Skip to main content
Back to News
news/AI Safety

AI Agents Force a New Security Layer for Enterprise Teams

Cymphony raised $30 million to map AI-agent access across enterprise systems, showing why identity and data controls must evolve beyond human users.

Stefan Trbojevic

Stefan Trbojevic

9 September 20263 min read
LinkedIn
Abstract enterprise identity graph with protected data paths

The takeaway

AI agents should be governed as first-class identities with explicit permissions, traceable tool use, and revocable access.

Why it matters for builders

Treat every AI agent as a first-class identity: scope its permissions, log its tool actions, and make access revocable.

AI Agents Force a New Security Layer for Enterprise Teams

AI agents are moving from chat windows into the systems where companies store sensitive data, approve work, and execute business processes. That shift is creating a security problem that traditional identity tools were not designed to solve.

What happened

Cymphony, a New York- and Tel Aviv-based startup, raised $30 million in new funding, including a $25 million Series A co-led by Sequoia Capital and SMBC Fin Atlas Beyond Fund, according to TechCrunch. The round values the company at more than $100 million.

Cymphony is building a “workforce graph” that combines identity, data, and activity signals across employees, AI agents, and other non-human identities. The company says it found roughly 85,000 files exposed to AI tools at one public company, although it reported that those files were not accessed through the systems it investigated.

The startup also described an incident involving an unsanctioned Claude installation that used an external collaborator’s existing access to scan thousands of sensitive files. Its platform can investigate incidents, prioritize remediation, and correct access permissions, with customers choosing how much automation security teams want to allow.

Abstract enterprise identity graph with protected data paths

Why it matters for builders

The important change is not simply that agents can call more tools. Agents can operate at machine speed, change their route through a workflow, acquire capabilities at runtime, and sometimes create additional agents. A permission model based only on named human users therefore misses the actor that actually touched the data.

For teams building automations, the practical response is to treat every agent as a first-class identity. Record which workflow version acted, which tool it invoked, what data it read, and what policy authorized the action. Separate read, write, and external-send permissions, then add approval gates for irreversible steps.

Cymphony’s funding is a market signal, but the engineering lesson is more immediate: agent deployments need an identity and activity layer before they need more autonomy. The safest agent is not the one with the fewest capabilities. It is the one whose capabilities are explicit, observable, and revocable.

Share𝕏

The Automation Brief

Read 5 AI stories instead of 50.

The essential moves in AI agents, models, automation and infrastructure — filtered for builders and operators, with the part that actually matters.

No noise. Unsubscribe anytime.

Editorial notes

Reported by

Stefan Trbojevic

Edited by

n8n Lab Editorial

Published

9 September 2026

Updated

9 September 2026

AI disclosure: AI assisted with research and drafting. Factual claims are reviewed by an editor.

n8n Lab is an independent service provider. We are not affiliated with, endorsed by, or sponsored by n8n GmbH. “n8n” is a trademark of n8n GmbH and is used here only to describe the platform-specific implementation and automation services we provide.