Live intel Wed · 19 Aug 2026 · 06:00 ET

ThePerimeter

FOR CIOs & CISOs
VOL. 1 · ISSUE 12 Sponsored by — your logo here — Subscribers: 22,180
// Good morning, defenders.

Black Hat came and went, and the thing worth noticing wasn't any single product or vulnerability. It was that the entire show floor converged on one problem. Rubrik launched Agent Identity. Zero Networks launched Least Agency Enforcement. Sweet Security launched Agentic AI Blocking. Cyera launched Agent Guardian. Acalvio launched deception guardrails for agentic environments. Strip the branding off and every one of them is answering the same question: what should this autonomous actor be permitted to do, and how do we stop it when the answer changes? That is an identity question wearing a runtime costume, and BeyondTrust put a number on why it matters — 75% of the attacks its offensive team ran last year involved an identity or privilege issue.

So this issue does three things. We walk the Black Hat announcements and the fortnight's other news, including a genuinely uncomfortable thread developing around Saviynt's release quality. Then a special research segment: Identity Security as Critical Infrastructure — the argument that AI's real disruption isn't more identities, it's more autonomous authority, and what that does to the market's size and shape. Then a vendor assessment of C1, formerly ConductorOne — a sharp, well-funded challenger with a culture signal worth reading carefully, and an acquisition profile that is hard to ignore once you notice who already sits on its cap table. Let's get into it.

01

Market Movers

two weeks, Black Hat included — & why it lands on your desk

Black Hat75%

The show floor converged on agent authority — and BeyondTrust priced the problem

Black Hat USA ran Aug 1–6 at Mandalay Bay with a dedicated AI Zone, and the vendor announcements told one story. Rubrik launched Agent Identity, arguing static credentials are structurally wrong for autonomous agents. Zero Networks launched Least Agency Enforcement — identity-based microsegmentation plus just-in-time MFA to stop agents exceeding intended authority. Sweet Security launched Agentic AI Blocking to terminate unauthorized tool calls at runtime. Cyera introduced Agent Guardian. Acalvio shipped deception guardrails that watch agent interactions for jailbreak and prompt-injection attempts. Underneath it all, BeyondTrust's Phantom Labs Research Index found 75% of attacks involved an identity or privilege issue, with credential exposure, privilege escalation, and identity misconfiguration leading the root causes.

Why it matters: the category formerly known as "AI security" is quietly becoming authorization. If your AI security budget sits entirely outside your identity program, you are about to buy two halves of the same control twice.
Vendor riskReleases

Saviynt's release quality is becoming a documented pattern, not a one-off

A thread worth watching. Practitioner complaints about Saviynt's release cadence and stability have moved from scattered to consistent. A March 2026 Gartner Peer Insights reviewer describes the company missing its own stated release timeline, shipping without advance release notes, and applying undisclosed hotfixes that broke a dev environment — "we had a major issue on our Dev environment behaving very different and had broken rules that prod did not have… support ticket and waited for weeks," resolved only when told the fix was to wait for the next city-named release. A G2 reviewer puts it plainly: "There were some issues being observed in every Saviynt release." Saviynt's own support forums carry a standing "Defect or Issue" label thick with post-upgrade breakage. Separately, an anonymous employee-review post this month alleges a recent named release is disrupting major customer environments; we have not been able to corroborate that claim and are not repeating its specifics.

Why it matters: we scored Saviynt "capable on paper — do your homework" in Issue 07 and marked its product score to 7.0. The verifiable record has not improved. If you run Saviynt, get your upgrade-notification and hotfix-disclosure terms in writing; if you're evaluating, ask for the last four release post-mortems.
StandardsNIST

Agent identity became a standards problem, not just a product category

NIST's AI Agent Standards Initiative, launched February, explicitly includes agent authentication and identity infrastructure for secure human-agent and multi-agent interaction; its National Cybersecurity Center of Excellence is separately running a project on identifying software agents and authorizing their access and actions. Meanwhile the July 2026 Model Context Protocol authorization spec landed on OAuth 2.1 resource-server semantics and explicitly requires audience-bound tokens rather than token passthrough.

Why it matters: when NIST and a de facto protocol standard both converge on agent authorization, the architecture stops being vendor-specific. Ask your vendors which of these they actually implement — "MCP support" without audience-bound tokens is a checkbox, not a control.
Hyperscalers3 of 3

Microsoft, AWS and Google now all ship first-class agent identity

Microsoft Entra Agent ID is generally available, giving agents identity, authentication, authorization, lifecycle governance, and — notably — a human sponsor construct with transferable ownership. AWS Bedrock AgentCore Identity handles agent identity, credential management, OAuth delegated access, and on-behalf-of token exchange that preserves both user and agent identity downstream. Google is exposing agent identities built on SPIFFE identifiers.

Why it matters: this validates the category and threatens to absorb it simultaneously. For heterogeneous estates the neutral cross-cloud governance layer still has a job — but the commodity floor just rose, and any vendor whose pitch is "we give agents identities" is now competing with something you already own.
Data21%

Deloitte: only 21% of organizations have mature agent governance

Deloitte's 2026 State of AI research found roughly one in five organizations expecting to deploy autonomous agents reported a mature agent-governance model — while close to three-quarters planned agent deployment within two years. PwC found lack of trust was already a top-three agent-adoption blocker, with trust dropping to 20% for financial transactions. Gartner expects more than 40% of agentic AI projects to be cancelled by end of 2027 on cost, unclear value, or inadequate risk controls.

Why it matters: the gap between deployment intent and governance maturity is the single best budget argument you have this cycle. It is also a warning: projects don't just fail on technology, they get cancelled on inadequate controls.
ThreatAgents

Researchers demonstrated the attack side of the same coin

Black Hat's research track ran hard at agentic risk: credential theft through agent workflows, autonomous attack chains, and emerging risks in AI coding agents and non-human identities. A new class of NAT trust-assumption attacks was disclosed alongside CVE-2026-20200, a critical Cisco Integrated Management Controller flaw enabling privileged access. One recurring theme from the sessions: an agent abusing its own legitimate credentials doesn't look like malware, because it isn't malware.

Why it matters: signature-based detection has no answer for a correctly-authenticated agent doing something it shouldn't. Behavioral baselining on non-human identities is the control that catches it — and most programs still don't have one.
02

Special Research

identity security as critical infrastructure for the AI economy

The thesis
AI doesn't create more identities. It creates more authority.

The common version of this argument — "AI means more identities, therefore identity vendors win" — is weak, and buyers can smell it. The stronger version survives scrutiny: enterprises now need a scalable way to determine which actor may exercise which authority, over which resource, on whose behalf, under what conditions, and for how long. That is a different and much harder problem.

Mature agent governance
21%Deloitte, 2026
Planning agent deployment
~75%within two years
Non-human : human
~45:1CSA, surveyed envs
Agentic projects cancelled
>40%Gartner, by 2027
Why this framing matters more than the headcount version

The first phase of generative AI was about output: can it write, summarize, code, reason. Those are questions about intelligence. The phase we're in now asks something categorically different: can it act? Can it open Salesforce, query Snowflake, change a customer record, authorize a refund, modify infrastructure, commit code, approve an invoice, trigger a wire transfer, provision another identity, delegate to another agent?

Every one of those has a structure underneath it. There is an actor. A principal on whose behalf it operates. A resource. An action. A permission, and a reason the permission exists. A policy. Possibly a delegation chain. A duration. An accountable owner. And — critically — a way to terminate the authority. That structure is the product. Not the identity count.

The durable formulation

Autonomous intelligence requires governable authority. AI creates intelligence. Identity establishes authority. Governance creates trust. That framing is far harder to disprove than declaring any single product category the sole "control plane" for AI — which is what most vendor marketing currently attempts.

The evidence is real — and it's coming from outside the vendors

What makes this more than a marketing narrative is that the architectural convergence is visible in places with no commercial stake in identity vendors doing well. NIST launched an AI Agent Standards Initiative in February that explicitly covers agent authentication and identity infrastructure; its NCCoE is separately working on identifying software agents and authorizing their access and actions. The July 2026 MCP authorization spec requires audience-bound tokens. And three major cloud ecosystems independently arrived at the same conclusion — Microsoft Entra Agent ID, AWS Bedrock AgentCore Identity, and Google's SPIFFE-based agent identities all treat the agent as an identity-bearing, authorization-requiring enterprise principal.

That's strong support for identity becoming a necessary architectural primitive for agentic computing. It is not proof that any standalone identity vendor captures the resulting economics — a distinction most vendor decks blur, and one worth holding onto.

The economics: an honest accounting

Here is where most versions of this argument fall apart, and where the discipline matters. There is a tempting move available: take the biggest available AI-spend number, multiply by a security percentage, announce a market. It is methodologically unsound, and the numbers on offer make it very tempting — IDC put AI infrastructure at $318B in 2025 heading past $1T by 2029; Gartner's broader taxonomy reaches $2.59T of total AI spend in 2026.

Those aren't contradictions, they're different market definitions — which is precisely why multiplying the largest one by a desired percentage produces a fantasy. The right denominator is addressable production AI spend: models and inference, AI applications, agent platforms and workflows, orchestration, AI-specific services. It should generally exclude semiconductor fabrication, grid investment, and hyperscaler data-center capex the enterprise doesn't own or secure.

Say the quiet part

No authoritative source establishes a universal "identity should be X% of AI spend" rule. Gartner's January 2026 forecast places $51.3B of "AI Cybersecurity" inside $2.53T of AI spending — arithmetically about 2.0% — but Gartner's public release doesn't define that category as spending required to secure AI, so it cannot honestly be used as proof of a 2% ratio. Any vendor citing it that way is overreaching.

What survives is a risk-adjusted planning hypothesis, explicitly labelled as one — because a hypothesis can be tested and falsified, whereas a benchmark asserted without evidence just gets quietly discredited:

AI operating modeWider trust allocationIdentity component
Experimental / assistive, no material write authority1–3%0.25–0.5%
Production read-heavy copilot3–5%0.5–1.0%
Tool-enabled production agent with write authority5–8%1–2%
Privileged / high-impact autonomous agent8–15%2–4%

So the defensible statement isn't "the industry standard is $1–2 of identity per $100 of AI." It's: a reasonable initial planning hypothesis is roughly $1–2 of identity-centric trust investment per $100 of production AI investment for tool-enabled agents with material enterprise authority — rising for privileged or irreversible use cases, falling materially for assistive read-only systems. That you can take to a CFO and defend.

The market envelope — arithmetic, not prophecy

SailPoint's own 2024 market-opportunity estimate was approximately $55B — and it's worth knowing how that was built: company counts by employee cohort, multiplied by average ARR among comparable customers. It is a company-count-and-headcount construction, not an independent industry forecast, and SailPoint explicitly warns actual penetration may differ.

That methodology matters for the AI thesis, because if the economic denominator shifts from employees toward governed autonomous authority, the old method may understate the growth vector. Compounding that $55B anchor:

$75B by 2030 — requires5.3% CAGR · conservative
$100B by 2030 — requires10.5% CAGR · plausible
$150B by 2030 — requires18.2% CAGR · aggressive
$200B by 2030 — requires24.0% CAGR · stretched
$300B by 2030 — requires32.7% CAGR · implausible
Derived calculation compounding SailPoint's self-reported 2024 $55B opportunity estimate. These are arithmetic scenarios, not analyst forecasts. By 2035 the $150–200B envelope becomes materially more plausible, requiring roughly 9.5–12.5% annual growth rather than extraordinary near-term expansion.

The useful conclusion: a $100B+ identity-security envelope by decade's end is a plausible scenario, not an established forecast. It doesn't require a $45B agent-identity category to materialize from nothing — it requires the existing envelope to compound at about 10.5%. That's a far more credible thing to tell a board than "AI makes identity a $200 billion market."

What could make this wrong

A thesis that can't fail isn't a thesis. Four bear cases deserve real weight:

1. Identity for AI becomes necessary but commoditized. If Microsoft, AWS and Google provide agent identity, authorization, credential exchange and lifecycle well enough, agent identity becomes an embedded feature rather than an independent category — the requirement grows enormously while the economics accrue to hyperscalers. The counterweight is enterprise heterogeneity: a Global 2000 firm runs Microsoft agents, AWS agents, Salesforce agents, ServiceNow agents, custom agents and MCP-mediated agents simultaneously. That's a real job for a neutral layer — but only if the layer stays technically relevant to runtime decisions.

2. Agent adoption disappoints. Gartner's >40% cancellation forecast is not a footnote. A slower agent market delays monetization without eliminating the architectural requirement.

3. Runtime authorization consolidates outside governance. This is the sharpest threat. Gartner predicts that by 2030 half of AI-agent deployment failures could be attributable to insufficient runtime enforcement. If that's directionally right, the prize migrates toward runtime platforms, cloud IAM, PAM, policy engines and gateways — and the governance vendors become the system of record around a real-time authorization market owned elsewhere. Still valuable. Materially smaller.

4. Pricing breaks in both directions. Charging human per-seat rates against millions of ephemeral agent instances gets rejected by buyers. Giving non-human identities away severs vendor economics from the fastest-growing identity class. The likely resolution is hybrid — human seats, lower-cost governed units for persistent machine identities, a risk premium on privileged authority, and consumption pricing on runtime enforcement, with ephemeral instances rolling up to logical blueprints.

What a CISO should actually do with this

Skip the market-size debate; it's a vendor problem. The operational takeaway is a metric worth putting on a board slide: Autonomous Authority Under Governance — the share of material autonomous actions governed by attributable policy. Not logged. Governed: associated with an actor, an accountable principal, explicit authority, a policy decision, and a revocation path.

The supporting board dashboard is unglamorous and answerable: production agent count, governed-over-discovered ratio, agents with an accountable sponsor, orphaned agents, privileged agents, privileged agents under JIT, delegation depth, mean time to revoke, and shadow-agent discovery rate. If you can't populate those today, that gap is your roadmap.

The one-line version for your board

An organization's maximum safe AI autonomy should be constrained by its ability to govern autonomous authority. Trust isn't a tax on AI — a mature trust layer expands how much autonomy you can rationally deploy.

SOURCING & METHOD: This segment condenses an evidence-classified research paper produced for The Perimeter (research date Aug 15, 2026). Standards and platform facts per NIST AI Agent Standards Initiative and NCCoE project pages, Microsoft Entra Agent ID documentation, AWS Bedrock AgentCore documentation, and the MCP authorization specification. Governance-maturity data per Deloitte 2026 State of AI and PwC Responsible AI research. Cancellation and runtime-enforcement forecasts per Gartner. Non-human identity ratio per Cloud Security Alliance — a surveyed average, not a universal constant. AI-spend figures per IDC and Gartner, whose differing totals reflect different market definitions. SailPoint's $55B figure is the company's own estimate from its filings, not an independent market measure; the CAGR table is our arithmetic on that anchor. The Trust Ratio and the risk-adjusted allocation table are explicitly proprietary planning hypotheses, not industry benchmarks — we've labelled them as such precisely because the underlying opportunity is real enough that it doesn't need inflating.
03

Vendor Spotlight

the pitch vs. the reality, synthesized from the people who run it

C1 (formerly ConductorOne)
Series B · $111M raised · Greycroft / Accel / Felicis / CrowdStrike Falcon Fund · AI-native IGA + IAM + PAM
VERDICT: STRONG PRODUCT, STRAINED ENGINE, OBVIOUS TARGET
Product / Capability
7.8/10
Implementation Ease
8.5/10
Vendor Stability
6.0/10
Culture & Execution Signal
4.0/10

Recent News — last 12 months

Funding Oct 2025
$79M Series B
$79M Series B — and CrowdStrike is on the cap table

Greycroft led a $79M Series B with participation from CrowdStrike Falcon Fund, Accel, Felicis, Oregon Venture Fund, and Operator Collective, bringing total funding to roughly $111M. Founded in Portland in 2020 by former Okta executives Alex Bovee and Paul Querna, the company unifies IGA, IAM and PAM in a single API-first platform. Greycroft's thesis: agentic systems will grow the identity population "by more than 100x," creating hundreds of billions of identities needing governance.

Read: note the strategic investor. CrowdStrike's venture arm putting money into an identity governance startup is not a passive financial bet — it is an option on a category CrowdStrike has since started buying into outright. More on that below.
C1 Series B announcement ↗
Rebrand Apr 6, 2026
ConductorOne becomes C1 — repositioning around agentic identity

The company dropped the longer name in April, explicitly repositioning from "orchestrating identity governance" to "powering the agentic enterprise." In June it shipped support for enterprise-managed authorization via the open MCP extension — issuing short-lived scoped tokens for MCP servers so agent access runs through one broker with central revocation rather than per-server OAuth consent.

Read: the MCP work is genuinely well-aimed. Central revocation across MCP servers is exactly the control that would have mattered in the Hugging Face incident we covered in Issue 10. This is a team that reads the same threat reports you do.
Product Mar 2026
AI Access Management launched to govern AI tools, agents and MCP connections

C1 shipped AI Access Management in March, alongside its own survey claiming 95% of enterprises now run AI agents autonomously. Independent evaluation from Start with Identity scores the platform 4.1/5, describing it as cloud-native access governance focused on least privilege, automated access reviews, and just-in-time grants — "part of the modern wave rebuilding governance for SaaS-heavy companies that find legacy suites too heavy and too slow to deploy."

Read: the positioning is credible and the independent score is solid. Treat the 95% survey figure as vendor-commissioned marketing, not data.
Culture signal Nov 2025 –
Jul 2026
Employee reviews describe a strained engine behind the product

This is where the assessment gets uncomfortable. C1's RepVue profile carries a 2.7/5 across 14 verified ratings (unclaimed profile). A former employee in June: "CEO running sales team poorly after firing VP of Sales. Change is constant and chaotic." A current AE in November: "If you have an offer here, RUN… Sales leadership is so toxic and fear-based… Product is pretty slick for what it's worth but this is not worth the toll on your mental health." More concerning for buyers, a Portland-based software engineer on Glassdoor: "There are multiple customer-facing incidents every day. Tech debt nightmare and no appetite to address it — even more features."

Read: small sample, and dissent exists — one current AE rates it 4.1 and calls it "disruptive product, tremendous innovation, fantastic team… not a place for the complacent." But note what the negative reviews consistently praise: the product. And what they consistently criticize: leadership churn and engineering debt. That specific pattern — good product, strained org — is a leading indicator worth pricing into a multi-year commitment.
SOURCING: Funding, investors and founder background per C1, Greycroft, Oregon Venture Fund, and CB Insights. Product and MCP capability per company announcements and Start with Identity's independent August 2026 evaluation. Customer names (DigitalOcean, Ramp, Loom, Panther, DeepWatch) per company press materials. Employee sentiment per RepVue (14 verified ratings) and Glassdoor as of Aug 2026 — a small sample from an unclaimed profile, and we weight it accordingly. Individual reviews are the opinions of their authors and are not independently verified; we quote them as sentiment signal, not as established fact about the company's operations.

The Pitch vs. The Reality

What C1 says
  • AI-native from day one — IGA, IAM and PAM unified in one platform, not bolted together
  • Built for agents as first-class identities, not humans with agent features retrofitted
  • API-first with deep connectors; deploys in weeks where legacy suites take quarters
  • Cuts audit effort up to 85% and reduces onboarding time by weeks
What the evidence shows
  • Independent evaluation scores it 4.1/5 — genuinely strong for cloud-first access governance
  • MCP broker work with short-lived scoped tokens and central revocation is real and well-targeted
  • Deployment speed is the consistent praise point; this is the anti-legacy-suite pitch, and it lands
  • Engineering reviews describe daily customer-facing incidents and unaddressed tech debt
  • Sales-leadership churn is documented across multiple reviews over eight months

Community Pulse — synthesized signal

Start with Identity · Independent eval 4.1/5 · Aug 2026
"Cloud-native access governance focused on least privilege, automated access reviews, and just-in-time grants across SaaS and infrastructure — part of the modern wave rebuilding governance for SaaS-heavy companies that find legacy suites too heavy and too slow to deploy."
— scored against a published rubric with no vendor sponsorship. Specifically credits the June 2026 MCP enterprise-managed authorization work: short-lived scoped tokens through one broker with central revocation, rather than per-server OAuth consent
strong, independent
RepVue · Employee Signal 2.7/5 · 14 ratings
"CEO running sales team poorly after firing VP of Sales. Change is constant and chaotic." / "If you have an offer here, RUN. Sales leadership is so toxic and fear-based… Product is pretty slick for what it's worth."
— former employee (Jun 2026) and current AE (Nov 2025). 93% verified, unclaimed profile. Small sample — 14 ratings is not a dataset, and go-to-market churn at a scaling startup is common. But the leadership-instability theme recurs across separate reviewers and separate quarters
leans negative
Glassdoor · Engineering Signal the buyer-relevant one
"This company is the epitome of bad startup culture. There are multiple customer-facing incidents every day. Tech debt nightmare and no appetite to address it — even more features. It's not sustainable and will eventually collapse under its own weight."
— software engineer, Portland, current employee 1+ yr (Nov 2025). Pros listed: "They pay me on time. Great product idea." Advice to management: "Sell the IP to a company with a real CTO and engineering culture." This is one engineer's opinion, not a verified operational fact — but "multiple customer-facing incidents every day" is a specific, checkable claim you can put to reference customers
strongly negative
The counterweight dissent exists
"Disruptive product, tremendous innovation, and fantastic team. This is not a place for the complacent. High effort, energy, and performance culture."
— current AE, 4.1/5 (Jun 2026). We include this deliberately. A high-intensity performance culture reads as "toxic" to some and "fantastic" to others, and a 14-rating sample amplifies whichever voice showed up. The honest read is a fast-moving company under real strain — not a company in crisis
positive outlier
Customer base · reported credible logos
"DigitalOcean, Ramp, Loom, Panther, DeepWatch — and Fortune 500 customers globally."
— per company press materials and Oregon Venture Fund. Skews cloud-native and mid-market-to-enterprise, which fits the product's design centre. We have not independently verified deployment scale at any named customer
real traction
METHOD: Synthesized from Start with Identity's independent August 2026 evaluation, RepVue (14 verified ratings), Glassdoor, company and investor announcements, and CB Insights company data as of Aug 2026. A note on the fourth axis: we replaced our usual sentiment score with Culture & Execution Signal and scored it 4.0 — low, but read the reasoning rather than the number. Fourteen RepVue ratings is a thin sample and a high-intensity startup will always generate polarized reviews. What moved us is the consistency of the specific complaint: multiple independent reviewers, across three quarters, describing leadership churn and engineering debt while simultaneously praising the product. That pattern is a leading indicator of delivery risk, not a verdict on the company. Product and Implementation scores reflect the genuinely strong independent evaluation. Vendor Stability (6.0) reflects real funding and a credible strategic investor weighed against Series B scale and an unresolved execution question.

The Signal Read

Trajectory: a good product with a real question attached — and a very short list of likely buyers. Start with what's genuinely strong. C1 is built by people who know this problem cold: Alex Bovee and Paul Querna came out of Okta, and the platform reflects it. An independent evaluator scores it 4.1/5. The MCP broker work — short-lived scoped tokens, central revocation across servers — is one of the better-aimed pieces of agent-access engineering we've seen this year, and it addresses precisely the failure mode that produced the Hugging Face incident. For a cloud-native organization that finds legacy IGA suites too heavy, this belongs on the shortlist.

The complication is the engine behind it. Fourteen RepVue ratings is a small sample, and we're weighting it as such. But across three quarters and multiple independent reviewers, the same two themes recur: go-to-market leadership churn, and engineering debt. One current engineer's description — "multiple customer-facing incidents every day" — is exactly the kind of claim a buyer can and should verify directly with references. It may be one frustrated voice. It may be a preview of your support experience. The way to find out is to ask, not to assume either way.

And then there is the acquisition question, which we think is the most interesting thing about C1 right now. Look at the pattern this newsletter has documented over five issues: Cisco bought Astrix (~$400M) then WideField. CrowdStrike bought SGNL, then Seraphic. SailPoint closed Entro (~$200M). 1Password bought Apono. Barracuda bought Evo. Cyera is buying Oasis for $1B. Every major platform has concluded it must own agentic identity, and almost none of them are building it. C1 is a $111M-raised, Series B, AI-native IGA/IAM/PAM platform with MCP-native architecture — and CrowdStrike's Falcon Fund is already an investor.

Speculation — clearly labelled as such

Does CrowdStrike buy C1? We'd put it as the single most plausible pairing in the current market, for four reasons. First, Falcon Fund's existing position gives CrowdStrike information rights, relationship access, and a cost basis — the same structural advantages that made the Cyera/Oasis deal so frictionless. Second, CrowdStrike has already demonstrated appetite: the SGNL acquisition put it directly into identity, and Seraphic followed within a week. Third, the architectural fit is clean — CrowdStrike owns endpoint and increasingly the agentic SOC; C1 would give it the governance and authorization layer without a build cycle it can't afford in this market. Fourth, C1's own engineering reviews suggest an organization that would benefit from a larger platform's resources, and at least one employee explicitly advised management to "sell the IP to a company with a real CTO and engineering culture."

The counter-arguments are real. CrowdStrike just spent on SGNL, which overlaps meaningfully with C1's authorization story — buying both would mean paying twice for adjacent capability, the same reason we argued in Issue 11 that Cyera is unlikely to also buy Linx. Palo Alto, Cisco, or a private-equity roll-up are all credible alternative acquirers. And C1's investors may simply want another round at a higher mark; a Series B company with this positioning has options.

Our read: C1 gets acquired within 18–24 months with meaningfully better-than-even odds, and CrowdStrike is the most likely single buyer without being the favourite outright. This is opinion, not reporting — we have no knowledge of any process, and nothing here should be read as a claim that talks exist. For a buyer, the practical consequence is unchanged from our Issue 10 advice on Linx: this is not a reason to walk away. It is a reason to negotiate change-of-control terms, roadmap commitments, and support continuity before you sign, when you still have leverage.

Consider it if…
  • You're cloud-native and legacy IGA suites are too heavy, too slow, or too expensive for your estate
  • MCP-mediated agent access is in your architecture — the token-broker work here is genuinely ahead
  • You want IGA, IAM and PAM from one platform without a multi-quarter integration project
  • You're comfortable trading incumbent scale for speed and a vendor that will take your calls
Do your homework on…
  • Ask references directly about incident frequency and support responsiveness over the last two quarters
  • Ask who your account team will be — leadership churn is the most consistent signal in the reviews
  • Get change-of-control terms, roadmap commitments and support continuity in writing now
  • Run a real proof-of-concept at your scale, not a scripted demo, and watch how they handle a bug
  • Model what a CrowdStrike or Palo Alto acquisition would mean for your deployment and your pricing
04

The Stack

a category, tool, or idea worth knowing this week

Board metric to adopt

Autonomous Authority Under Governance

The share of material autonomous actions governed by attributable policy. The word doing the work is governed — an action counts only if you can associate it with an actor, an accountable principal, explicit authority, a policy decision, and a revocation path. Logging alone doesn't count. If you can't produce this number today, the gap between what you can measure and what this metric requires is a fair description of your agent-governance roadmap.

Question for every vendor

"Audience-bound tokens, or token passthrough?"

The July 2026 MCP authorization spec explicitly requires audience-bound tokens and prohibits passthrough. That single question separates vendors who implemented the spec from vendors who added "MCP support" to a slide. Ask it early, ask for the implementation detail, and notice how fast the answer arrives.

Diligence technique

Read employee reviews for the pattern, not the verdict

Any small company will have polarized reviews, and a 14-rating sample proves nothing on its own. What's diagnostic is consistency of the specific complaint across independent reviewers and separate quarters — and especially the combination we saw in this issue's spotlight, where negative reviews praise the product and criticize the org. That pattern predicts delivery risk far better than a star rating. Then take the checkable claims to reference customers and let them settle it.

05

Boardroom

one line to sound three moves ahead in your next exec meeting

Say this

Reframe trust from a tax on AI into the thing that lets you deploy more of it

The default board conversation treats AI governance as friction — a cost that slows the AI roadmap down. That framing loses you the budget argument every time, because it puts security in opposition to the thing the CEO wants. Invert it. Deloitte found only 21% of organizations have mature agent governance while three-quarters plan agent deployment within two years, and Gartner expects over 40% of agentic projects to be cancelled partly on inadequate risk controls. Governance isn't what slows AI down. It's what stops your AI programme from being one of the cancelled ones.

"Our maximum safe AI autonomy is capped by our ability to govern autonomous authority. Right now that cap is lower than our ambition. Raising it isn't a security project — it's how we get more AI into production without becoming a cautionary tale."
06

Overheard

a spicy anonymized take from the community this week

"Walked the Black Hat floor and counted eleven vendors selling me a way to stop AI agents doing things they shouldn't. Not one of them could tell me how they'd know which agents I already have. Everyone's selling the brakes. Nobody's selling the odometer."
— CISO, global manufacturer · overheard on the show floor, lightly paraphrased