New From Cyera: AI Security for Every Agent, Assistant, and Data Store

Aug 18, 2026
Teilen

Every business already has agents running somewhere, sanctioned or not. The moment they go live, they inherit the access of the person who launched them, creating a workforce that never sleeps, rarely asks twice, and multiplies faster than security teams can review or contain.

That is what makes agentic AI security a data security challenge first. The risk is not just that an agent exists; it is what that agent can reach, what it can do with the data it finds, and whether anyone can prove what happened after it acts. To secure this new workforce, teams need to discover where agents are running, understand what each one can access, govern how they are allowed to act, protect sensitive data at runtime, and validate the impact after the fact.

That is the foundation behind this release: Cyera Agent Guardian anchors the move from agent visibility to agent control, while the rest of the platform extends the same data context into incident response, Cy-powered investigations, DLP workflows, AI activity trails, and the systems where agents already operate.

Below, we'll walk through five release highlights:

  • Agent Guardian: Discover, govern, protect, and validate every AI agent, wherever it runs.
  • Incident Materiality Assessment: Know exactly every record that was exposed when an incident happens, including the AI tools and agents involved.
  • New in Cy: Investigate data risk, surface deeper insights, and reuse proven workflows with an AI assistant that understands your data.
  • Projects: Delegate data governance to specific teams with logically segmented views of data, alerts, and identities in a single tenant.
  • Access Trail for Microsoft Exchange Online and NetApp: Audit visibility extends to Outlook and NetApp on-prem file shares, right where AI assistants are already active.
  • Extending the Ecosystem: Data security support for on-prem databases and our integration ecosystem expand to reach the same places your AI tools do.

Introducing Agent Guardian: protect AI agents at the endpoint and beyond

Most agent security solutions monitor prompts, outputs, or individual tool calls. They can see isolated actions, but they often miss the deeper context: what data an agent can access, whose permissions it inherits, and how that access could be used.

That gap matters because access is usually invisible until it becomes a problem. A new hire typically grows into permissions over time and may never touch most of what they’re technically allowed to see. An agent is different. On day one, it can inherit broad entitlements and use them immediately whenever a task requires it.

Cyera Agent Guardian makes every agent as visible and accountable as a human employee, with decisions grounded in data sensitivity and identity context. It combines automated data classification, identity access rights, behavioral baselines, and runtime analysis to evaluate both how agents are designed and what they attempt to do.

It secures the agent lifecycle in four phases:

  • Discover: Builds a live inventory of every agent across cloud platforms, SaaS tools, endpoints, and even Shadow AI (tools you didn’t know are used in your environment), mapping the models, tool access, and data connections behind each one.
  • Govern: Watches for posture issues and intent drifts as they form, including the combinations of broad access, high autonomy, and privileged identity that turn an ordinary agent into a risky one.
  • Protect: Steps in during execution, blocking a risky tool call or stripping sensitive fields out of a response before it reaches somewhere it shouldn't.
  • Validate: Runs continuous adversarial red teaming against prompt injection and jailbreak attempts, generating audit-ready evidence for regulatory frameworks.

That accountability also has to reach agents wherever they run, including on employee laptops. Cyera Endpoint extends Agent Guardian to the device, giving security teams real-time visibility and control over both sanctioned and unsanctioned agents. It shows which agents are running, what data they can reach, and how they’re using local tools like bash, run-code, and MCP calls. By applying the same data protection controls wherever agents run, security teams can enforce policies consistently across corporate tools, personal accounts, and desktop apps like Claude Code, Cowork, ChatGPT Desktop, and others.

Incident Materiality Assessment: determine the true impact of a security incident with advanced data scanning and expert-led analysis  

Non-human identities add new uncertainty when incidents happen. If an agent, copilot, or AI workflow is involved, teams need more than an estimated blast radius. They need to know exactly what records were potentially compromised. Traditional incident response explains how an attacker got in and how far they went, but not always which data classes, records, and individuals were affected, or whether the exposure triggers disclosure obligations. 

Cyera Incident Materiality Assessment, now Generally Available, pairs fast, targeted data scanning and enriched classification with expert-led analysis to deliver: 

  • A defensible inventory of sensitive data touched by data class
  • Severity and materiality context for disclosure decisions
  • A timeline of who accessed what, and when
  • A report built for legal, the board, and regulators

It augments incident response efforts with the data-specific impact analysis needed to move from a generic “a breach occurred” to a defensible account of impact, in days instead of weeks. 

Learn more about Cyera Incident Materiality Assessment or request a demo today to find out how we enable teams to quantify the impact of an exposure.

New in Cy: one AI assistant across the Cyera Platform

As AI, DLP, DSPM, endpoint, identity, and activity signals converge, investigations are getting more complex. Teams need one path from question to insight to action.

Cy, Cyera’s Data and AI security assistant, helps security, compliance, and governance teams investigate faster, prioritize risk, and complete manual work more efficiently. Cy now expands across more of the Cyera platform, including support for DLP questions, bringing alert, exposure, and sensitive data context into a single natural-language investigation experience. Cy also now supports project-scoped responses, so users can ask questions within the right business, team, or operational context. 

Teams can ask Cy questions like:

  • Which incidents or alerts need attention first?
  • What sensitive data was involved?
  • Where did the data move, and who accessed it?
  • Are there risk patterns that require follow-up?
  • Where should I focus next?

Cy also makes investigations repeatable. With Saved Prompts, teams can turn useful sessions into reusable, parameterized workflows, capturing not only what the user asked, but the logic Cy used to answer. Suggested next steps help users continue the investigation after an answer, with follow-up recommendations such as exporting results, refining scope, or narrowing by owner. 

Unified Projects: the right data scope for every team across the Cyera Platform

As security operations scale, more teams need to participate. But they don’t all need access to the same data, alerts, or identities. Projects gives organizations a unified way to delegate responsibility across teams and business units while maintaining centralized governance in a single Cyera tenant.

Enterprise security teams collaborate across many cross-functional groups, each needing a working view scoped to its own responsibility, without overexposing data, duplicating workflows, or splitting operations across separate tenants. Administrators can define a project and assign users or groups to it. When project users log in, they see only the data and alerts within their project’s scope, while global users retain their organization-wide visibility.

With Projects, customers can:

  • Segment data access: assign project users to designated datastores and alerts, limiting exposure to irrelevant data.
  • Focus triage: ensure project users see only the issues and alerts they’re responsible for, cutting noise and helping large teams respond faster. 
  • Control identity visibility: choose whether project users see all identities across the organization or only those with access to resources in the project's datastore scope.  
  • Scope API access: enable project users to create personal API tokens that inherit their assigned project scope and role permissions.  

Customers can delegate work safely, reduce noise for each team, and keep access aligned with each team’s responsibilities, all while operating from a single environment. 

Access Trail Expanded Coverage: audit visibility that keeps pace with AI

Microsoft Copilot and other AI assistants already reach into Outlook and File Shares to execute tasks. Security teams need an audit trail across those same environments so they can trace sensitive data activity, investigate exposure, validate policy, and prove what happened.

Access Trail now extends to Microsoft Exchange Online mailboxes and NetApp, covering message access, attachment access, send activity, deletions, inbox rules, folder permissions, and delegated access. Teams can investigate faster, support stronger governance, and execute more defensible audits wherever AI tools interact with sensitive data.

Extending the Ecosystem: on-prem databases and new integrations 

As agents begin to query on-prem databases directly, security teams need the same visibility and controls they have in cloud and SaaS environments to secure the data these agentic workflows depend on. Cyera now extends on-prem database coverage across MySQL and MariaDB, clustered Oracle RAC deployments, MSSQL 2025 on Windows or Linux, and Db2 for i on IBM Power Systems, helping teams discover, classify, and govern sensitive data wherever agents and applications reach.

In addition, Cyera’s integration ecosystem continues to grow to carry that same context downstream, into tools built specifically for the AI security moment:

  • Microsoft Agent 365 now brings Cyera Agent Guardian’s data context and risk signals into the Agent Registry, showing each agent’s permissions, tools, and access paths to sensitive data.
  • Akamai enriches Guardicore VM inventory with Cyera's classification so micro-segmentation policies follow data sensitivity.
  • Swimlane turns Cyera findings into playbooks that remediate exposed data, enforce policy, and close the loop with an audit trail.
  • Eve Security uses Cyera's classification labels to enforce real-time guardrails for AI agents, preventing them from reaching sensitive data before it's exposed.
  • Nagomi combines agentic exposure investigations with Cyera's classification to prioritize exposures that pose a risk to sensitive data.
  • Panorays auto-syncs the providers Cyera discovers behind your datastores into third-party risk coverage grounded in a real data footprint.
  • Native Security translates Cyera's data sensitivity findings into automated cloud infrastructure controls across AWS, Azure, Google Cloud, and OCI.

AI security that reaches everywhere your data does

With these recent innovations, security teams can now:

  • Govern every AI agent from discovery through runtime enforcement with Agent Guardian and Cyera Endpoint
  • Know exactly what data was exposed after an incident with the Incident Materiality Assessment
  • Turn complex investigations into deeper, actionable insights with Cy
  • Scope data and alerts by team or business unit as AI adoption grows with Projects
  • Extend audit visibility to Outlook and NetApp on-prem file shares with Access Trail
  • Reach the same places your AI tools do with expanded on-prem database coverage and a wider integration ecosystem

If you want to see how these capabilities work together in your environment, request a demo today.

Teilen