Black Hat came and went, and the thing worth noticing wasn't any single product or vulnerability. It was that the entire show floor converged on one problem. Rubrik launched Agent Identity. Zero Networks launched Least Agency Enforcement. Sweet Security launched Agentic AI Blocking. Cyera launched Agent Guardian. Acalvio launched deception guardrails for agentic environments. Strip the branding off and every one of them is answering the same question: what should this autonomous actor be permitted to do, and how do we stop it when the answer changes? That is an identity question wearing a runtime costume, and BeyondTrust put a number on why it matters — 75% of the attacks its offensive team ran last year involved an identity or privilege issue.
So this issue does three things. We walk the Black Hat announcements and the fortnight's other news, including a genuinely uncomfortable thread developing around Saviynt's release quality. Then a special research segment: Identity Security as Critical Infrastructure — the argument that AI's real disruption isn't more identities, it's more autonomous authority, and what that does to the market's size and shape. Then a vendor assessment of C1, formerly ConductorOne — a sharp, well-funded challenger with a culture signal worth reading carefully, and an acquisition profile that is hard to ignore once you notice who already sits on its cap table. Let's get into it.
two weeks, Black Hat included — & why it lands on your desk
Black Hat USA ran Aug 1–6 at Mandalay Bay with a dedicated AI Zone, and the vendor announcements told one story. Rubrik launched Agent Identity, arguing static credentials are structurally wrong for autonomous agents. Zero Networks launched Least Agency Enforcement — identity-based microsegmentation plus just-in-time MFA to stop agents exceeding intended authority. Sweet Security launched Agentic AI Blocking to terminate unauthorized tool calls at runtime. Cyera introduced Agent Guardian. Acalvio shipped deception guardrails that watch agent interactions for jailbreak and prompt-injection attempts. Underneath it all, BeyondTrust's Phantom Labs Research Index found 75% of attacks involved an identity or privilege issue, with credential exposure, privilege escalation, and identity misconfiguration leading the root causes.
A thread worth watching. Practitioner complaints about Saviynt's release cadence and stability have moved from scattered to consistent. A March 2026 Gartner Peer Insights reviewer describes the company missing its own stated release timeline, shipping without advance release notes, and applying undisclosed hotfixes that broke a dev environment — "we had a major issue on our Dev environment behaving very different and had broken rules that prod did not have… support ticket and waited for weeks," resolved only when told the fix was to wait for the next city-named release. A G2 reviewer puts it plainly: "There were some issues being observed in every Saviynt release." Saviynt's own support forums carry a standing "Defect or Issue" label thick with post-upgrade breakage. Separately, an anonymous employee-review post this month alleges a recent named release is disrupting major customer environments; we have not been able to corroborate that claim and are not repeating its specifics.
NIST's AI Agent Standards Initiative, launched February, explicitly includes agent authentication and identity infrastructure for secure human-agent and multi-agent interaction; its National Cybersecurity Center of Excellence is separately running a project on identifying software agents and authorizing their access and actions. Meanwhile the July 2026 Model Context Protocol authorization spec landed on OAuth 2.1 resource-server semantics and explicitly requires audience-bound tokens rather than token passthrough.
Microsoft Entra Agent ID is generally available, giving agents identity, authentication, authorization, lifecycle governance, and — notably — a human sponsor construct with transferable ownership. AWS Bedrock AgentCore Identity handles agent identity, credential management, OAuth delegated access, and on-behalf-of token exchange that preserves both user and agent identity downstream. Google is exposing agent identities built on SPIFFE identifiers.
Deloitte's 2026 State of AI research found roughly one in five organizations expecting to deploy autonomous agents reported a mature agent-governance model — while close to three-quarters planned agent deployment within two years. PwC found lack of trust was already a top-three agent-adoption blocker, with trust dropping to 20% for financial transactions. Gartner expects more than 40% of agentic AI projects to be cancelled by end of 2027 on cost, unclear value, or inadequate risk controls.
Black Hat's research track ran hard at agentic risk: credential theft through agent workflows, autonomous attack chains, and emerging risks in AI coding agents and non-human identities. A new class of NAT trust-assumption attacks was disclosed alongside CVE-2026-20200, a critical Cisco Integrated Management Controller flaw enabling privileged access. One recurring theme from the sessions: an agent abusing its own legitimate credentials doesn't look like malware, because it isn't malware.
identity security as critical infrastructure for the AI economy
The common version of this argument — "AI means more identities, therefore identity vendors win" — is weak, and buyers can smell it. The stronger version survives scrutiny: enterprises now need a scalable way to determine which actor may exercise which authority, over which resource, on whose behalf, under what conditions, and for how long. That is a different and much harder problem.
The first phase of generative AI was about output: can it write, summarize, code, reason. Those are questions about intelligence. The phase we're in now asks something categorically different: can it act? Can it open Salesforce, query Snowflake, change a customer record, authorize a refund, modify infrastructure, commit code, approve an invoice, trigger a wire transfer, provision another identity, delegate to another agent?
Every one of those has a structure underneath it. There is an actor. A principal on whose behalf it operates. A resource. An action. A permission, and a reason the permission exists. A policy. Possibly a delegation chain. A duration. An accountable owner. And — critically — a way to terminate the authority. That structure is the product. Not the identity count.
Autonomous intelligence requires governable authority. AI creates intelligence. Identity establishes authority. Governance creates trust. That framing is far harder to disprove than declaring any single product category the sole "control plane" for AI — which is what most vendor marketing currently attempts.
What makes this more than a marketing narrative is that the architectural convergence is visible in places with no commercial stake in identity vendors doing well. NIST launched an AI Agent Standards Initiative in February that explicitly covers agent authentication and identity infrastructure; its NCCoE is separately working on identifying software agents and authorizing their access and actions. The July 2026 MCP authorization spec requires audience-bound tokens. And three major cloud ecosystems independently arrived at the same conclusion — Microsoft Entra Agent ID, AWS Bedrock AgentCore Identity, and Google's SPIFFE-based agent identities all treat the agent as an identity-bearing, authorization-requiring enterprise principal.
That's strong support for identity becoming a necessary architectural primitive for agentic computing. It is not proof that any standalone identity vendor captures the resulting economics — a distinction most vendor decks blur, and one worth holding onto.
Here is where most versions of this argument fall apart, and where the discipline matters. There is a tempting move available: take the biggest available AI-spend number, multiply by a security percentage, announce a market. It is methodologically unsound, and the numbers on offer make it very tempting — IDC put AI infrastructure at $318B in 2025 heading past $1T by 2029; Gartner's broader taxonomy reaches $2.59T of total AI spend in 2026.
Those aren't contradictions, they're different market definitions — which is precisely why multiplying the largest one by a desired percentage produces a fantasy. The right denominator is addressable production AI spend: models and inference, AI applications, agent platforms and workflows, orchestration, AI-specific services. It should generally exclude semiconductor fabrication, grid investment, and hyperscaler data-center capex the enterprise doesn't own or secure.
No authoritative source establishes a universal "identity should be X% of AI spend" rule. Gartner's January 2026 forecast places $51.3B of "AI Cybersecurity" inside $2.53T of AI spending — arithmetically about 2.0% — but Gartner's public release doesn't define that category as spending required to secure AI, so it cannot honestly be used as proof of a 2% ratio. Any vendor citing it that way is overreaching.
What survives is a risk-adjusted planning hypothesis, explicitly labelled as one — because a hypothesis can be tested and falsified, whereas a benchmark asserted without evidence just gets quietly discredited:
| AI operating mode | Wider trust allocation | Identity component |
|---|---|---|
| Experimental / assistive, no material write authority | 1–3% | 0.25–0.5% |
| Production read-heavy copilot | 3–5% | 0.5–1.0% |
| Tool-enabled production agent with write authority | 5–8% | 1–2% |
| Privileged / high-impact autonomous agent | 8–15% | 2–4% |
So the defensible statement isn't "the industry standard is $1–2 of identity per $100 of AI." It's: a reasonable initial planning hypothesis is roughly $1–2 of identity-centric trust investment per $100 of production AI investment for tool-enabled agents with material enterprise authority — rising for privileged or irreversible use cases, falling materially for assistive read-only systems. That you can take to a CFO and defend.
SailPoint's own 2024 market-opportunity estimate was approximately $55B — and it's worth knowing how that was built: company counts by employee cohort, multiplied by average ARR among comparable customers. It is a company-count-and-headcount construction, not an independent industry forecast, and SailPoint explicitly warns actual penetration may differ.
That methodology matters for the AI thesis, because if the economic denominator shifts from employees toward governed autonomous authority, the old method may understate the growth vector. Compounding that $55B anchor:
The useful conclusion: a $100B+ identity-security envelope by decade's end is a plausible scenario, not an established forecast. It doesn't require a $45B agent-identity category to materialize from nothing — it requires the existing envelope to compound at about 10.5%. That's a far more credible thing to tell a board than "AI makes identity a $200 billion market."
A thesis that can't fail isn't a thesis. Four bear cases deserve real weight:
1. Identity for AI becomes necessary but commoditized. If Microsoft, AWS and Google provide agent identity, authorization, credential exchange and lifecycle well enough, agent identity becomes an embedded feature rather than an independent category — the requirement grows enormously while the economics accrue to hyperscalers. The counterweight is enterprise heterogeneity: a Global 2000 firm runs Microsoft agents, AWS agents, Salesforce agents, ServiceNow agents, custom agents and MCP-mediated agents simultaneously. That's a real job for a neutral layer — but only if the layer stays technically relevant to runtime decisions.
2. Agent adoption disappoints. Gartner's >40% cancellation forecast is not a footnote. A slower agent market delays monetization without eliminating the architectural requirement.
3. Runtime authorization consolidates outside governance. This is the sharpest threat. Gartner predicts that by 2030 half of AI-agent deployment failures could be attributable to insufficient runtime enforcement. If that's directionally right, the prize migrates toward runtime platforms, cloud IAM, PAM, policy engines and gateways — and the governance vendors become the system of record around a real-time authorization market owned elsewhere. Still valuable. Materially smaller.
4. Pricing breaks in both directions. Charging human per-seat rates against millions of ephemeral agent instances gets rejected by buyers. Giving non-human identities away severs vendor economics from the fastest-growing identity class. The likely resolution is hybrid — human seats, lower-cost governed units for persistent machine identities, a risk premium on privileged authority, and consumption pricing on runtime enforcement, with ephemeral instances rolling up to logical blueprints.
Skip the market-size debate; it's a vendor problem. The operational takeaway is a metric worth putting on a board slide: Autonomous Authority Under Governance — the share of material autonomous actions governed by attributable policy. Not logged. Governed: associated with an actor, an accountable principal, explicit authority, a policy decision, and a revocation path.
The supporting board dashboard is unglamorous and answerable: production agent count, governed-over-discovered ratio, agents with an accountable sponsor, orphaned agents, privileged agents, privileged agents under JIT, delegation depth, mean time to revoke, and shadow-agent discovery rate. If you can't populate those today, that gap is your roadmap.
An organization's maximum safe AI autonomy should be constrained by its ability to govern autonomous authority. Trust isn't a tax on AI — a mature trust layer expands how much autonomy you can rationally deploy.
the pitch vs. the reality, synthesized from the people who run it
Greycroft led a $79M Series B with participation from CrowdStrike Falcon Fund, Accel, Felicis, Oregon Venture Fund, and Operator Collective, bringing total funding to roughly $111M. Founded in Portland in 2020 by former Okta executives Alex Bovee and Paul Querna, the company unifies IGA, IAM and PAM in a single API-first platform. Greycroft's thesis: agentic systems will grow the identity population "by more than 100x," creating hundreds of billions of identities needing governance.
The company dropped the longer name in April, explicitly repositioning from "orchestrating identity governance" to "powering the agentic enterprise." In June it shipped support for enterprise-managed authorization via the open MCP extension — issuing short-lived scoped tokens for MCP servers so agent access runs through one broker with central revocation rather than per-server OAuth consent.
C1 shipped AI Access Management in March, alongside its own survey claiming 95% of enterprises now run AI agents autonomously. Independent evaluation from Start with Identity scores the platform 4.1/5, describing it as cloud-native access governance focused on least privilege, automated access reviews, and just-in-time grants — "part of the modern wave rebuilding governance for SaaS-heavy companies that find legacy suites too heavy and too slow to deploy."
This is where the assessment gets uncomfortable. C1's RepVue profile carries a 2.7/5 across 14 verified ratings (unclaimed profile). A former employee in June: "CEO running sales team poorly after firing VP of Sales. Change is constant and chaotic." A current AE in November: "If you have an offer here, RUN… Sales leadership is so toxic and fear-based… Product is pretty slick for what it's worth but this is not worth the toll on your mental health." More concerning for buyers, a Portland-based software engineer on Glassdoor: "There are multiple customer-facing incidents every day. Tech debt nightmare and no appetite to address it — even more features."
Trajectory: a good product with a real question attached — and a very short list of likely buyers. Start with what's genuinely strong. C1 is built by people who know this problem cold: Alex Bovee and Paul Querna came out of Okta, and the platform reflects it. An independent evaluator scores it 4.1/5. The MCP broker work — short-lived scoped tokens, central revocation across servers — is one of the better-aimed pieces of agent-access engineering we've seen this year, and it addresses precisely the failure mode that produced the Hugging Face incident. For a cloud-native organization that finds legacy IGA suites too heavy, this belongs on the shortlist.
The complication is the engine behind it. Fourteen RepVue ratings is a small sample, and we're weighting it as such. But across three quarters and multiple independent reviewers, the same two themes recur: go-to-market leadership churn, and engineering debt. One current engineer's description — "multiple customer-facing incidents every day" — is exactly the kind of claim a buyer can and should verify directly with references. It may be one frustrated voice. It may be a preview of your support experience. The way to find out is to ask, not to assume either way.
And then there is the acquisition question, which we think is the most interesting thing about C1 right now. Look at the pattern this newsletter has documented over five issues: Cisco bought Astrix (~$400M) then WideField. CrowdStrike bought SGNL, then Seraphic. SailPoint closed Entro (~$200M). 1Password bought Apono. Barracuda bought Evo. Cyera is buying Oasis for $1B. Every major platform has concluded it must own agentic identity, and almost none of them are building it. C1 is a $111M-raised, Series B, AI-native IGA/IAM/PAM platform with MCP-native architecture — and CrowdStrike's Falcon Fund is already an investor.
Does CrowdStrike buy C1? We'd put it as the single most plausible pairing in the current market, for four reasons. First, Falcon Fund's existing position gives CrowdStrike information rights, relationship access, and a cost basis — the same structural advantages that made the Cyera/Oasis deal so frictionless. Second, CrowdStrike has already demonstrated appetite: the SGNL acquisition put it directly into identity, and Seraphic followed within a week. Third, the architectural fit is clean — CrowdStrike owns endpoint and increasingly the agentic SOC; C1 would give it the governance and authorization layer without a build cycle it can't afford in this market. Fourth, C1's own engineering reviews suggest an organization that would benefit from a larger platform's resources, and at least one employee explicitly advised management to "sell the IP to a company with a real CTO and engineering culture."
The counter-arguments are real. CrowdStrike just spent on SGNL, which overlaps meaningfully with C1's authorization story — buying both would mean paying twice for adjacent capability, the same reason we argued in Issue 11 that Cyera is unlikely to also buy Linx. Palo Alto, Cisco, or a private-equity roll-up are all credible alternative acquirers. And C1's investors may simply want another round at a higher mark; a Series B company with this positioning has options.
Our read: C1 gets acquired within 18–24 months with meaningfully better-than-even odds, and CrowdStrike is the most likely single buyer without being the favourite outright. This is opinion, not reporting — we have no knowledge of any process, and nothing here should be read as a claim that talks exist. For a buyer, the practical consequence is unchanged from our Issue 10 advice on Linx: this is not a reason to walk away. It is a reason to negotiate change-of-control terms, roadmap commitments, and support continuity before you sign, when you still have leverage.
a category, tool, or idea worth knowing this week
The share of material autonomous actions governed by attributable policy. The word doing the work is governed — an action counts only if you can associate it with an actor, an accountable principal, explicit authority, a policy decision, and a revocation path. Logging alone doesn't count. If you can't produce this number today, the gap between what you can measure and what this metric requires is a fair description of your agent-governance roadmap.
The July 2026 MCP authorization spec explicitly requires audience-bound tokens and prohibits passthrough. That single question separates vendors who implemented the spec from vendors who added "MCP support" to a slide. Ask it early, ask for the implementation detail, and notice how fast the answer arrives.
Any small company will have polarized reviews, and a 14-rating sample proves nothing on its own. What's diagnostic is consistency of the specific complaint across independent reviewers and separate quarters — and especially the combination we saw in this issue's spotlight, where negative reviews praise the product and criticize the org. That pattern predicts delivery risk far better than a star rating. Then take the checkable claims to reference customers and let them settle it.
one line to sound three moves ahead in your next exec meeting
The default board conversation treats AI governance as friction — a cost that slows the AI roadmap down. That framing loses you the budget argument every time, because it puts security in opposition to the thing the CEO wants. Invert it. Deloitte found only 21% of organizations have mature agent governance while three-quarters plan agent deployment within two years, and Gartner expects over 40% of agentic projects to be cancelled partly on inadequate risk controls. Governance isn't what slows AI down. It's what stops your AI programme from being one of the cancelled ones.
a spicy anonymized take from the community this week