Identity Meets Data: Defining the AI Trust Layer for the Agentic Enterprise

The combination of data security and non-human identity security creates a new foundation for securing AI agents at enterprise scale.

Cyera has officially completed the acquisition of Oasis Security. This is one of the most consequential moves in cybersecurity history. It brings together two security disciplines, data security and identity security, that have spent decades evolving separately but are now critical to unify.

This is more than an expansion of the Cyera platform. It reflects a fundamental change in how enterprises need to think about security in the age of AI.

For most of the history of cybersecurity, the primary actor was a person. Identity systems were built to manage employees, their roles, their permissions, and their lifecycle, while data security focused on discovering sensitive information and reducing its exposure. The model worked because a human sat between identity and data. People introduced judgment, friction, and accountability into every interaction with enterprise information. That assumption is disappearing.

Enterprises are rapidly automating work through agentic software, creating an enormous and growing population of non-human identities: service accounts, workloads, API keys, tokens, credentials, and now AI agents. Humans naturally place limits on the risk created by over-permissioned access. Cyera and Oso research analyzing 2.4 million workers and 3.6 billion permissions found that workers use just 4% of the permissions available to them, leaving 96% unused. The research also found that workers interact with only 9% of the sensitive data they can access, highlighting just how much access exists beyond what employees actually need to do their jobs. AI agents remove that natural constraint. If an agent can access data, it can potentially use that entire access immediately and at machine speed, reasoning over information, moving between applications, invoking tools, and taking actions autonomously. What was once largely dormant exposure can become active data risk in an instant.

This is where the combination of Cyera and Oasis becomes so important.

AI Makes the Standing Security Trust Model Unsustainable

For decades, security could rely on a fundamental assumption: the actor behind an identity was a human capable of exercising judgment about how and when to use the access they had been given. That assumption no longer holds when the actor is an autonomous system inheriting a human identity and privileges.

A permission granted months ago can no longer be treated as reliable simply because it was appropriate when it was granted. An AI agent can use that permission dynamically, based on the task it has been given and the information it encounters along the way. Trust therefore has to become a decision made at the moment of action.

That decision requires context. Security needs to understand the identity requiring access, the data it is trying to reach, the sensitivity of that data, and what the agent is attempting to do. Only then can access be appropriately scoped to the task rather than inherited from a standing grant.

Cyera and Oasis bring these two sides together. Bringing data and identity together establishes the foundation for dynamic trust: a unified understanding of the relationship between every non-human identity and the data it can reach. Cyera brings deep intelligence into enterprise data—understanding where it resides, what it contains, how sensitive it is, how it is exposed, and the business context that makes it consequential. Oasis brings the intelligence to understand the identities, credentials, workloads, and agents accessing it. Together, that context can inform the access decision itself—whether this identity should access this data, for this action, at this moment.

From Visibility to Action

The value of this new context is not simply better visibility. It changes what security teams can do about risk.

Today, organizations often discover excessive permissions by looking at identity posture or data exposure independently. That can produce thousands of findings without a clear understanding of which ones matter most. Connecting identity to data changes the equation. An overprivileged credential that can reach an empty development environment is fundamentally different from one that can reach millions of sensitive records. The sensitivity and business importance of the data provide the context needed to prioritize the risk and determine the right response.

That response can also become more precise. Instead of treating access as a binary decision (granted or revoked) security teams can right-size permissions, rotate or revoke credentials, and increasingly enforce access according to the data involved and the task being performed. The goal is not to eliminate access. It is to ensure that every non-human identity has only the access it needs, when it needs it, and no more.

This creates a continuous path from discovery to action: understand the identities operating in the environment, understand the data they can reach, identify where exposure matters, and take action to reduce it.

Securing the Agentic Enterprise at Scale

The significance of this architecture extends beyond today's AI agents. Enterprises are becoming increasingly dependent on software that acts on their users’ behalf, from cloud workloads and service accounts to automated workflows, application integrations, and autonomous agents.

These actors will continue to multiply, change ownership, acquire new capabilities and additional privileges, and interact with new sources of data. Security cannot depend on manually reviewing each identity or anticipating every way an agent might operate. It needs to scale with the environment and continuously adapt as identities, data, and activity change.

That is the opportunity created by bringing Cyera and Oasis together: to make the integration between identity and data a first-class security control, rather than leaving organizations to piece that context together across separate systems.

The result is a security model built for an enterprise where software is no longer simply executing predefined instructions. It is increasingly making autonomous decisions, accessing information, and taking action on behalf of the business.

Defining the AI Trust Layer

The next generation of enterprise security will not be defined by another isolated control. It will be defined by the ability to establish trust around autonomous action.

That requires knowing what is being accessed, who or what is accessing it, why access is occurring, and whether that access is appropriate at that moment. As AI becomes more capable and more deeply embedded in business processes, those decisions will become fundamental to how organizations govern technology.

Cyera and Oasis are coming together to build that foundation. By unifying data intelligence with non-human identity intelligence, Cyera can help organizations move from simply knowing what their AI systems can access to continuously controlling what they are allowed to access and do.

This is the beginning of a new security architecture for the agentic enterprise—one designed around the reality that identity and data are no longer separate parts of the security decision.

One platform to secure the agentic enterprise.

Share