Identity Security
What identity security is
Identity security is the discipline of governing who (and increasingly what) can access which resources, under what conditions, and for how long. It is not one product but a stack of adjacent control points that grew up separately and are now colliding:
- Access management (IAM / SSO / MFA): the front door — authenticating a human or service and issuing a session. Revenue model: per-user-per-month SaaS, priced on monthly active identities.
- Privileged access management (PAM): vaulting, rotating, and brokering the powerful credentials (admins, root, service accounts) that attackers most want. Higher ACV, stickier, compliance-mandated.
- Identity governance & administration (IGA): the system of record for entitlements — who should have access, certified on a cadence, joiner-mover-leaver automation. Slow-moving, deeply embedded, audit-driven.
- Machine / non-human identity (NHI): the fastest-growing frontier — securing the secrets, tokens, API keys, and workload identities that now outnumber humans 40-to-1 in a modern cloud estate.
- Identity threat detection & response (ITDR) / CIEM: the detection layer that watches identity in use and flags compromise or over-permissioned entitlements.
These were five separate buying centers a decade ago and are converging into a single identity fabric; whoever assembles the most complete fabric, with distribution, captures the pool.
Economics and differentiation across layers
| Layer | Leaders | Challengers | Economics & moat | M&A posture |
|---|---|---|---|---|
| Access (IAM/SSO/MFA) | Microsoft Entra, Okta | Ping (Thoma Bravo), Cloudflare, Beyond Identity | Per-MAU SaaS; moat = directory lock-in + app integrations (Okta's ~7,000+ pre-built connectors) | Okta independent buyer; Ping a TB roll-up |
| PAM | CyberArk (now Palo Alto), Delinea (TPG), BeyondTrust | Teleport, StrongDM, HashiCorp Vault (IBM) | Highest ACV in identity; vaulting is compliance-mandated and highly retentive | CyberArk absorbed; Delinea/BeyondTrust are sponsor-owned consolidators |
| IGA | SailPoint (re-IPO'd 2025), Saviynt | Omada, Zilla (CyberArk), Lumos | Deep ERP/HR integration; switching cost is enormous; slow sales cycles | SailPoint public again; Saviynt a likely strategic target |
| Machine / NHI | Astrix, Aembit, Token Security, Oasis, Silverfort, Clutch | Entro, Britive, Corsha | Land-grab pricing; moat still forming; secrets sprawl is the wedge | VC-backed, strategic-scarce; primarily sell-side candidates |
| ITDR / CIEM | Silverfort, Microsoft, CrowdStrike | Permiso (Okta, agreed Jul 30 2026), Sonrai, Ermetic (Tenable) | Detection layer; rides the platform's data | Tuck-in fuel for platforms (Tenable–Ermetic, Microsoft, Okta–Permiso) |
The key differentiation: PAM and IGA are "system-of-record" businesses (high switching cost, durable, compliance-anchored — which is why TB and PANW pay up for them), whereas access management is a distribution business (whoever owns the directory — Microsoft — has structural advantage), and NHI is a greenfield land-grab (no incumbent has won yet, which is why it draws the most sell-side interest).
Consolidation map
Signature deals
- Palo Alto → CyberArk, $25B, closed Feb 11 2026 — the largest pure-play identity deal ever; puts PAM at the center of a network/cloud/SOC platform and reframes identity as the platform battleground.
- Thoma Bravo → SailPoint (2022, $6.9B) → re-IPO 2025 (~$12B+) — the take-private-improve-relist loop, executed on the IGA leader; SailPoint's NHI line is now its fastest-growing segment (see 06a).
- Thoma Bravo → Ping Identity ($2.8B) + ForgeRock ($2.3B), merged — built an access-management challenger by combining two assets it owned.
- Tenable → Ermetic; CrowdStrike, Microsoft into ITDR — detection-layer tuck-ins that pull identity telemetry into the platform.
- Okta → Permiso, agreed Jul 30 2026 (~$200M reported; terms undisclosed by Okta) — the access-management leader extends beyond identity issuance into identity threat detection and response, adding runtime detection across human, non-human and AI-agent identities and pulling Okta into the security operations center. Part of the same 2026 wave of identity and data-security platforms absorbing agentic-identity capability (cf. Cyera–Oasis; see 20b).
- 1Password → Apono, ~$250–300M (reported ~$275M), announced Jun 15 2026 — extends 1Password (AgileBits) from credential security into access governance: just-in-time, policy-scoped, auto-revoked access for every human, machine, and AI-agent identity, paired with its new Credential Broker. The clearest sign that the password-manager incumbents now see NHI/agent access as core, not adjacent. See 11.
- Machine-identity rounds (2025–26): Persona's ~$200M Series D and continued raises across Astrix, Aembit, Token Security, and Oasis confirm NHI as the venture frontier — and the next strategic shopping list. NewCore extended this in Jun 2026 with a $66M seed at a $300M valuation (Cyberstarts-led; founder Zohar Alon of Dome9/Check Point), launching a "security-first identity" platform that treats AI agents as first-class identities — the largest pure AI-agent-identity seed to date.
- Oak — $60M seed, announced Jul 15 2026 (emerged from stealth) — co-led by Accel, CRV, and Greylock Partners, with Hetz Ventures and AlphaDrive Ventures. Founded December 2025 by Shai Morag (CEO; prior exits include Secdo→Palo Alto Networks 2018 and Ermetic→Tenable 2023) and Tal Marom, Oak is an AI-native identity platform — a single control plane intended to replace the fragmented identity-governance/security stack — governing every identity, whether human, machine, or AI agent, generally available and deployed at enterprise customers at launch. Alongside NewCore's $66M and Ent's $100M seed rounds, it is the third identity mega-seed of the 2026 cycle, a signal that agent-era identity now attracts repeat founders at unprecedented entry prices (PR Newswire, Jul 15 2026 · TechCrunch); see 11.
- Keyfactor → Cofide, announced Jul 27 2026 (terms undisclosed) — the first strategic acquisition off that growth capital. Keyfactor acquires UK-based Cofide (founder and CEO Matthew Bates), an open-standards platform built on SPIFFE, OAuth and OIDC that issues each software workload and AI agent a unique, short-lived verified identity in place of static secrets, extending the Trust Control Plane from PKI and certificates into cloud-native workload and agentic identity. The machine-identity incumbent moving into agentic identity by issuance — the counterpart to Okta–Permiso's move into agentic-identity detection — with team and technology joining immediately. See 11, 20b.
AI-agent access governance
The fastest-moving thread inside NHI is no longer just secrets sprawl but governing what an autonomous AI agent is allowed to do — provisioning an agent identity, scoping its access to a task, and revoking it when the work is done. Agentic workflows broke the old assumption that identity = a human with a standing account: agents are non-deterministic, numerous, and short-lived, so the control model shifts from vaulting a credential to brokering just-in-time, policy-bound access in real time. This is the wedge under the 2026 identity buying wave — CrowdStrike–SGNL (real-time grant/revoke), Cisco–Astrix and Cisco–WideField (agent/NHI discovery + telemetry into Splunk's Agentic SOC), SailPoint–Entro (secrets + machine-identity into its Agentic Fabric), 1Password–Apono (JIT access governance), and Keyfactor–Cofide (SPIFFE-based workload/agent identity issuance). Finro's Q2 2026 dataset confirms the pull at the deal level: IAM led every cyber niche with 15 M&A transactions at a ~20x average EV/Revenue, explicitly attributing the demand to "AI-agent proliferation making identity infrastructure non-negotiable for platform buyers" (see 12). The independents still in play — Aembit, Token Security, Oasis, Britive, Corsha, plus newly-funded NewCore — sit directly in the path of that demand.
The bear case
If Microsoft's directory advantage compounds — Entra bundled into E5, free Security Copilot capacity, ITDR built in — then standalone access vendors (even Okta) face structural multiple compression, and the independent identity premium narrows to PAM, IGA, and NHI only. The falsifiable test is Okta's net revenue retention and whether NHI startups can reach durable seven-figure ACVs before the platforms ship "good-enough" native NHI. If NHI economics stay thin and platforms ship native, the land-grab collapses into tuck-ins rather than standalone exits.
→ Cross-references: Vendors, Thoma Bravo, Deals & Comps, AI Security, Buy-Side Prospect Framework.
Adjacent market: the fraud-prevention and identity-verification industry converging with cyber identity is mapped on Fraud & Identity Verification.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.