The Olam
AI

Identity for AI Agents: Oasis Security and the Next Identity Cycle

By The Olam Editorial Team · May 26, 2026

Identity for AI Agents: Oasis Security and the Next Identity Cycle

Non-human identities outnumber human identities by 80 to one. AI agents add a new identity class that existing identity systems were not built for. Oasis Security is the Israeli cohort leader in the non-human identity category.

Non-human identities outnumber human identities by 80 to one inside large enterprises. AI agents add a new identity class that did not exist in the framework most enterprises built their identity systems around. Israeli cybersecurity is at the center of the build-out. Oasis Security is the category leader by venture funding and brand recognition in 2026, building the identity governance platform that maps, secures, and ultimately governs the non-human and agent identity layer.

The structural shift

Identity, in the legacy enterprise framework, was a human problem. Active Directory, Okta, Ping Identity, CyberArk's privileged access — these systems were built to govern users with corporate email addresses, login credentials, and roles. The non-human identity layer — service accounts, API keys, OAuth tokens, secrets, certificates, machine credentials — grew underneath the human identity layer without consistent governance. Cloud adoption accelerated the gap. By 2024, Gartner estimated machine-to-human identity ratios had reached 45-to-1 in cloud-native enterprises. By 2026, the ratio crossed 80-to-1, driven by AI agent proliferation.

The AI agent identity problem is structurally different. An AI agent — a Microsoft Copilot Studio agent, an Anthropic-powered customer service agent, a Salesforce Einstein Copilot, an internally developed LangChain pipeline — needs to authenticate, hold permissions, take actions, and be governed. The identity system underneath was not designed for agents. It was designed for service accounts and API keys held by humans. AI agents act autonomously, take actions across systems, hold context, and execute multi-step workflows. They need a different governance layer.

Oasis Security: the company

Founded in 2022 by Danny Brickman (CEO) and Amit Zimerman (CTO) — both former Unit 8200 — Oasis Security is headquartered in New York with R&D in Tel Aviv. The company raised a $35 million Series B in May 2024 led by Sequoia Capital with participation from Accel and Cyberstarts. Total funding to date is approximately $75 million. The platform inventories, monitors, and governs non-human identities across cloud, SaaS, and on-premise environments — providing visibility into ownership, permissions, usage patterns, and risk for service accounts, OAuth tokens, secrets, and (as of 2025) AI agents.

The company's positioning in the NHI category is platform-comprehensive. Competitors approach the problem from narrower angles: Astrix Security focuses on SaaS-to-SaaS non-human connections. Aembit focuses on workload identity. Apono focuses on just-in-time access provisioning. P0 Security focuses on access analytics. Andromeda Security focuses on detection. Oasis's approach is governance-first — building the system of record for non-human identity, then layering risk and governance on top.

The AI agent identity extension

In 2025, Oasis Security extended the platform to cover AI agent identities — a category that did not have a defined name or boundary in the previous identity framework. The product addition responds to the operational reality that enterprises deploying AI agents in production cannot govern them through traditional IAM. AI agents need: discoverable identity (so security teams can see them), permissioning (so they can only access what they need), action governance (so they don't take destructive actions), and audit (so their actions are reconstructable).

The competitive question is platform versus specialist. CyberArk — now part of Palo Alto Networks — claims the privileged identity layer extends naturally to AI agents. Microsoft Entra Permissions Management positions the same thesis from the cloud entitlements direction. Okta has signaled interest in extending workforce identity to non-human and AI agents. Oasis's positioning is that the AI agent identity problem is structurally distinct from privileged human identity and from workforce identity — and that the company purpose-built for the NHI category will own the AI agent extension.

The Israeli cybersecurity bench

The Oasis Security thesis is part of a broader Israeli identity-security cohort that has emerged post-CyberArk's institutional success. Astrix Security (Tel Aviv, founded by Alon Jackson and Idan Gour, both former 8200) raised a $45 million Series B from Bessemer in 2024. Silverfort (Tel Aviv, founded by Hed Kovetz, Yaron Kassner, and Matan Fattal) is the broader identity-security platform, valued above $1 billion. Apono (Tel Aviv, founded by Rom Carmel and Ofir Stein) focuses on just-in-time access. Aim Security (Tel Aviv) focuses on AI security including agent governance. The cluster represents the most concentrated Israeli cybersecurity sub-category in the 2024–2026 cycle.

The platform consolidation question

PANW's $25 billion acquisition of CyberArk in February 2026 has accelerated the consolidation timeline for identity security. Microsoft has signaled interest in NHI through Entra. Google, post-Wiz, has positioned for the cloud-identity layer. CrowdStrike is positioned to extend identity coverage. The buyers for the next-tier NHI platforms — Oasis, Astrix, Silverfort, Apono — are visible.

For Oasis specifically, the structural question is whether the AI agent identity category becomes the company's defining product surface or a feature inside someone else's platform. The 2026 product cycle suggests the former: AI agent identity is sufficiently distinct, the governance requirements are sufficiently different, and the enterprise buying behavior is concentrated enough at the security team rather than the IAM team to support a category-defining standalone.

The cycle read

Every identity cycle has produced a category-defining Israeli company. The 1990s/2000s cycle: CyberArk (privileged access). The 2010s cycle: Silverfort (modern multi-factor and unified identity protection). The 2020s cycle, plausibly: Oasis (non-human and AI agent identity). The framing in Israeli cyber is that identity is the most defensible single category in cybersecurity — and the operators who own it carry exit comparables that price the category against the platform vendors. The CyberArk-PANW outcome anchors that read.

Crypto & Digital Assets

View all →