TL;DR: Enterprises are handing AI agents broad access to their most sensitive SaaS applications, often without realizing the exposure that creates. Obsidian’s own data shows 90% of those agents are over-permissioned and move 16 times more data than humans accessing the same systems. Existing security tools weren’t built for threats that move at machine speed. Obsidian Security raised $85M to bridge that gap, applying its decade of SaaS identity and access visibility to the AI agents now operating inside enterprise environments.

Enterprises deploying AI agents have asked one question: what can these agents do? Few have asked the harder one: what can they reach?

Those are not the same question, and the difference between them is where the exposure starts. AI agents plugged into enterprise SaaS inherit permissions, form integrations, and move data across every connected application, often with far less oversight than any human employee would receive. When one is misconfigured or compromised, it doesn’t click a few wrong links. It moves across systems at machine speed, touching data that most security teams didn’t know it could reach.

The security stack most enterprises have today was built for human identities. AI agents are something else entirely, and the tools haven’t kept up.

Obsidian Security raised $85M because knowing what your agents can do is no longer enough.

The Threat Didn’t Evolve. It Changed Shape.

Traditional enterprise security relied heavily on perimeter controls. As operations moved into SaaS applications, identity and access became more central to the security model.

Attackers adapted, increasingly relying on stolen credentials, compromised sessions, and over-permissioned accounts to gain access. The wall stopped being the problem. The door became the problem.

Identity became the real battleground. Then AI agents arrived, introducing an entirely new layer of identities, non-human ones, that most existing security tools weren’t built to track.

Hundreds of Apps, and Nobody Watching All of Them

Obsidian Security was founded in 2017 on a problem that was already large and getting larger. A modern enterprise doesn’t run on one system. It runs on hundreds of SaaS applications, Salesforce, Microsoft 365, Workday, and dozens of others, each holding a different slice of the company’s most sensitive data.

The challenge is that many security teams struggle to maintain one complete view across their SaaS environments. The problem is partly structural: each application has its own configurations, identities, integrations, and permissions, making centralized oversight difficult.

That’s exactly where Obsidian built its business around. Its platform tracks identities, permissions, configurations, and activity across connected SaaS applications, watching for compromised accounts, risky configurations, and identity-based attacks across the estate.

Now, AI agents are layered on top of that same SaaS infrastructure. They operate under the same identity and access model. And they create risks that most existing security tools weren’t designed to catch.

A Compromised Agent Creates Risks That Move at Machine Speed

This is where the business case becomes much clearer.

A compromised human account can expose sensitive systems. A compromised AI agent, however, may create additional risk because it can operate autonomously across connected applications, often carrying broad privileges, long-lasting tokens, and moving data at machine speed.

CEO Hasan Imam has been direct about what that looks like inside real enterprise environments:

The data backs that up: agents are granted up to ten times more permissions than their workflows actually need, and that excess access is what turns a misconfiguration into a company-wide exposure. 

An over-permissioned or compromised agent may act across several connected applications and access large volumes of data before the activity is reviewed. A misconfigured or hijacked agent can expose data across every application and integration connected to its permissions, including SaaS supply chains that extend far beyond the original deployment.

The problem is that existing SaaS governance processes often rely on manual reviews that cannot match the speed of autonomous agents. That gap is where the exposure lives.

Why Obsidian Was Already in the Right Place

Obsidian has spent years mapping identities, permissions, configurations, and activity across the SaaS applications connected to its platform. Securing AI agents is, in large part, about controlling what they can reach and flagging when they reach beyond what they should. That existing visibility gives Obsidian a foundation for extending its platform to AI-agent access and activity.

Rather than starting from scratch, its AI-agent offering extends the identity and integration visibility already central to its SaaS security platform. The company monitors and governs agents operating across applications including Microsoft Copilot Studio, Salesforce Agentforce, and Anthropic’s Claude.

Imam put the customer reality plainly: 

The numbers help explain why. Obsidian counts 60 of the Fortune 500 among its customers, spanning financial institutions, social media networks, and telecom providers. More than 100 customers now spend over $100,000 annually on its platform. The company grew close to 1,000% between 2021 and 2024, ranking No. 95 on the 2025 Deloitte Technology Fast 500.

AI Is Creating New Demand for Security Software

Most software categories are reckoning with what AI does to their business model. For Obsidian, AI adoption is creating additional demand for visibility, access governance, and threat detection.

With every new AI integration, enterprises introduce additional identities, permissions, and data flows. Greater AI adoption is likely to increase scrutiny of agent permissions and SaaS integrations, and security budgets tend to follow once the risk becomes concrete.

The shift is already underway. Databricks completed its acquisition of Panther Labs on August 3, 2026, its third security acquisition, combining Panther’s SOC workflows and detection capabilities with its own security lakehouse infrastructure. That a company of Databricks’ scale is buying its way directly into cybersecurity, rather than partnering for it, says something about where enterprise priorities are heading.

The same infrastructure enterprises use to run AI is now the infrastructure that needs governing.

The Wager Every Enterprise Is Now Being Asked to Make

The question underneath all of this isn’t really about any single security vendor. It’s about how enterprises think about the access they’ve already handed out, and whether the tools they have today are actually built to govern it.

Most are focused on what their agents can do. The bigger question is what those agents can reach. That includes which applications, identities, data flows, and the blast radius would look like when something goes wrong at machine speed with no human in the loop. Those are not the same conversation, and enterprises that treat them as one are working with an incomplete picture of their own exposure.

That’s exactly where Obsidian is betting that SaaS security and AI-agent security are becoming the same problem. That bet isn’t a pivot or a repositioning. It’s the natural extension of nearly a decade spent mapping what enterprise SaaS environments can touch, what they expose, and where the risks concentrate. The $85M is the market’s signal that the timing is right.

Ultimately, what enterprises decide now, about governance, permissions, and what their agents are allowed to reach, will determine how that plays out. 

Author

She enjoys breaking down complex topics into content that feels clear, useful, and easy to connect with. When she isn’t writing, she’s usually lost in a book or spending time with her three cats who bring equal parts chaos and companionship to her day.Follow Poulami on LinkedIn.

Write A Comment