a company with the balance sheet to buy rather than build, in a category where twelve months of build time is a category-defining eternity.
Oasis is estimated to be doing somewhere in the range of $10–20M ARR. At a $1B price, that's a 50–100x revenue multiple. For context, that tops Google's acquisition of Wiz (roughly 46x) and Okta's acquisition of Auth0 (roughly 43x) — two deals that were themselves considered aggressive at the time.
A 50–100x multiple is not a revenue multiple in any meaningful analytical sense. It's a strategic option price — Cyera is buying a category position and a team, not a P&L. That can be perfectly rational. It also means the number tells you almost nothing about whether Oasis's product is good, and you should not read the price as a quality signal when it lands in a vendor's pitch deck.
Here's the detail that reframes the whole transaction. This is not one investor nudging two portfolio companies together. The top of both cap tables is nearly identical.
| Investor | In Cyera (acquirer) | In Oasis (target) | Role |
|---|---|---|---|
| Cyberstarts | ✓ | ✓ | Seed-stage, both from inception |
| Sequoia Capital | ✓ | ✓ | Growth backer, both sides |
| Accel | ✓ | ✓ | Growth backer, both sides |
| Craft Ventures | — | ✓ | Led Oasis $120M Series B, Mar 2026 |
When the same heavyweights hold board influence over both the buyer and the seller, the ordinary friction of M&A — price discovery, diligence adversarialism, competitive process — drops substantially. That is not inherently improper; related-party transactions happen constantly in venture and there are well-established governance mechanisms (independent directors, recusal, fairness opinions) for handling them. But it does mean the price was set inside a room where most of the people had an interest on both sides of the table.
To understand the timing, you have to understand what venture firms are under pressure to produce in 2026. The metric that matters right now is DPI — Distributed to Paid-In capital. Not paper markups, not TVPI, not "our portfolio is worth $40B on the last round." Actual cash, wired back to limited partners. The IPO window has been unreliable, hold periods have stretched, and LPs have grown openly skeptical of unrealized marks.
Now look at the structure. Cyera raised $600M in June and holds a war chest. It deploys roughly $700M of that cash to buy Oasis. Cyberstarts, Sequoia, and Accel — holding meaningful positions in Oasis from early rounds at low cost basis — convert a large portion of that stake into realized cash today. The remaining consideration rolls into Cyera equity, which keeps them exposed to the bigger prize: a future Cyera IPO at a much larger valuation.
They return hundreds of millions in hard DPI to LPs now, keep upside exposure to the combined entity, remove a portfolio company that would have needed years and hundreds of millions more to reach independent scale, and hand Cyera a genuine product gap-filler in the hottest category in security. One transaction, four objectives. Whatever else you think of it, it is extremely well constructed.
None of which requires cynicism about the product logic. Both things are true at once: the strategic case stands on its own merits, and the deal structure solves a pressing problem for three funds simultaneously. Sophisticated investors are perfectly capable of doing a smart strategic deal that also happens to be excellent portfolio management.
Expect consolidation pressure on your renewals. Cyera now sells data security and NHI governance as one platform. If you buy DSPM from one vendor and NHI from another, you will get a bundling pitch — and probably a decent discount to consolidate. Evaluate whether the integration is real or roadmap before you take it.
Watch the integration risk. Cyera has now made six acquisitions (Trail Security $162M, Ryft ~$100–130M, Genie ~$50M, plus Otterize and Shape AI) totalling roughly $1.35–1.4B. That is a lot of engineering surface to knit together in eighteen months. Ask specifically which acquired components share a data model today versus which are still separately-operating units.
Re-underwrite the standalone NHI vendors. If you were mid-evaluation with Oasis, your vendor's roadmap and support model just changed owners. That's not automatically bad — more resources, broader platform — but the product priorities of a $1B acquisition inside a $12B company are not the priorities of an independent Series B.
The obvious question, and one we flagged in Issue 10 before this deal was announced: Cyberstarts also backed Linx Security from inception. Gili Raanan has been explicit about the thesis — "we believe identity would become the core control layer of modern security" — and the firm now has a demonstrated playbook for realizing that thesis through intra-portfolio consolidation.
Linx raised a $50M Series B in March 2026 led by Insight Partners at a reported ~$83M total raised, with roughly 100 employees and enterprise contracts in banking, healthcare, and the Fortune 500. It sits in IGA and agent governance — adjacent to, but not identical with, what Oasis brought to Cyera. Insight leading the B rather than an existing investor is a meaningful difference from the Oasis pattern, and it argues for Linx building independently for a while.
Our read: a near-term Linx acquisition by Cyera specifically seems unlikely — the capability overlap with Oasis is too high to pay twice. But Linx as an acquisition target generally, inside the next 18–24 months, looks entirely plausible given how aggressively Cisco, CrowdStrike, Palo Alto, and Check Point are buying in this exact space. If you're evaluating Linx, that's not a reason to walk away — it is a reason to negotiate change-of-control protections and get roadmap commitments in writing. We said the same thing in Issue 10, and this week made the point louder.
Saviynt's big week — $300M ARR, a new platform, and some awkward arithmetic
Saviynt announced $300M+ ARR, 80%+ bookings growth, 96% retention, and launched Zuma — a full AI identity security platform. All genuinely notable. But the valuation math is tighter than the press release suggests, and Zuma's positioning bears a resemblance to a competitor's May launch that is difficult to unsee.
Several outlets and a good deal of LinkedIn chatter this week framed the $300M as new capital. It isn't. The $300M is an annual recurring revenue milestone. The capital event was in December 2025: a $700M Series B growth equity round led by KKR, with Sixth Street Growth, TenEleven, and Carrick Capital participating, at a valuation of approximately $3 billion.
The distinction matters enormously for how you read the announcement. "We raised $300M" is a statement about investor conviction today. "We crossed $300M ARR" is a statement about customer conviction — arguably the better signal, and to Saviynt's credit, the harder one to manufacture. Crossing $300M ARR in this category is a real accomplishment and deserves to be reported as one.
Now put the two numbers together. A ~$3B valuation on ~$300M ARR is roughly a 10x ARR multiple. Is that supportable in the current market? It depends entirely on one variable, and the answer is genuinely uncertain.
Per Jamin Ball's Clouded Judgement data as of July 31, 2026, here is where public SaaS actually trades:
So the question becomes: which bucket is Saviynt in?
This is where we part company with the simpler version of this argument circulating this week. If Saviynt's 80%+ bookings growth converts into sustained high revenue growth, a $3B valuation is not aggressive — it's conservative against a 19.5x high-growth median. KKR is not a naive buyer; they priced this round with access to the data room.
But if growth normalizes into the mid-tier — and bookings growth is a leading indicator that does not always convert cleanly into recognized revenue growth, particularly when it includes multi-year prepaid deals or heavy discounting — the same $300M ARR supports something closer to $1.5B. That would make the December round the high-water mark, and any subsequent primary raise a down round with the dilution and preference-stack consequences that follow.
Because down rounds change vendor behavior. They trigger structure — liquidation preferences, ratchets — that pressures management toward short-horizon revenue. That shows up in your world as harder-edged renewal negotiations, more aggressive upsell motions, and occasionally a thinner product-investment budget. You are not investing in Saviynt, but you are underwriting a multi-year dependency on them. The financial trajectory is legitimately part of your diligence.
Saviynt launched Zuma on July 28. SailPoint launched Agentic Fabric on May 11 — ten weeks earlier. Both companies announced from Nasdaq. Both structured the launch around a free discovery trial that upgrades into paid tiers. We put the public positioning of the two side by side, and we'll let you form your own view.
| Dimension | SailPoint Agentic Fabric — May 11 | Saviynt Zuma — Jul 28 |
|---|---|---|
| Problem framing | AI agents act at machine speed, "often without clear ownership, oversight, or consistent controls" | AI agents are autonomous and dynamic, and "exist outside established governance processes" |
| Signature line | "You cannot secure what you cannot see" | "You can't secure what you can't see" |
| Structural triad | Discover · Govern · Protect | Discover · Protect · Manage (Insights · Access · Governance) |
| Identity treatment | Treat AI agents as "first-class identities" alongside humans | Govern AI agents as "first-class, non-human identities" |
| Discovery layer | Complete inventory + identity graph; surfaces shadow AI | Zuma Insights: continuous inventory, access map, shadow-AI discovery |
| Ownership model | Map every agent to a human owner + lifecycle controls | Ownership management, succession, lifecycle from registration to retirement |
| Runtime layer | Real-time authorization, threat detection, automated response, least privilege | Zuma Access + "Intent-Aware Runtime Authorization" evaluating intent, context, risk |
| Packaging | Free Discovery Tool trial → Agentic Business / Business Plus tiers | Free ISPM-for-AI/NHI trial → extend into Access + Governance |
| Platform claim | "Delivered by our core SailPoint Platform" | "Built on the same Saviynt Identity Security Data Fabric" |
| Category claim | "New era" of identity for the agentic enterprise | "Industry's first comprehensive enterprise AI Identity Security Platform" |
| Venue | Nasdaq | Nasdaq |
To be scrupulously fair: there is a legitimate defense here, and it deserves airtime. Categories converge on shared vocabulary. "Discover, govern, protect" is close to an industry-standard triad. Every vendor in this space is solving a genuinely similar problem, reading the same analyst notes, and hearing the same objections from the same CISOs. Convergent positioning is not evidence of copying — it is often just evidence that the market has settled on how to describe a problem. Saviynt would presumably say exactly this, and it would not be an unreasonable answer.
And there are real differences. Zuma's "Intent-Aware Runtime Authorization" is a distinct framing — evaluating an agent's intent per action, not just its entitlements — and if the implementation matches the ambition, it's a genuine idea rather than a repackaged one. Saviynt also brings a real ISPM heritage that predates this launch.
But the accumulation is what makes this hard to wave away. One shared phrase is coincidence. A near-verbatim signature line, a mirrored structural triad, the identical "first-class identities" framing, the same free-trial-to-tiers packaging motion, the same platform-foundation claim, and the same launch venue — ten weeks apart — is a pattern. Reasonable people can disagree about what the pattern means. Our view is simply that a buyer should notice it, and should ask Saviynt directly what in Zuma is architecturally new versus newly named.
Zuma is described as "available now." Screenshots circulating from the launch show a clean, modern dashboard — identities discovered, AI agents and non-human counts, a "Risk at a glance" severity breakdown. It looks good. It also looks, to more than a few practitioners who've mentioned it to us, like a great many other modern security dashboards: the visual language of a rapidly-assembled contemporary web app rather than something with years of enterprise iteration behind it.
That observation lands differently for Saviynt than it would for most vendors, because of a pattern we documented in Issue 07. Practitioners have repeatedly described a gap between Saviynt's announcement cadence and its delivered reality — the Glassdoor reviews describing a culture that prioritizes "speed over quality," where "product releases sometimes feel more like early-stage iterations than mature enterprise solutions," and the r/IdentityManagement threads describing failed jobs and instability under load. Saviynt is genuinely well known for announcing well. The recurring practitioner question is whether the shipped product matches the launch deck.
We scored Saviynt "CAPABLE ON PAPER — DO YOUR HOMEWORK" three issues ago, and marked its product score down to 7.0 on exactly this basis. Nothing this week changes that verdict; if anything it sharpens it. A vendor with an unresolved trade-secrets suit from Delinea over allegedly misappropriated PAM product information — allegations, not findings, and Saviynt has moved to dismiss — announcing a platform whose positioning closely tracks a competitor's from ten weeks earlier is, at minimum, an unfortunate juxtaposition. We are not connecting those two things causally. We are noting that a company in active IP litigation has a stronger-than-usual interest in demonstrating originality, and that this launch does not obviously do that.
The practical advice is unchanged and unglamorous: ask for a proof-of-concept against your own environment at your own scale, ask which Zuma components are generally available versus in preview, ask for reference customers running it in production rather than in pilot, and ask what specifically is new engineering versus new packaging on the existing Identity Security Data Fabric. Those questions are fair to ask of any vendor. They're just more load-bearing here.
the pitch vs. the reality, synthesized from the people who run it
A voice-phishing campaign against employees yielded a corporate Microsoft Entra single sign-on account tied to Abbott's Cancer Diagnostics business. Attackers reportedly persisted for weeks, stealing credential files and deleting logs before detection. This is not an Entra product vulnerability — it's social engineering against the human in front of it — but it illustrates the concentration risk of the identity everything runs through.
Microsoft has continued pushing Entra well past directory services: ID Governance for lifecycle and access reviews, Privileged Identity Management for just-in-time elevation, Workload Identities for service principals, Verified ID, and the Global Secure Access line. The strategic pitch is that identity, endpoint, and security operations converge inside one Microsoft estate.
Entra's capability tiers span P1, P2, ID Governance add-ons, and M365 E3/E5 bundles, with meaningful security features gated across them. G2's negative tag cloud for Entra ID is led by "Complexity," "Expensive," "Complex Administration," and "Difficult Learning." One Gartner Peer Insights reviewer of ID Governance put the cost structure bluntly: powerful basics are in E5 or P2, "but for the full IGA solution, additional licenses are needed" — so the real price is E5 plus the add-ons on top.
Trajectory: structurally dominant, functionally uneven. Microsoft Entra is the most consequential identity product in the enterprise market, and mostly not because it wins feature bake-offs. It wins because it is already in the agreement. Core authentication, SSO, MFA, and Conditional Access are genuinely excellent — 4.5 on G2 across nearly 900 reviews, with ease of use and security leading the praise. If your estate is Microsoft-centric and your requirement is strong, well-integrated workforce authentication, Entra is not merely adequate; it is a very good answer.
The governance story is where the platform claim strains. The most useful review we found this cycle described Entra ID Governance as having "a great back-end" while "the front-end is missing" — you either invest heavily in user education or integrate a real IGA on top. Reporting is described as "very poor." A separate reviewer called Microsoft "still immature compared to some other well established vendors" in this category. That is a meaningfully different product maturity from the auth layer, and the single bundled brand name obscures it.
And then there's the licensing. It is genuinely the most consistent complaint across every platform we checked — P1 versus P2 versus ID Governance add-ons versus E3 versus E5, with security features distributed across tiers and, per reviewers, little in-product clarity about what you're missing. The practical consequence is that organizations routinely believe they have controls they have not licensed. That is a security problem dressed as a procurement problem.
Net for a CISO: use Entra for what it's genuinely best at, and be honest with yourself about the governance gap rather than assuming the bundle closes it. The most common expensive mistake we see is not choosing Entra — it's choosing Entra, assuming governance is covered, and discovering at audit time that it isn't.
a category, tool, or idea worth knowing this week
230 security deals this year, and the identity cluster is the densest. There is a real probability that a vendor you sign this quarter is owned by someone else before your first renewal. Ask for: continuity of support terms through an acquisition, roadmap commitments that survive a change of control, and a termination-for-convenience right if the product is materially deprecated. Vendors resist these. Ask anyway — the ones confident in their independence will negotiate.
This week's Zuma/Agentic Fabric side-by-side is a useful reminder: category vocabulary converges fast, and marketing language is the cheapest thing a vendor produces. Before you're impressed by a launch, pull the last two quarters of competitor announcements in the same category. If the positioning is near-identical, the differentiation — if it exists — is in the architecture, not the deck. Ask what's engineered differently, and make them answer in specifics.
You're not an investor, but you are underwriting a multi-year dependency. A private vendor priced well above current public comps has to either grow into that number or reprice down — and down rounds bring liquidation preferences, structure, and short-horizon revenue pressure that eventually shows up in your renewal. Jamin Ball's Clouded Judgement publishes the public multiples free every week. Ten minutes a quarter is enough to know whether your vendor's last round looks reasonable or heroic.
one line to sound three moves ahead in your next exec meeting
Your board and your CFO are reading the same headlines about billion-dollar security acquisitions. The instinct that follows is "shouldn't we consolidate vendors and save money?" — a reasonable question with a genuinely nuanced answer. Get there first, and frame it as portfolio risk management rather than a spend debate. The strongest position is knowing which of your vendors are acquisition candidates before someone else raises it.
a spicy anonymized take from the community this week