Okta and Cyera just paid $1.2 billion to acquire two startups that govern enterprise AI agents — and the CEO of a third player names, bluntly, the risk that also poses to small businesses
Between July 27 and 30, 2026, five separate deals put a real price on a single problem: who controls what an AI agent is allowed to do. Okta paid $200 million for Permiso Security, Cyera $1 billion for Oasis Security, and Inforcer raised $50 million to help IT service providers (MSPs) protect their small-business clients — its CEO bluntly naming a real risk: AI also lowers the barrier to attacking.
The week of July 27, 2026 saw five separate deals — uncoordinated with each other — converge on the same narrow problem: who controls the AI agents running inside enterprise systems. Cyera, which had just raised $600 million at a $12 billion valuation, paid roughly $1 billion to acquire Oasis Security, an identity and access governance platform for AI agents. Okta paid $200 million for Permiso Security, which specializes in cloud identity analytics. Both acquisitions target the same finding: a company's identity perimeter now includes non-human agents, and existing tools weren't built for that. The same day, Inforcer — a UK platform dedicated to managed service providers (MSPs), the companies that run IT for thousands of small businesses — raised $50 million in a Series C led by Insight Partners, specifically to help those MSPs govern their clients' AI deployments.
Inforcer's CEO, Jamie Daum, put it bluntly: "Anthropic's Claude Code can turn anyone into a 'vibe coder,' and Mythos can turn anyone into a hacker. The threat landscape has never been more dangerous for small businesses." In other words: AI doesn't just lower the barrier to automating a job — it also lowers the barrier to attacking a company that can't afford a dedicated security team. The market's response, so far, is an extra layer: an MSP that manages, on the small business's behalf, a separate AI governance and security platform — one more subscription and one more vendor, not a native property of the tool the small business already uses every day.
For AppH
- Confirms, with real money ($1.2 billion in acquisitions the same week), that governing what an AI agent is allowed to do is now recognized as urgent infrastructure — exactly the stance AppManager applies by default on every module since its design, with no separate security subscription to add on top.
- The principle Inforcer sells as an add-on feature to its MSP clients — knowing precisely what an agent did and why — is, at AppH, explicit human approval before the action, logged in DECISIONS.md/the audit trail, never an optional checkbox.
Against / what doesn't apply
- AppH isn't a security or threat-detection platform: it doesn't monitor "shadow AI" (an employee pasting company data into a personal AI tool) or the overall security of a client's Microsoft 365 environment — its governance covers what happens INSIDE AppManager, not the client's entire information system.
- The price of these acquisitions ($1.2 billion combined) reflects a problem at the scale of companies with thousands of employees and complex cloud environments — the real exposure of an AppH client small business is far more modest in absolute terms, even if the principle (someone must decide what an agent is allowed to do) applies at any scale.
What strikes us as important about this week of acquisitions is that it confirms — with real money, not a prediction — that the question "who has the right to decide what an AI agent can do" is becoming a full enterprise-security budget line item, not an optional extra. We've shared that view since AppManager's first module: nothing executes without explicit, logged human validation. But we want to be honest about a real limit rather than dress it up: Inforcer and the platforms Okta and Cyera just acquired govern a company's entire IT environment — every tool, every account, every agent, wherever it runs. AppManager governs what happens inside AppManager. If a small business's real risk is an employee pasting confidential data into a public AI tool from their personal computer, that's not a problem AppManager solves today — and saying so clearly matters more to us than letting anyone believe otherwise. What we can state without overstating it: within the perimeter AppManager actually covers (quotes, invoices, CRM, calendar, fleet, and the rest), the principle that a billion dollars in acquisitions just validated this week — human approval before every agent action, a record of why — was already there, by default, at no extra charge.
Reviewed by a human at AppH