Research Notes

AI Agents Turn SaaS Into A Runtime Security Boundary

Research Finder

Find by Keyword

AI Agents Turn SaaS Into A Runtime Security Boundary

Why identity, permissions, and cross-application behavior must be actively governed before autonomous agents execute commands in the enterprise.

08/06/2026

Key Highlights

  • Obsidian Security’s $85 million Series D validates agent security as an emerging enterprise budget category.
  • Nearly 70% of Obsidian customers reportedly allow AI agents to interact with business data, making agent access a current operational issue, not a future concern.
  • Identity controls can establish whether an agent has access, but access alone does not reveal what the agent can accomplish across connected applications.
  • The real risk is cumulative authority: individually legitimate permissions can combine into a dangerous execution path.
  • Agent inventory is table stakes. Enterprises need correlated visibility across identities, tokens, permissions, application activity, data movement, and downstream actions.
  • Agent security will ultimately converge with identity, SaaS security, AI gateways, and runtime governance. Buyers should be wary of creating another disconnected control plane.

The News

Obsidian Security has raised $85 million in Series D funding at a reported valuation of $1.1 billion. Crescent Cove Advisors led the round, with existing investors Greylock Partners and Menlo Ventures participating.

The company plans to use the capital to expand its platform for monitoring and governing AI agents operating across third-party applications, including Microsoft Copilot Studio, Salesforce Agentforce, and Anthropic’s Claude. Obsidian CEO Hasan Imam said that nearly 70% of the company’s customers already permit agents to interact with business data. Read the announcement.

Analyst Take

Enterprises are giving agents machine-speed access to SaaS applications faster than security teams can establish machine-speed oversight. The problem is no longer simply who can log into an application. It is what an agent can do across several applications once access has been granted.

The market is filling with tools that discover agents, inventory models, or approve AI systems for production. Those capabilities are necessary, but they are not sufficient. An inventory tells an organization that an agent exists. It does not necessarily reveal the complete chain of trust that allows the agent to move information and execute commands across Salesforce, Microsoft 365, ServiceNow, Slack, GitHub, and other connected systems. The real control problem is cumulative authority.

Every individual permission may look legitimate. The Salesforce token is approved. The Slack integration is sanctioned. The GitHub access is appropriate. The ServiceNow workflow is functioning as designed. Yet, when an autonomous agent chains those permissions together, the result may be an execution path that nobody intentionally authorized. Identity is the beginning of agent security, not the end.

Traditional identity controls answer whether an account, user, or service can enter an application. Agent security must answer a harder set of questions:

  • What is the agent doing after access is granted?
  • Which permissions is it combining?
  • How much data is it moving?
  • In what sequence is it acting?
  • Which downstream systems are affected?
  • Can security intervene before a permitted action becomes a damaging pattern?

This distinction matters because agents operate at machine speed. A human with excessive access represents risk. An autonomous system with excessive access can repeatedly exercise that authority across several applications before a human analyst understands what happened.

HyperFRAME Research Lens data shows why the market is struggling with this transition. Although 62% of organizations cite governance and security as a concern and 53% identify security attacks as a critical risk, only 40% have institutionalized a dedicated AI governance committee. Enterprises are scaling AI access faster than they are building the organizational and technical capacity to govern it. That gap creates an opportunity for Obsidian. It also creates a danger for buyers.

Security teams do not need another attractive dashboard generating an additional stream of disconnected alerts. They need evidence that agent-security platforms can correlate identity, permissions, tokens, application behavior, and data movement, and then support safe intervention without breaking legitimate automation. The hard part is not discovering an agent. The hard part is stopping an authorized agent from doing something the enterprise never intended.

What Was Announced

The Series D provides Obsidian with additional capital to expand its AI-agent security platform. The funding announcement itself should not be confused with a completely new product launch; many of the underlying capabilities were introduced previously.

Obsidian launched its SaaS AI Agent Defense offering in September 2025. The company describes a knowledge graph that correlates agent activity, identity privileges, SaaS connections, and workflows. Its announced capabilities include maintaining a live agent inventory, mapping entitlements to actions, producing correlated audit trails, and detecting attempts to misuse access or escalate privileges. Initial integrations included Microsoft Copilot Studio, ChatGPT Enterprise, Salesforce Agentforce, and n8n.

In January 2026, Obsidian expanded its positioning to the broader SaaS supply chain. The company said its platform unifies identity, permissions, OAuth scopes, and activity data to identify risky integrations and understand downstream exposure.

This architecture is directionally aligned with where agent security must go. Agents do not operate in isolation. Their authority is inherited from the accounts, tokens, APIs, integrations, and applications around them. A security platform must therefore understand both what an agent is permitted to do and what it is actually doing across that environment.

Obsidian now needs to demonstrate that its correlated view can consistently produce reliable enforcement in heterogeneous enterprise environments. Mapping every possible execution path across changing permissions and competing SaaS platforms remains a difficult engineering problem. Vendor claims about visibility and prevention should be tested against deployment time, coverage gaps, false positives, response latency, and operational overhead.

Looking Ahead

Agent security is unlikely to remain a clean standalone market. Identity vendors already control authentication and privileged access. SaaS security vendors understand application behavior and integration risk. AI gateways govern model interaction. Data-security platforms track sensitive information. Observability providers capture execution telemetry. Each has a plausible claim on part of the agent-security stack.

The likely outcome is convergence and considerable category conflict. Obsidian’s advantage is that agents increasingly act through SaaS, where the company already has context about applications, permissions, integrations, and behavior. Its challenge is proving that this context translates into better enforcement than enterprises could obtain by extending their existing identity and security platforms.

Buyers should avoid evaluating agent-security products as isolated tools. They should ask where policy authority resides, how telemetry moves between platforms, and which system can actually stop an action. Adding a new agent-security console without resolving those questions may increase visibility while leaving accountability fragmented.

The $85 million round is therefore significant, but not because it shows Obsidian has won the market. It shows that investors believe agent security will command its own budget. The more important question is whether that budget produces a durable security layer or simply another wave of overlapping tools.

The companies that win will not be the ones with the longest agent inventory. They will be the ones that can govern cumulative authority across the enterprise without making an already fragmented security architecture worse.

Author Information

Stephanie Walter | Practice Leader - AI Stack

Stephanie Walter is a results-driven technology executive and analyst in residence with over 20 years leading innovation in Cloud, SaaS, Middleware, Data, and AI. She has guided product life cycles from concept to go-to-market in both senior roles at IBM and fractional executive capacities, blending engineering expertise with business strategy and market insights. From software engineering and architecture to executive product management, Stephanie has driven large-scale transformations, developed technical talent, and solved complex challenges across startup, growth-stage, and enterprise environments.