This website uses cookies

Read our Privacy policy and Terms of use for more information.

Sponsored by

Save 10+ Hours a Week With 37 Claude Prompts

Every manager faces the same situations before lunch: a message to land, a meeting to run, a hiring call, a report due. The AI Report built 37 Claude prompts for exactly those moments, organised by the situations every manager faces. 

Copy the prompt, fill the brackets, run it in Claude, and get back 10+ hours a week. Oh, and it's free. 

All you have to do is subscribe to The AI Report, a 5-minute daily AI brief read by 400,000+ business leaders at IBM, AWS and Microsoft, and the full prompt pack lands in your welcome email. The newsletter and the prompts, both free. Subscribe and grab both

-THE WIRE  THIS WEEK IN IDENTITY

N°01 · M&A

SailPoint closed its $200M acquisition of Entro Security

The dominant IGA vendor just spent a reported $200 million to bolt on non-human identity capability it didn't have. Entro built a platform for mapping and protecting NHIs — secrets, tokens, certificates, agent credentials — and it now feeds SailPoint's Agentic Fabric. If you still had any doubt that NHI governance is table stakes for a complete identity program, the market just answered you. SAILPOINT

N°02 · POLICY

The NSA published its first security guidance for Model Context Protocol

Not NIST. Not a vendor whitepaper. The NSA. Seventeen pages from its Artificial Intelligence Security Center on why MCP's rapid adoption has outpaced the security controls enterprises actually need — and what to do about it before your agents outrun your governance. NSA.GOV

N°03 · FUNDING

Oak came out of stealth with a $60M seed to be the "Identity Operating System"

Accel, Greylock, and CRV co-led a $60 million seed for a company billing itself as the AI-native Identity Operating System: one continuously updated control plane governing every identity — human, machine, AI agent — replacing the fragmented legacy stack outright. A seed round that size, for a category that barely existed 18 months ago, is a signal worth pricing into your budget. PR NEWSWIRE

Hey {{first_name|there}},

Before we dive in for this week, we need to hop in the time machine real quick and check out next week. Something is clearly in the water when it comes to identity companies, as both C1 and Saviynt are launching something to the market. C1 on the 27th, and Saviynt on the 28th. I’ll give you three guesses on what it’s about..lol. I digress, let’s get to the good stuff!

Someone asked me last week what I'd do with a $500K identity budget in today's environment. One fiscal year, no strings, but you have to show real risk reduction by the time it's spent.

I've been thinking about that question ever since, because the honest answer is that the question itself is where most organizations go wrong. And the three stories in the Wire above are exactly why: the market is moving fast, money is moving fast, and where to put your identity budget has never been harder to answer.

Most teams arrive at the budget conversation backward. They have a line item for IAM tools. They're renewing their IGA platform, maybe evaluating a cloud entitlements product, maybe adding another CASB layer. They're spending money to maintain an architecture they built five years ago and hoping it holds.

It will not hold. Not in 2026.

I've watched the access model evolve through mainframes, client-server, cloud, SaaS, and now agentic AI. Every transition didn't just add new things to govern. It broke the assumptions the previous governance model was built on.

The assumption that just broke is the simplest one. That identities are people.

Your IGA platform was designed around human identities. A worker joins, gets provisioned, gets certified, gets deprovisioned. The model worked because every identity had a human owner who could certify its access. AI agents don't have human owners in any meaningful sense. They act autonomously. They call APIs, write to databases, and spin up other agents. They acquire credentials you didn't provision and access resources you didn't authorize. And your current access review process has no mechanism to even see them.

This isn't a fringe worry anymore. The Cloud Security Alliance's survey of enterprises running autonomous agents found that 40 percent already have agents in production, and the most common way they authenticate them is still static API keys. By most counts, non-human identities in an enterprise already outnumber humans by something like 45 to 1, and far more than that in cloud-native shops. The 2026 Verizon Data Breach Investigations Report named service accounts and machine identities as the identities most likely to be leveraged as attackers move into the agentic era. SailPoint just paid $200 million because this is not a small gap.

So back to the $500K. The wrong answer is the one most people reach for first, which is to go shopping. Pick the shiniest agent-identity platform, write the biggest check the budget allows, and hope the demo survives contact with your environment. I've watched that movie enough times to tell you how it ends. You spend $400K on a platform, $100K on the integration the platform needed but the salesperson didn't mention, and a year later you have a tool nobody owns sitting next to the problem it was supposed to solve.

Here's how I'd actually spend it, in order, because the order is the whole point. Each step earns the right to the next.

The first $50K doesn't go to a vendor. It goes to visibility you own. Some of the inventory work I keep preaching is free, but a clean, automated, continuously refreshed picture of every non-human and agent identity in your environment is worth paying for, because the version you maintain by hand decays the week you stop. Remember the number: 45 non-human identities for every human one, and most organizations operating blind on the majority of that surface. Spend here first, because every dollar after this is wasted if you're aiming it at a map you can't trust. Buy the eyes before you buy anything that acts on what they see.

The next $150K goes to enforcement at runtime. Not another quarterly certification cycle. Per-action authorization, scoped to context, that can actually deny an agent in flight instead of certifying its access three months after the fact. This is what those static-credential defaults are really telling you: most enterprises can watch their agents misbehave and can't stop them. The DBIR just told you machine identities are where attackers are headed. The $150K buys you the brake pedal. If I could only fund two things, it would be the eyes and the brake. Everything else is optimization on top of those two.

The next $100K is the one nobody budgets for and everybody needs, which is people and process. An ownership model. A named human for every identity that matters. A lightweight gate at creation so the inventory you just paid to see doesn't refill with ungoverned junk by Q3. You can buy the best platform on earth and it will rot if no one owns the identities it's governing. This is unglamorous, and it's the difference between a tool and a program. I'd rather have a mid-tier platform with real ownership underneath it than a best-in-class one governing a swamp.

The next $100K I'd hold. On purpose. Because the agent-identity market is moving so fast that the right product in Q4 may not exist in Q1, and Oak is the proof. A team just came out of stealth with $60 million from Accel, CRV, and Greylock to rebuild identity from the agent up, in a category that barely existed 18 months ago. SailPoint just spent $200 million buying capability it couldn't build fast enough. When the market is inventing new categories on a quarterly cadence, spending your whole budget in January means buying last year's answer to this year's problem. Hold a real reserve and stay liquid enough to buy the thing that's actually built for where you'll be, not where you were.

That's $400K. The last $100K is the one that pays for all the rest, and it's the one almost nobody funds. It goes to translation. To being able to walk into the room where next year's budget gets decided and prove, in the language executives fund, what this $500K bought. What the blast radius was before and after. What the quantified exposure looked like and what closing it was worth. Because the brutal truth of a one-year identity budget is that the work doesn't end when the money does, and the only way you get the second budget is by pricing the first one in terms the people with the checkbook actually understand.

That's the part I'd protect most fiercely, because I've watched genuinely good identity work die at renewal time. Not because it didn't reduce risk, but because the practitioner who did it couldn't translate the risk reduction into the only dialect the budget room speaks, which is dollars and exposure and what-this-prevents. The technical win was real and the funding still evaporated, because nobody connected the work to the number.

That translation is exactly what I built the Identity Value Matrix for, and it's why I'd spend the last $100K making sure I could do it well. It's the tool I use to turn "we hardened our agent identity posture" into "here is the exposure we closed, here is what it was worth, here is why year two funds itself." It's a Knight-tier resource and I'll point you to it below, because the spend isn't the hard part of this job. The spend is easy. Proving the spend was worth it, in a way that gets you the next one, is the part that separates the programs that compound from the ones that restart from zero every fiscal year.

So forget the $500K for a second. When your team sits down to plan next year's identity budget, the first question is usually some version of "what do we need to renew?" That's a maintenance mindset, and maintenance thinking in a threat environment that has fundamentally changed is how you end up three years behind. Look at who moved this month alone: SailPoint bought its way into NHI, the NSA wrote the guidance, Oak raised sixty million to rebuild identity from the agent up. Vendors on every side of this market saw the same gap at the same time.

What question is your team not asking right now?

Quick thing before you go.

If this one landed, there's a version of Identity Jedi that goes a lot deeper than the free edition. Members get the full Deep Dives with nothing held back, plus the tools I actually use in the field. The Identity Value Matrix is the one this issue is built around, the framework for turning identity work into the budget language executives fund, and the spend sequence above is a lot sharper when you can put real numbers behind it. Knight is 49 a month, it includes the Identity Value Matrix and the monthly live Q and A with me.

You've been reading for a reason. Want the tools that go with it?

The Last Word

Spend in order, because the order matters more than the size of any single line. Eyes before action. Ownership before tooling. A reserve held back for the answer the market hasn't shipped yet. And the bet that pays for all the others is the one you make on your own ability to prove the spend was worth it. Get that one wrong and the best identity work of your career still ends at renewal. Get it right and the money compounds.

See ya next week.

Be good to each other, be kind to each other, love each other

David Lee

Reply

Avatar

or to participate

Keep Reading