Cyera Acquires Oasis to Build an Agentic Security Platform

The News

Cyera has signed a letter of intent to acquire Oasis Security, an access management platform focused on non-human identity in agentic environments. The combination is intended to close the gap between data intelligence (Cyera’s existing strength in DSPM and DLP) and machine identity governance (Oasis’s specialty in tracking what AI agents can access and who owns those identities). Alongside the acquisition announcement, Cyera previewed Agent Guardian, a four-phase agent security framework heading toward public preview, and teased a third major announcement at Black Hat 2026: Endpoint Security, which extends the platform from browser-based AI controls to the device layer itself.

Analyst Take

The identity-data gap is the defining security problem of the agentic era

For years, identity security and data security have been sold as adjacent disciplines that occasionally overlap. The Cyera-Oasis combination is a direct bet that adjacency is no longer sufficient. When an AI agent makes an API call, two questions have to be answered simultaneously: is this identity authorized to act, and is the data it’s touching appropriately classified and protected? Answering only one of those questions leaves a gap that attackers, and increasingly misbehaving agents, will find. Cyera’s acquisition logic is sound precisely because neither half of this equation is optional.

The scale of the challenge is growing faster than most security programs anticipated. ECI Research’s 2026 Application Development survey found that 52.6% of respondents have AI-assisted coding tools standardized across teams, meaning agent-like behavior is already embedded in the development workflow at a majority of organizations. These aren’t experimental pilots. They’re production-grade tools generating code, reading repositories, and accessing internal systems at machine speed. The security stack that was designed for human users authenticated once per session is structurally mismatched to this reality.

Why Agent Guardian’s shared policy engine is the technically significant detail

Most of the commentary around Cyera’s Agent Guardian will focus on the four-phase framework: discover, govern, protect, validate. That structure is coherent and maps well to how mature security teams think about control surfaces. But the more consequential detail is that Agent Guardian runs on the same policy engine as Cyera’s existing DSPM and DLP capabilities. That matters for developers and security engineers alike. A policy written once to govern a human analyst’s access to a sensitive S3 bucket automatically extends to an agent’s API call against the same resource. There’s no second policy language to learn, no shadow rule set to maintain.

This architectural choice also targets a practical problem: security teams are already stretched thin. ECI Research’s 2026 DevSecOps and AppSec survey found that 45.3% of respondents say AI-assisted development has increased security risk moderately, with another 17.2% saying it has increased risk significantly. That’s nearly two-thirds of organizations reporting elevated risk from the very tools their developers are standardizing on. Layering a separate agent-specific security framework on top of an already strained security organization would be operationally untenable for most enterprises. A shared policy engine is the right architectural answer to that constraint.

Endpoint Security completes the surface coverage story

Browser Shield, launched at RSAC earlier this year, addressed AI use inside the browser. The forthcoming Endpoint Security capability addresses the device itself, where local coding agents and assistants operate entirely outside network visibility. This is a coverage gap that most DSPM and DLP vendors have not yet addressed, and Cyera is moving to close it before competitors have fully mapped the terrain. The sequencing (cloud data, then browser, then endpoint) mirrors the progression of where AI-driven data exposure is actually occurring in enterprise environments, which suggests deliberate product strategy rather than reactive feature addition.

For ITDMs evaluating their data security posture, the practical question is whether a single platform can eventually replace the collection of siloed tools that currently covers these surfaces separately. Cyera is clearly positioning for that consolidation. The Oasis acquisition accelerates the identity side of that story; Endpoint Security extends the device side. The platform thesis is coherent. Execution across three major announcements in a single month is ambitious, and the integration work required to deliver on the Oasis combination will be substantial.

Looking Ahead

The Cyera-Oasis deal, if it closes as intended, will create one of the more complete data-plus-identity security platforms in the market. Expect the combined entity to compete directly with the identity governance capabilities of established players like SailPoint and Saviynt, while simultaneously pressing into territory that traditional DLP vendors have not covered: agent-level access controls tied to real-time data classification. The competitive pressure this creates on point-solution vendors in both the DSPM and non-human identity categories is real. Organizations that have been buying these capabilities separately should treat this as a signal to re-evaluate their vendor roadmaps.

Over the next 12 to 18 months, the measure of whether this platform strategy is succeeding will come down to policy consolidation: can enterprises actually retire redundant tooling, or does Cyera’s platform become one more layer in an already complex stack? The Black Hat announcements, and particularly whatever Cyera reveals in the embargoed webinar content, will be an early indicator of how far along the integration work actually is. Watch the Agent Guardian public preview timeline closely. If it ships with the shared policy engine delivering on its promise across both human and non-human identities, Cyera will have a durable architectural advantage that is difficult to replicate quickly.

Authors

  • Paul Nashawaty

    Paul Nashawaty, Practice Leader and Lead Principal Analyst, specializes in application modernization across build, release and operations. With a wealth of expertise in digital transformation initiatives spanning front-end and back-end systems, he also possesses comprehensive knowledge of the underlying infrastructure ecosystem crucial for supporting modernization endeavors. With over 25 years of experience, Paul has a proven track record in implementing effective go-to-market strategies, including the identification of new market channels, the growth and cultivation of partner ecosystems, and the successful execution of strategic plans resulting in positive business outcomes for his clients.

    View all posts
  • With over 15 years of hands-on experience in operations roles across legal, financial, and technology sectors, Sam Weston brings deep expertise in the systems that power modern enterprises such as ERP, CRM, HCM, CX, and beyond. Her career has spanned the full spectrum of enterprise applications, from optimizing business processes and managing platforms to leading digital transformation initiatives.

    Sam has transitioned her expertise into the analyst arena, focusing on enterprise applications and the evolving role they play in business productivity and transformation. She provides independent insights that bridge technology capabilities with business outcomes, helping organizations and vendors alike navigate a changing enterprise software landscape.

    View all posts