Cyera’s Proposed Oasis Security Acquisition Puts Non-Human Identity at the Centre

Cyera’s reported plan to acquire Oasis Security for $1 billion signals how quickly non-human identity has moved from a specialist concern to a strategic security category. The transaction would bring data-security visibility and machine-identity controls closer together at a time when enterprises are deploying AI agents that can act across cloud services, applications and sensitive data stores.

For security leaders, the important story is not simply the valuation. It is the recognition that AI agents need durable identities, constrained privileges and evidence of what they did. Without those controls, an agent is effectively a fast-moving account with unclear ownership, excessive access and no reliable route for investigation.

The problem with AI-agent expansion

Traditional identity programmes were designed around employees, contractors and familiar service accounts. Agentic workloads do not fit neatly into those categories. They can be created dynamically, invoke tools on behalf of people, call other agents and continue operating beyond the original user session. That creates an identity graph in which ownership, authority and purpose can change rapidly.

An acquisition combining complementary capabilities could address several practical gaps. First, discovery must extend beyond directories. Teams need to find tokens, workloads, service principals and autonomous processes, then connect each one to an accountable owner and business purpose.

Second, access decisions need context. An agent accessing a production database at 3 a.m. may be legitimate, but only if its task, approval chain, environment and requested data all align. NHI security therefore requires policy to follow the workload, not merely the static account.

Third, controls must operate at runtime. Short-lived credentials, narrow permissions, transaction-level authorisation and continuous verification are more appropriate than permanent secrets. When an agent changes behaviour, reaches an unusual system or exceeds its task boundary, security teams need the ability to pause or revoke it immediately.

What buyers should evaluate

The market signal should prompt CISOs to test whether their current IAM and security tooling can inventory non-human identities across multi-cloud environments. They should also ask whether ownership is captured as data, whether machine identities are reviewed like human entitlements, and whether activity can be reconstructed after an incident.

The proposed deal also highlights the value of convergence. AI-agent security cannot be separated cleanly into identity, data and application silos. A useful control plane should show which agent accessed which data, through which credential, under whose authority and for what declared purpose. That level of context is becoming the baseline for safe Agentic Identity adoption.