Last issue we made a bold, falsifiable prediction about what CrowdStrike would announce at Fal.Con — built entirely on job postings rather than teasers — and then promised to grade ourselves in public. Good news for our credibility, mixed news for the concept of surprise: we mostly nailed it. Agentic Identity Provider is real, Continuous Identity extended everywhere we said it would, the endpoint-to-browser-to-cloud fabric shipped, supply-chain protection landed. We'll show our work below, including the one call we got wrong and the thing we completely missed. A prediction you don't grade is just a horoscope.
The rest of the week kept pace: Proofpoint circling Varonis for ~$5.4B, Saviynt closing a $255M investment that is much more interesting than the headline once you read the fine print — and a small filing in a UK companies registry that, read alongside that raise, tells a story nobody at Saviynt is telling out loud. Then our vendor assessment of Omada, the quietly excellent European IGA that almost nobody in America talks about and probably should. Let's get into it.
the week, distilled — & why it lands on your desk
Reuters, Bloomberg and the WSJ all reported Proofpoint (Thoma Bravo-owned since a $12.3B take-private in 2021) is in advanced talks to acquire data-security firm Varonis, sending Varonis up ~10–13% to a market value near $5.4B. Nothing's signed and another bidder could still emerge, but the logic is clean: Proofpoint protects the human attack surface, Varonis protects and classifies the data behind it. Together that's a data-security-plus-human-risk platform — and, notably, another data-security consolidation right as data and identity keep converging (see: Cyera/Oasis, ServiceNow/Veza).
Carrick Capital announced a $600M single-asset continuation vehicle for Saviynt on Aug 31, including a $255M new commitment — Carrick's largest-ever investment, led by Coller Capital with HSBC Asset Management co-leading. But read what it actually does. It "gave Carrick's existing limited partners the option to roll their equity into the continuation vehicle or realize an 11x gross multiple," and the new money "helped fund a tender offer that provided liquidity to Saviynt employees," completing the final close of the previously announced $700M Series B at the same ~$3B valuation.
At Fal.Con (Sep 2), CrowdStrike introduced the Agentic Identity Provider in Falcon Next-Gen Identity Security, giving every AI agent a trusted identity tied to the human and workload behind it, with short-lived access, MFA requirements, and continuous authorization from the SGNL acquisition. It also extended modern privileged access across SaaS, endpoints, code repos and cloud; shipped software-supply-chain protection that blocks malicious package installs at the endpoint; unified NHI ownership and visibility; and brought the Falcon platform to Anthropic's Claude marketplace. Sentonas flagged "more exciting Agentic IdP announcements at Fal.Con Europe in November."
Even as CrowdStrike blanketed Fal.Con with launches, CRWD traded down roughly 6% across the event days. Nothing broke — the announcements were well received — but the market has grown selective about "AI security" narratives from companies already priced for perfection. It's a healthy reminder heading into the Saviynt and Idira valuation conversations this newsletter keeps having: momentum framing and enterprise value are not the same thing.
Alongside the agent news, CrowdStrike brought CLEAR's verified human identity into the Falcon platform to help teams distinguish trusted users from potential threats — a notable move as deepfakes and synthetic identity make "is this a real human" a live security question, not just an onboarding one. It rhymes with the broader theme: the boundary between identity verification (proving who someone is) and identity security (governing what they can do) is blurring as agents and synthetic identities proliferate.
CrowdStrike and Zscaler extended their partnership to bring Continuous Identity into zero-trust access, and CrowdStrike expanded its standards footprint via OpenID and IDPro. The through-line across the week: agent authorization is standardizing fast — SPIFFE, Shared Signals, CAEP — and the vendors are racing to be the ones whose enforcement point everyone else plugs into.
grading last issue's Fal.Con predictions against what actually shipped
Last issue we argued that hiring is the one roadmap a company can't spin, and made six ranked, falsifiable predictions about Fal.Con. Fal.Con happened. A prediction you don't grade is a horoscope, so here's the honest scorecard — hits, the miss, and the thing we didn't see coming.
| Grade | What we predicted (Issue 14) | What actually shipped at Fal.Con |
|---|---|---|
| ✓ HIT | Continuous Identity reaches GA and becomes the identity headline; the "identity control plane for the agentic enterprise" (~80%) | Agentic Identity Provider launched in Falcon Next-Gen Identity Security, explicitly billed as "the identity control plane for the agentic enterprise." Near word-for-word. |
| ✓ HIT | Continuous Identity extends zero-standing-privilege beyond AD/Entra into SaaS, code repos, cloud (~80%) | CrowdStrike extended "modern privileged access across SaaS applications, endpoints, code repositories, and cloud infrastructure." Exactly the surfaces we named. |
| ✓ HIT | Charlotte AI / AgentWorks and AIDR advancements; "agentic SOC" as the narrative (~85%) | Agentic SOC took center stage on Day 2; AIDR, cross-domain OverWatch hunting into Guardian, and autonomous investigation were core. |
| ✓ HIT | Endpoint → browser → cloud fabric, Falcon Secure Access featured (~75%) | Falcon Secure Access (Seraphic) featured as the browser layer, unified with identity and cloud protection. |
| ✓ HIT | Unified NHI ownership, visibility and intelligence (~implied) | Shipped: unified ownership, visibility and intelligence across non-human identities. |
| ~ EARLY | A cloud entitlement management / NHI governance product from the "new team… at its infancy" posting (~45%) | No standalone CIEM product launched. The hiring signal was real but the product isn't GA — consistent with "at its infancy." We flagged 45%; the market said "not yet." |
| ✗ MISSED | — | Software-supply-chain protection: blocking malicious open-source package installs at the endpoint (XZ-style). We didn't call this. |
| ✗ MISSED | — | Falcon on the Anthropic Claude marketplace, and the CLEAR verified-human-identity integration. Didn't see either coming. |
The core thesis held up well: the dedicated "Sr. Project Manager, Continuous Identity" posting was the tell, and it was accurate. Companies staff a program manager for a launch with a date, and the launch arrived on schedule with the exact positioning we quoted. The Tel Aviv browser-security cluster correctly predicted Falcon Secure Access featuring prominently. Reading the org chart beat reading the teasers.
In Issue 14 we told governance buyers to listen for four words from a product stage — governance, certification, entitlement, lifecycle — as the signal that CrowdStrike was moving into true IGA. None of them shipped as a certification or lifecycle product. Agentic IdP is authorization and enforcement, not access certification campaigns or joiner-mover-leaver provisioning. Our "adjacent, not direct" call on the IGA incumbents holds: CrowdStrike is squeezing the authorization and NHI layers hard, but it did not ship classic governance. SailPoint and Omada's core workflows remain uncontested — for now.
The miss on the upside: we didn't predict software-supply-chain protection or the Anthropic marketplace deal. In hindsight the supply-chain move was foreseeable — the XZ compromise had made "malicious package at the endpoint" a live board-level worry — but there was no distinct hiring cluster pointing at it, which is exactly the limitation of a hiring-signal method: it catches what a company staffs a new team for, and misses what an existing team ships as an extension. The Claude marketplace deal was a distribution move, not a product, so it was never going to show up in engineering reqs.
The one we over-weighted: we put CIEM/entitlement management at 45% and it didn't ship as a product. The "new team at its infancy" language was real, but "at its infancy" turned out to mean exactly that — a team, not a launch. Lesson logged: a hiring post confirms intent and timeline-start, not ship date. We'll calibrate future "infancy" signals lower.
Five of six broadly correct, the miss was a missing prediction rather than a wrong one, and the single most important strategic call — "adjacent, not direct" on IGA — resolved in our favor. We'll keep grading ourselves in public. It's the only way a prediction is worth printing, and it's a useful discipline against the thing this whole newsletter exists to fight: confident claims nobody ever checks.
Saviynt's $255M, the departing director, and what a flat continuation vehicle signals
The headline said "$255M investment in Saviynt." The structure says something more specific — and, read alongside a small filing in a UK companies registry, more interesting. None of it is improper. All of it is worth understanding before you take a "hypergrowth" framing at face value.
Strip the announcement to mechanics. Carrick has held Saviynt since leading its $35M Series A in 2018 — it was the company's only institutional investor until the Series B. Those 2018 dollars are now sitting on a reported ~11x gain, and Carrick's fund that holds them is aging. LPs in an eight-year-old fund want their money back.
A single-asset continuation vehicle solves that. Carrick raises a new ~$600M fund (led by Coller Capital and HSBC), moves the Saviynt stake into it, and offers its original LPs a choice: take the 11x now, or roll into the new vehicle. The $255M of "new capital" primarily funds that liquidity — cashing out exiting LPs and, via a tender offer, letting Saviynt employees sell some shares. Per dot.LA, it "was completed as part of the final close of Saviynt's previously announced $700M Series B," at the same ~$3B valuation.
Fresh primary capital goes onto the company's balance sheet to hire, build, and expand. Secondary capital changes whose name is on existing shares and puts cash in sellers' pockets. This transaction is predominantly the second kind. That is completely legitimate — employees deserve liquidity and funds have lifecycles — but "$255M investment in Saviynt" invites you to picture a war chest for product, and that is mostly not what this is.
Here's the part worth sitting with. The continuation vehicle is priced at roughly $3B — the same valuation as the December 2025 Series B. Eight months, a $300M ARR milestone, an 80%-bookings-growth story, a major platform launch in Zuma… and the mark didn't move.
There are innocent readings — continuation vehicles are often priced conservatively to be defensible to new LPs, and a flat mark protects the incoming Coller/HSBC investors. But connect it to the arithmetic we ran in Issue 11: at ~$300M ARR, a $3B valuation is ~10x, which is supportable only if Saviynt sustains high-growth-tier revenue. A flat continuation mark eight months later is at minimum consistent with a company whose growth is solid but not accelerating the valuation — and a sponsor choosing "give LPs the option to cash out at 11x" over "raise a step-up primary round to fund the next leg" is making a revealed-preference statement about which of those was available.
On September 1, 2026 — the day after the Carrick announcement — the UK companies registry recorded a Form TM01 for SAVIYNT EUROPE LTD: "Termination of appointment of James Jackson as a director on 2026-08-31." A single director resignation at a regional subsidiary is, on its own, nothing. Directors rotate constantly, and we want to be very clear: we have no information about why this happened, and it may be entirely routine.
What makes it worth a careful mention is the timing. The departure is dated August 31 — the exact day of the continuation-vehicle close — and filed September 1. Governance changes at subsidiaries frequently cluster around transaction closings for mundane reasons: board reconstitutions, entity restructurings, and share-ownership changes routinely trigger director updates as a matter of corporate housekeeping. That is the most probable explanation and we'd bet on it.
We are not suggesting anything improper, and we are not speculating about this person. We're noting a factual, public filing whose date lines up precisely with a transaction close, because in aggregate — a flat continuation mark, a secondary-heavy structure, and subsidiary governance changes at the closing date — the picture is of a company and sponsor tidying up and providing liquidity, not one raising fuel for a growth sprint. If your read on Saviynt has been shaped by the momentum framing, this is the counterweight. Nothing here is an allegation; all of it is on the public record.
None of this says Saviynt is a bad product or an unstable vendor. $300M ARR is real, 96% retention is real, and a sponsor willing to keep holding via a continuation vehicle is a form of conviction. What it says is narrower and more useful: discount the "hypergrowth" framing, and price the vendor on its fundamentals, not its press releases. A flat mark and a liquidity-driven raise are the financial equivalent of the "do your homework" verdict we gave Saviynt's product back in Issue 07. The two readings rhyme.
Practically: if you're mid-cycle with Saviynt, this changes nothing about your deployment — but it's a good reason to hold firm on pricing and to get the same upgrade-notification and roadmap commitments we've recommended all along. A vendor providing employee liquidity at a flat mark is a vendor with every incentive to protect revenue, which shows up at renewal.
the pitch vs. the reality, synthesized from the people who run it
While the American incumbents raced to become "identity security platforms" spanning PAM, NHI, ITDR and runtime, Copenhagen-based Omada did something almost contrarian: it stayed an identity governance and administration company and got very good at it. Full-featured, enterprise-grade, cloud-native IGA — identity lifecycle, access certification, role management, policy, and compliance — with a stated specialty in the regulatory regimes European enterprises actually live under (GDPR, NIS2). It's publicly traded on Nasdaq Copenhagen, which brings a level of financial transparency most of its private competitors don't offer.
Omada carries a 4.6/5 aggregate across 218 verified Gartner Peer Insights reviews (44% five-star, 50% four-star, 0% one- or two-star — a genuinely unusual distribution), with 87% willing to recommend. The capability breakdown is telling: Scalability 4.5, Integration 4.5, Identity Life Cycle 4.5, Access Certification 4.3, Customization 4.2. The recurring praise is out-of-the-box connectors, a low-code/no-code administration model, and — repeatedly — the quality of the people. One banking director: "much better than the competition… they pushed very hard to get the product implemented on our timelines."
The most consistent criticism isn't about the product; it's about everything around it. Straight from Gartner reviews: "poor availability of implementation partners… closed user group, with less answers to questions… in the public internet there are no groups or entries in StackOverflow etc." Another, more affectionate but pointed: "The possibilities are endless — but only if you know how." A third describes needing three years and a third-party consultancy to learn the product's depth. The capability is there; finding people who can unlock it is the friction.
Independent buyer's guides now place Omada (SaaS + on-prem, 4.6) alongside a widening field: cloud-native challengers like Linx (5/5), Veza (4.8), Lumos (4.6) and Opal below it on modernity, and SailPoint (4.8) and Saviynt (4.8) above it on scale and mindshare. Omada's cleanest positioning is "GDPR/NIS2 compliance" and European enterprise — a real and defensible niche, but a niche. The agentic/NHI wave is a genuine strategic test: Omada must extend its governance model to non-human and agent identities without losing the focus that makes it good.
Trajectory: the best IGA product most American buyers have never seriously evaluated. After fourteen issues of vendors whose problems ranged from stability to culture to valuation games, Omada is a slightly disorienting change of pace: a company whose biggest weakness is that not enough people know how to implement it. The product is genuinely strong — 4.6/5 with zero bottom-ratings across 218 reviews is a distribution we haven't seen from anyone else in this newsletter — and the consistent praise for its people is the kind of signal that predicts good deployment outcomes.
The focus is the whole thesis, and it cuts both ways. Omada didn't chase the platform-consolidation wave. It stayed an IGA company while SailPoint added NHI, Saviynt added Zuma, Okta added governance and CrowdStrike added everything. That discipline is why its core is so well-regarded — and it's also why Omada is boxed in: cloud-native challengers are more modern, the mega-platforms are broader, and the agentic/NHI wave is a real test of whether a focused governance vendor can extend into non-human identity without losing its edge. Omada's answer to that ("Leading the Future of IGA with AI") is still more slogan than proof.
The honest positioning: this is a European enterprise's best-fit IGA and an American enterprise's underrated option. If you operate under GDPR and NIS2, want hybrid SaaS-plus-on-prem deployment, and value governance done deeply over governance bundled cheaply, Omada should be on your shortlist and frequently isn't. The single caveat that determines your experience is partner availability — confirm you can staff the implementation, from Omada or a capable SI in your region, before you sign. Get that right and this is one of the lower-regret buys in the category.
a category, tool, or idea worth knowing this week
This issue's Saviynt deep dive is the case study. "$255M investment" and "$255M to fund a tender offer so LPs and employees can cash out" are both true and wildly different. Primary capital builds product; secondary capital changes whose name is on the shares. When a vendor cites a raise as proof of momentum, ask which kind it was and whether the valuation stepped up. The pause before the answer is often more informative than the answer.
We predicted CrowdStrike's Fal.Con slate from job postings last issue and graded ourselves this issue — five of six, one miss, calibration noted. The discipline matters beyond bragging rights: a forecast nobody checks is a horoscope, and an industry drowning in unchecked vendor claims should model the opposite behavior. Whatever you predict in a board deck — a vendor's trajectory, a category's direction — write down what would prove you wrong, and revisit it. It's the cheapest credibility you'll ever buy.
This issue's spotlight, Omada, has a 4.6/5 rating with zero bottom ratings across 218 reviews and is barely discussed in American identity circles. Meanwhile the loudest vendors in the category are the ones we've flagged for stability, culture, and valuation games. Marketing spend and product quality are not correlated — sometimes they're inversely correlated. Before you build a shortlist from the vendors you've heard of, check who the practitioners in the reviews actually rate.
one line to sound three moves ahead in your next exec meeting
Your board and your CFO know the loud names — the ones with the biggest booths and the most LinkedIn badges. What they rarely hear is that some of those names are the ones this kind of analysis flags for culture problems, flat valuations, or shelfware, while quieter vendors quietly outscore them with actual customers. When you defend a shortlist, lead with practitioner evidence, not brand recognition. It reframes the conversation from "is this a safe name" to "is this the right tool," which is the conversation you actually want to be having.
a spicy anonymized take from the community this week