Live intel Sat · 26 Sep 2026 · 06:00 ET

ThePerimeter

FOR CIOs & CISOs
VOL. 1 · ISSUE 17 Sponsored by — your logo here — Subscribers: 26,610
// Good morning, defenders.

Okta gathered the industry in Las Vegas this week and unveiled a "Blueprint for the Secure Agentic Enterprise," complete with a "Blueprint Alliance" of CrowdStrike, Zscaler, AWS, Salesforce and Google. It is a genuinely useful set of ideas wrapped in the most crowded word in security. And it arrived in the same fortnight that Cyera raised another $400M — its third round of 2026 — at a valuation that, notably, did not move. Two very different signals about where this market's money and language are going, and both worth reading closely.

So this issue covers the last two weeks in full: Oktane and why we're skeptical of alliance theater, Cyera's remarkable cash intake and the operational-efficiency question it raises, and a vendor deep-dive on One Identity — a good product inside an ownership structure we think is about to change hands. Plus a piece on the quiet mistake underneath the agent-governance gold rush: everyone is racing to govern non-human identities while the human identity program that makes it all work sits half-built. We refresh the Buzzword Index too. Let's get into it.

01

Market Movers

two weeks, distilled — & why it lands on your desk

EventOktane

Okta unveils a "Blueprint for the Secure Agentic Enterprise" — and an alliance to go with it

At Oktane (Sep 22–24), Okta announced its Blueprint framework built around three questions — where are my agents, what can they connect to, what can they do — plus "Okta for AI Agents" to discover known and "shadow" agents, register them as first-class identities in Universal Directory, and "instantly revoke access… the ultimate kill switch." It extended its Identity Security Fabric (SSO, governance, provisioning) to agents, proposed "Cross-App Access" (XAA) as an open MCP extension, and closed its Permiso acquisition. The headline organizational move: a "Blueprint Alliance" with CrowdStrike, Zscaler, AWS, Salesforce and Google.

Why it matters: the technical work — agents as a governed identity class, XAA on MCP, a revoke path — is real and useful. The alliance is the part to price carefully. We make the skeptical case in section 02: identity-security alliances have a poor track record of turning into anything a buyer can actually deploy, and a fabric announced alongside a five-logo slide is still, mostly, a slide.
Funding$400M

Cyera raises again — a third 2026 round — at a flat $12B valuation

On Sep 22, Cyera announced a $400M Series G extension led by Goldman Sachs Alternatives. It is the company's third raise this year: a $300M Series F in January (~$9B), a $540M Series G in June (~$12B), and now this extension — at the same ~$12B valuation as June. That's roughly $1.2B raised in 2026 and more than $2B in total for a company founded in 2021, now ~1,500 employees across 18 countries with six acquisitions behind it (including Oasis Security for ~$1B).

Why it matters: a flat valuation on a fresh round is not a knock by itself in this market — but the sheer volume of capital, on the back of a data-security business that is compute- and storage-heavy by nature, raises a fair question about unit economics and burn. We take a hard, fair look in the deep dive.
M&AReport

One Identity may be headed for a new owner — or the chopping block

Bloomberg reported that Clearlake Capital — which owns Quest Software, and with it One Identity — is exploring options that include combining One Identity with RSA's SecurID into a new company and selling a stake to another private-equity firm. One Identity has passed through Dell, then Francisco Partners, then Clearlake (2021, ~$5.4B for Quest), took a $350M Clearlake debt-refinancing infusion in 2025, and installed a new CEO, Praerit Garg, the same year.

Why it matters: if you run One Identity — Safeguard, OneLogin, Identity Manager, Active Roles — a change-of-control scenario just moved from theoretical to reported. This issue's vendor spotlight is One Identity, and our prediction is unambiguous: another PE flip, a merger, or a carve-up. Model it now.
M&AEmpowerID

Omada buys EmpowerID — and the way it was framed tells you how far EmpowerID had fallen

On Sep 24, Omada — our Issue 15 spotlight and current #3 on the Vendor Index — announced it had acquired EmpowerID. Terms were not disclosed. The official framing is strategic and forward-looking: Omada gets runtime authorization for AI agents (an AuthZEN-compliant policy decision point, an MCP gateway, 300+ connectors) and "a credible path" into PBAM, PAM and Zero Trust. Notably, the announcement said almost nothing about EmpowerID's own IGA suite or its existing customers — one reference deployment governs 569,000 identities — and analysts immediately flagged the risk that the EmpowerID product line gets absorbed and its heavily-customized deployments orphaned. Remember what EmpowerID was: a KuppingerCole "Overall Leader" in its IDaaS-IGA Leadership Compass. That is a steep arc — from named leader to an acquisition that's pitched entirely around one piece of the tech and silent on the rest.

Why it matters: when an acquirer buys a full IGA platform but talks only about its agent-authorization engine, the market read is that it wanted the parts, not the company — the profile of an asset bought cheap out of weakness rather than at a premium out of strength. If you're an EmpowerID customer, treat this as a change-of-control event today: get written support commitments and a roadmap for the product line you actually run, especially if you depend on customizations. Our read (labeled speculation): the undisclosed terms, the parts-first framing, and a former KC Leader landing here read to us like a distressed, fire-sale-shaped exit — a company that ran out of room rather than one sold at the top. Omada and EmpowerID have not characterized it that way, and no bankruptcy filing is reported; this is our interpretation, not reported fact.
ProductXAA

The quiet good news at Oktane: agent-access standards keep converging

Beneath the framework branding, the interoperability work is genuine. Okta's Cross-App Access extends MCP with audience-bound tokens; it dovetails with CrowdStrike's SPIFFE/CAEP posture at Fal.Con and the July MCP authorization spec. For all the marketing sameness, the plumbing under agent identity is standardizing — which is the thing buyers should actually reward.

Why it matters: a vendor implementing open agent-access standards is handing you exit options; one pushing a proprietary agent model is building a moat around your estate. When you're pitched an "agentic" story, ask which one it is — the answer is more predictive than any keynote.
ThreatHuman

The agent-governance rush keeps ignoring where the breaches actually start: people

The market's whole vocabulary this fortnight was non-human: agents, NHIs, workload identity, machine credentials. Meanwhile the incidents that keep landing — including the Hugging Face token exposure we revisit in section 04 — trace back to ordinary human-identity hygiene: over-scoped tokens, no lifecycle, no real identity program behind the machine accounts. The governance you're being sold for agents only works if the human layer under it is already sound.

Why it matters: before you fund an NHI or agent-governance project, ask whether your human joiner-mover-leaver, least-privilege and access-review basics are actually operating. If they're not, you're buying a lock for the window while the front door stands open.
Market93%

The Sea of Sameness ticked up — Oktane poured more of the same words in

Our Buzzword Index refresh (below) reads a higher composite this fortnight, driven almost entirely by Oktane. "Fabric," "first-class identities," "shadow agents," "kill switch," "control plane," "blueprint" — Okta's launch language is now nearly indistinguishable from SailPoint's, Saviynt's and CrowdStrike's. Cross-vendor claim overlap on the core agentic themes nudged to about 93%.

Why it matters: when claim overlap runs in the low-90s, the marketing has no shortlisting value at all. Cut vendors on what they demonstrate in your environment, not on what they say from a stage. That is the entire reason the Buzzword Index exists.
02

The Analysis

Oktane's Blueprint Alliance, and why we grade alliances on delivery, not press releases

Alliance theater
Another year, another five-logo alliance. Show us the integration.

Okta's "Blueprint Alliance" — CrowdStrike, Zscaler, AWS, Salesforce, Google — is the latest in a genre the identity market has run for years: the big-tent security alliance, announced with a keynote and a shared slide, promising an integrated future. We are skeptical, and the skepticism is earned. The overwhelming majority of these alliances have not turned into a single thing a buyer can deploy differently the next morning.

What was actually announced

Okta's Blueprint is a coherent framework: treat agents as first-class identities, discover the shadow ones, govern them through the existing Identity Security Fabric, and keep a fast revoke path. The technical pieces — Okta for AI Agents, XAA on MCP, the Universal Directory agent category — are real product. The Alliance, by contrast, is a statement of intent among six companies that already integrate with each other in the ordinary course of business. Even Okta's own leadership signaled restraint: co-founder and CEO Todd McKinnon described joint go-to-market and shared economic incentives as "premature." When the company announcing the alliance is publicly tapping the brakes on what it actually means commercially, a buyer should take the cue.

The track record, which is the whole argument

The identity and security industry has produced a long parade of alliances, consortia and "ecosystems" over the past several years. A few — mostly the standards bodies — produced durable, useful specifications. Most of the commercial alliances produced a launch moment and little a customer could point to a year later. The pattern is consistent enough to treat as a base rate:

What gets announcedThe promiseWhat usually materializes
A branded alliance of 4–6 large vendors "Deep, seamless integration across the stack" The same API-level integrations that already existed, now with a logo lockup
Joint go-to-market language "One motion, better outcomes for shared customers" Rarely a joint SKU, joint support, or joint accountability; sales teams still compete
A shared "framework" or "blueprint" "An open, vendor-neutral reference architecture" A reference architecture that centers the announcing vendor's platform
A standards commitment inside the alliance "We'll converge on open protocols" This part often does deliver — but it delivers through the standards body, not the alliance branding

Note the last row, because it's where we're fair to Okta. The genuinely valuable output of this announcement — Cross-App Access on MCP — is real precisely because it's headed for an open specification, not because it's inside a branded alliance. The plumbing standardizes; the alliance mostly markets.

Why alliances underdeliver — structurally, not cynically

This isn't bad faith; it's incentives. A commercial alliance among large, independently public (or PE-owned) vendors has no shared P&L, no shared roadmap authority, and no mechanism to force a partner to prioritize a joint integration over its own quarter. Each member optimizes for its own pipeline. The alliance has a marketing budget and a logo; it does not have the one thing that produces integrated products, which is a single team that owns the outcome and can be fired for missing it. That is why the durable interoperability in this industry comes from standards (SAML, SCIM, OIDC, SSF/CAEP, and now MCP) and from acquisitions — one company buying another and merging the codebases — and almost never from an alliance.

What a buyer should do with the Blueprint

Take the framework seriously and the alliance lightly. The three Blueprint questions are good governance questions; ask them of every agentic vendor, Okta included. But do not let "member of the Blueprint Alliance" appear on a vendor's scorecard as a capability. It isn't one. If Okta and CrowdStrike genuinely ship a jointly-supported, jointly-accountable integration with a name, a SKU and a support path, reward that when it exists — and hold the receipt from this week to check against it a year from now. We will.

SOURCING & CARE: Oktane announcements, product names and framing per Okta's own Sep 22–24 2026 materials and contemporaneous reporting. The McKinnon "premature" characterization of joint go-to-market/economic incentives is drawn from event coverage; we quote it as a signal of Okta's own posture, not as criticism of the executive. Alliance-membership list per Okta. The "track record" table is our editorial synthesis of how large commercial security alliances have historically converted into deployable product — it is analysis and a stated base-rate argument, not a claim about any specific prior alliance's contractual terms. Okta was not contacted and did not review this analysis. Nothing here questions the technical merit of XAA/MCP, which we credit as genuine.
03

Deep Dive

Cyera raised a third time in 2026 — where is all that money going?

Follow the cash
$2B+ raised, a flat valuation, and a business that is expensive to run by design

Cyera is one of the most impressive growth stories in security — real ARR, real logos, a category it helped define. It is also raising money at a pace that deserves a clear-eyed question no keynote will ask: for a data-security platform that must continuously scan, classify and monitor its customers' data at cloud scale, what do the unit economics actually look like — and is this much capital a sign of momentum, or of burn?

2026 rounds
3F · G · G-ext
Raised in 2026
~$1.2BJan + Jun + Sep
Latest valuation
$12Bflat vs. June
Headcount
~1,50018 countries
The raise cadence, laid out

Three rounds in nine months is unusual even by late-stage standards. What stands out is not that Cyera is raising — great companies raise into strength — but the frequency and the flat mark on the most recent one.

Jan 2026 — Series F~$300M @ ~$9B
Jun 2026 — Series G~$540M @ ~$12B
Sep 2026 — Series G extension~$400M @ ~$12B (flat)
Total raised, lifetime$2B+
Round sizes and valuations per Cyera announcements and contemporaneous reporting; figures are approximate and rounded. A flat headline valuation on an extension can reflect deal structure (extensions often price at the prior round) rather than a down-round, and we don't read it as a down-round. We read the cumulative capital intake as the signal worth examining.
Why this specific business is expensive to run

Here is the part the funding headlines skip. Cyera's core value proposition — a "data security platform" that discovers, classifies and continuously monitors sensitive data across a customer's clouds, SaaS and on-prem — is, architecturally, one of the more compute- and storage-intensive things you can sell in security. To do it well you have to:

• Scan at volume, continuously. Classifying petabytes of customer data, and re-scanning as it changes, is sustained compute and egress — not a one-time index. Every large customer is an ongoing cloud bill, not just a license.

• Run AI/ML classification. The "AI-powered" classification that differentiates modern DSPM is inference at scale, which is GPU/accelerator cost that rises with usage, not with headcount.

• Store and process metadata. The data map itself — lineage, sensitivity, access — is a large, hot dataset that has to be kept current per customer.

• Integrate broadly. Coverage across every cloud, database and SaaS is a permanent engineering tax that grows with the surface area, not the revenue.

The honest framing

None of this means Cyera is unhealthy — we have no visibility into its actual gross margins, and we're not asserting they're bad. We're saying the shape of the business points to structurally higher cost-of-goods than a pure control-plane vendor (an SSO or an MFA company processes tokens, not petabytes). When a company with that cost shape raises $1.2B in nine months, "high COGS, heavy data-processing spend, or elevated burn" is the most parsimonious explanation for the appetite — and it's the thing a buyer's procurement team should probe.

The acquisition engine adds to the appetite

Cyera has made roughly six acquisitions, including Oasis Security for about $1B. M&A at that clip is itself a use of cash — and integrating six teams, six codebases and six roadmaps is an operating cost that shows up as burn long before it shows up as synergy. A company buying growth and building coverage simultaneously will consume capital fast even if the underlying SaaS margins are fine. That's not a criticism; it's arithmetic. But it means the raise cadence can be explained without any ARR problem at all — which is exactly why the operational-efficiency question, not the growth question, is the right one to ask.

What a buyer should actually do with this

Cyera is a strong product in a real category; nothing here says don't buy it. It says buy it with your eyes open on two fronts. First, price durability. A company raising this often is either scaling into enormous demand or funding a cost structure that hasn't yet turned the corner — and you can't tell which from the outside, so negotiate as if either is true: multi-year price protection, defined overage terms, and clarity on what happens to your rate card if the funding environment tightens. Second, interrogate the cost model in your own deployment. Because the platform's cost scales with your data volume and scan frequency, ask exactly how your bill behaves as your estate grows, and get it in writing. The same economics that make this an expensive business to run are the economics that can make it an expensive product to operate.

SOURCING & CARE: Funding rounds, valuations, headcount, country count and acquisition activity per Cyera's own announcements and contemporaneous reporting as of Sep 2026; figures are approximate. The COGS / data-processing / burn discussion is explicitly an inference from the architectural shape of a data-security platform, not a reported financial metric. We have no access to Cyera's gross margins, burn rate or internal financials, we assert none, and nothing here alleges the company is in financial difficulty — Cyera by all public indications is growing fast and well-capitalized. This section argues that the cost structure of the category makes operational efficiency the right question, and that a large, frequent capital raise is consistent with (not proof of) heavier spend. Cyera was not contacted and did not review this analysis.
04

The Argument

everyone's governing the robots; almost no one has finished governing the humans

First principles
Human identity governance is the foundation NHI and agent governance are built on — not the legacy problem they replace

The entire market has rotated toward non-human and agent identity in the space of a year. It's the right frontier. But there's a quiet error in how it's being sold: as if human identity governance were a solved, boring, legacy problem you can skip past on the way to the exciting agentic stuff. It isn't. It's the substrate. And the incidents prove it — Hugging Face being the cleanest example.

The over-rotation, and why it's a mistake

Count the launches in this issue alone: Okta for AI Agents, agents as first-class identities, shadow-agent discovery, kill switches. Every vendor has an NHI story and an agent story. Almost none of them are leading with the unglamorous question of whether their customers' human identity programs — joiner-mover-leaver, least privilege, access certification, privileged access, offboarding — actually work. The implicit pitch is that agent governance is a new, separable layer. It is not separable. Every meaningful control you want to apply to an agent or an NHI is a control you first have to be able to apply to a person:

• Ownership. An NHI or agent is only governable if a human owns it and that ownership is maintained through the human's own lifecycle. Orphaned service accounts are just NHIs whose human owner left and whose access review never caught it.

• Least privilege. You cannot scope an agent's entitlements correctly if you never mastered scoping a person's. The same entitlement model, the same role design, the same review cadence carry over — or fail to.

• Lifecycle. Agents and tokens need creation, rotation, and revocation on a schedule. That is joiner-mover-leaver applied to a non-human — the exact muscle a mature human IGA program already has, and an immature one does not.

• Certification. "Who should have this access, and do they still need it?" is the same question whether the subject is an employee, a contractor, a service account or an agent. If your human access reviews are rubber-stamped, your NHI reviews will be too.

Hugging Face: a "non-human" incident that was a human-governance failure

The Hugging Face token exposures are held up as an NHI/secrets story — leaked API tokens, exposed access to models and organizations. And at the surface layer, yes, the artifact that leaked was a machine credential. But step back one level and the root cause is human identity governance, or the absence of it:

The actual failure chain

Tokens with broad, standing scope were issued and then not governed. There was no strong lifecycle behind them, no owner accountable for each one through their own tenure, no least-privilege discipline constraining what a single leaked token could reach, and no review process that would have caught over-permissioned or stale credentials before an attacker did. Those are not gaps in an "agent governance" product. They are gaps in a foundational identity security program — the human-anchored discipline of ownership, scoping, lifecycle and review that a machine credential is supposed to inherit. The token leaked because the house wasn't in order, not because the industry lacked a shiny NHI dashboard.

Put plainly: Hugging Face was exploited because it did not have a real identity security program in place, and the machine credentials sat on top of that void. A world-class agent-governance tool bolted onto that same void would have leaked the same tokens. You cannot govern the non-human layer to a standard you haven't reached on the human layer, because the non-human layer inherits its controls, its ownership, and its lifecycle from the human one.

What a buyer should actually do with this

Sequence it correctly. Before you fund an NHI-discovery or agent-governance initiative, run an honest audit of the human foundation: Do you have accurate joiner-mover-leaver? Is least privilege real or aspirational? Are access certifications meaningful or rubber-stamped? Is there a named owner for every privileged and service account, maintained as those owners come and go? If the answer to those is shaky, spend there first — not because agents don't matter, but because agent governance built on a broken human foundation is a more expensive way to fail. The vendors selling you the agentic layer would rather you not ask this, which is exactly why you should.

SOURCING & CARE: The Hugging Face token-exposure incidents are matters of public reporting; our description of the failure chain is an analytical characterization of publicly reported facts (over-scoped, poorly-governed access tokens), framed to illustrate the human-governance argument. We are not asserting non-public detail about Hugging Face's internal security program; "no real identity security program" is our editorial read of the public record and the nature of the exposures, and reasonable people could characterize it differently. The broader argument — that NHI and agent governance inherit their controls from human identity governance — is our stated editorial position. Hugging Face was not contacted and did not review this analysis. Nothing here alleges wrongdoing by any individual.
05

Vendor Spotlight

a solid product inside an ownership structure we think is about to change

One Identity
Quest Software / Clearlake Capital · est. ~$250M revenue (self-reported) · ~7,500 customers, ~125M identities · IGA (Identity Manager) + PAM (Safeguard) + AD mgmt (Active Roles) + OneLogin
VERDICT: CAPABLE PORTFOLIO, UNSETTLED OWNERSHIP — PRICE THE CHANGE-OF-CONTROL RISK IN
Product / Capability
7.0/10
Implementation Ease
5.5/10
Vendor Stability
4.5/10
Roadmap Confidence
5.0/10

The ownership story is the story

The report Sep 2026
Bloomberg: Clearlake exploring a One Identity + RSA SecurID combination, with a stake sale to another PE firm

Per Bloomberg reporting, Clearlake Capital is weighing options for the identity assets it controls, including merging One Identity with RSA's SecurID business into a new company and selling a stake to another private-equity firm. Nothing is confirmed and no transaction has been announced. But the direction of travel is exactly what the ownership history would predict.

Read: when a PE owner is reported to be exploring a merge-and-sell-a-stake structure, the base case for the asset is no longer "steady independent operation." It's a transaction. For a customer, that means the roadmap, support model and pricing you're evaluating today may sit under different owners within a year.
The history 2016 →
2021
Three owners in a decade: Dell → Francisco Partners → Clearlake

One Identity was carved out of Dell Software and sold (with Quest) to Francisco Partners and Elliott Management in 2016, then sold again to Clearlake Capital in 2021 as part of the ~$5.4B Quest Software deal. In May 2025, Clearlake put a reported ~$350M into a debt refinancing for Quest, and a new CEO, Praerit Garg, took over the same year. That is a lot of financial engineering and leadership change for one asset in a short window.

Read: serial PE ownership isn't inherently bad — but it establishes a pattern. Assets that have been flipped twice tend to be flipped again; the financial owner's job is to exit, and a debt refinancing plus a new CEO is often the grooming that precedes a sale, not a settling-in.
The portfolio current
The product set is genuinely broad — which is exactly what makes a carve-up easy

One Identity spans four fairly distinct products: Identity Manager (enterprise IGA, deep and complex), Safeguard (PAM), Active Roles (AD/Entra management), and OneLogin (access management/SSO, acquired 2021). Each has its own buyer, its own competitors, and its own natural acquirer. That breadth is a selling point operationally — and a liability structurally, because a portfolio of separable assets is the easiest kind to break apart and sell in pieces.

Read: the same modularity that lets you buy just Safeguard or just OneLogin is the modularity that lets an owner sell Safeguard to one buyer and OneLogin to another. If you depend on the integration across these products, that's the thing most at risk in a carve-up.
The product, fairly current
To be clear: the technology is solid and the install base is real

Identity Manager is a legitimately capable enterprise IGA with strengths in complex, on-prem-heavy and hybrid environments where the newer cloud-native tools are thinner. Safeguard is a credible PAM. The company reports ~7,500 customers and ~125M identities under management. This is not a distressed product; it's a solid, somewhat-legacy portfolio with a loyal base — which is precisely the kind of asset PE likes to buy, optimize, and sell.

Read: don't let the ownership skepticism read as a product knock. If Identity Manager fits your hybrid estate, it may genuinely be the right tool. The caution is about the wrapper around the tool, not the tool.
SOURCING: The Clearlake / One Identity + RSA SecurID exploration is per Bloomberg reporting; no transaction has been announced and the reported plans may not proceed. Ownership history (Dell Software carve-out; Francisco Partners/Elliott 2016; Clearlake 2021 as part of the ~$5.4B Quest acquisition; ~$350M 2025 debt refinancing; Praerit Garg as CEO) per public reporting and company statements. Revenue (~$250M) is self-reported/estimated and not independently audited here; customer (~7,500) and identity (~125M) counts are company-reported. Product descriptions per One Identity's own materials. One Identity was not contacted and did not review this assessment.

The Signal Read

The product is a solid B; the ownership is the variable that should move your decision. One Identity sells a broad, capable identity portfolio — deep IGA in Identity Manager, credible PAM in Safeguard, useful AD tooling in Active Roles, and access management in OneLogin. In a hybrid or on-prem-heavy enterprise, that breadth is real value that the cloud-native challengers can't always match. The scores reflect that: good product, moderate implementation burden (Identity Manager is powerful and not simple), and a loyal base.

What drags the composite is stability and roadmap confidence, and that's deliberate. An asset on its third PE owner, freshly refinanced, with a new CEO and now a reported merge-and-sell exploration, is an asset in motion. The financial owner's mandate is to exit. Everything about the current setup — the debt refi, the leadership change, the separable portfolio, the reported RSA combination — reads like preparation for a transaction, not a decade of patient independent product investment. For a buyer, that's not a reason to walk away; it's a reason to price the risk in.

Prediction — clearly labelled

Our call: within roughly the next 12–24 months, One Identity gets flipped to another PE firm, merged (most plausibly with RSA's SecurID into a new identity entity, per the Bloomberg reporting), or carved up and sold in pieces. We think a flip-or-merge is more likely than a carve-up in the near term — the RSA combination is the specific structure reported, and combining two mature identity bases to sell a stake is a cleaner PE play than piecemeal disposal. But the portfolio's modularity keeps the carve-up path live: Safeguard, OneLogin, Active Roles and Identity Manager each have distinct natural buyers.

This is a prediction, not reporting. We have no non-public information and no knowledge of any actual process beyond what Bloomberg has reported. It is our stated opinion based on the ownership history, the base rates for serial-PE-owned software assets, the recent refinancing and CEO change, and the reported RSA exploration. It may not happen, or may happen differently. For a buyer the practical takeaway is the same regardless: negotiate change-of-control protections now.

Buy the story if…
  • You run a hybrid or on-prem-heavy estate where Identity Manager's depth genuinely beats the cloud-native IGAs
  • You want IGA, PAM and AD management from one vendor and value that consolidation operationally
  • You can lock multi-year pricing and support terms that survive a change of control
  • You're replacing something worse and need a capable, proven platform now, not a bet on a startup
Do your homework on…
  • Get explicit change-of-control language: what happens to your rate card, support SLAs and roadmap commitments if the asset is sold or merged
  • If you depend on cross-product integration (e.g. Identity Manager + Safeguard + OneLogin together), understand that a carve-up puts exactly that at risk
  • Pin down the OneLogin roadmap specifically — access management is the piece most exposed in any reshuffle toward an IGA/PAM-centric combination
  • Budget the implementation honestly — Identity Manager is powerful and correspondingly heavy to deploy and operate
  • Ask, directly, how continued R&D investment is being funded through a refinancing and a possible transaction
06

The Stack

a category, tool, or idea worth knowing this fortnight

Buying discipline

Grade alliances on delivery, never on the announcement

When a vendor cites membership in a security "alliance" or "blueprint" as evidence of integration, treat it as marketing until proven otherwise. Ask the only question that matters: is there a jointly-supported, jointly-accountable integration with a name, a SKU and a single support path? If yes, reward it. If it's an API integration that already existed plus a logo lockup, it earns nothing on your scorecard. Keep the press release and check it against reality in twelve months.

Diligence technique

For any heavily-funded vendor, model your bill against their cost curve

The Cyera analysis generalizes. When a platform's cost-to-serve scales with your usage — data volume scanned, events processed, inference run — a vendor's fundraising tells you the category is capital-hungry, and your contract needs to account for it. Ask exactly how your bill behaves as your estate grows, get overage terms in writing, and secure multi-year price protection. Capital intake upstream tends to become pricing pressure downstream.

Sequencing rule

Fix the human foundation before you fund the agent layer

Before approving an NHI-discovery or agent-governance project, audit the human basics that the non-human layer inherits: joiner-mover-leaver accuracy, real least privilege, meaningful access certification, and a named owner for every privileged and service account. If those are shaky, spend there first. Agent governance built on a broken human foundation — the Hugging Face pattern — is just a more expensive way to leak the same credentials.

07

Boardroom

one line to sound three moves ahead in your next exec meeting

Say this

We govern agents by first governing ourselves

The board will hear "AI agents" and "non-human identity" from every vendor this year. The mature framing — the one that separates you from the room chasing the shiny layer — is that agent security is downstream of identity fundamentals, not a replacement for them. Every control we want over an agent is a control we first have to run reliably over a person. So our investment sequence is foundation first, frontier second: get human identity governance genuinely operating, and the agent layer inherits controls that actually work. Skip that, and we're buying a lock for the window while the front door stands open.

"Before we fund anything 'agentic,' I want proof our human identity basics — least privilege, access reviews, joiner-mover-leaver — actually work. Agents inherit those controls. If the foundation is broken, the agent governance inherits the break."
08

Overheard

a spicy anonymized take from the community this fortnight

"Watched a vendor spend forty minutes on their 'agent kill switch' and then couldn't tell me who owns the service account that's had domain admin since 2019. We're building autopilot for a plane with no landing gear."
— identity architect, Fortune 100 · overheard in a peer Slack, lightly paraphrased