Identity-security startup Oak emerged from stealth on July 15 with $60 million in seed funding. Accel, Greylock Partners and CRV co-led the round, which will support a platform intended to govern human, machine and AI-agent identities through one control plane.

The company is entering a security market built around a basic enterprise question: who or what is allowed to access a system? Agents make that question harder because their permissions may need to expand and contract as they perform a task.

Static accounts meet dynamic work

An employee usually has a relatively stable role, a manager and an account that can be disabled. An agent may be created for one workflow, call several other agents, use service accounts and move across applications in seconds. Its authority may come from a person, a department policy or another piece of software.

Traditional identity tools already manage many nonhuman accounts. The agent problem is different in degree and behavior: systems can initiate actions, choose tools and generate new sequences of work. A permission that is harmless for a reporting script may be dangerous when granted to an agent that can decide how to use it.

Oak says its platform maintains a continuously updated view of identities and access relationships. The product is generally available, according to the company, but buyers will need to verify how well it discovers agents, integrates with existing identity providers and enforces policy across a mixed technology stack.

Every action needs a chain of authority

Agent security requires more than authentication. An organization needs to connect each action to a purpose and principal: which agent acted, who delegated the task, what data it used, which policy allowed the action and when the permission expires.

That suggests practical controls such as short-lived credentials, least-privilege access, task-specific approval and logs that capture the agent’s identity as well as the human or system behind it. A shutdown mechanism should revoke authority immediately across connected applications.

Oak is one of many vendors likely to compete for this layer, including established identity companies. Its funding shows that agentic AI is creating a market not just for smarter software but for the controls that make autonomous action legible and reversible. Before companies deploy more agents, they need to know exactly which keys those agents are holding.


Sources for editorial review

Drafting note: This draft was prepared with AI assistance from the linked source material and requires author review, independent fact-checking and final editorial approval before publication.