Skip to content
TECH CEO Daily
SaaSAnalysis

Salesforce requires AI agent identity as Cyera and Island raise $800 million

Software platforms are starting to treat AI agents as users with their own badges. Security vendors are racing to govern them, and CISOs need an agent inventory now.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Salesforce said on September 17 that AI agents must be registered with their own credentials and permissions.
  • 2Cyera and Island each raised $400 million in late September for what they describe as governing AI agent access and data use.
  • 3CISOs should inventory agents, assign owners, remove borrowed human credentials and enforce least privilege.

The news

Salesforce (CRM) said on September 17 that AI agents calling its platform must be registered with their own credentials. Over the following week, Cyera and Island each raised $400 million for what they describe as governing AI agent identity, access and data use across the enterprise.

Salesforce's help article describes a feature called Agentic Identity. Administrators register each agent and give it narrower permissions than a human user, which Salesforce describes as "issuing the agent its own badge, rather than lending it an employee badge." Customers will have three months to register agents after Salesforce says the feature is available. A September 22 Salesforce blog for IT teams described a separate feature, MCP Risk Scores, which scans MCP servers connected to Agentforce for threats at registration and keeps scanning them afterward. Model Context Protocol (MCP) is a standard that lets AI models call outside tools.

Investors moved quickly. On September 22, data security company Cyera announced a $400 million extension of its Series G from Goldman Sachs Alternatives' growth equity team, valuing it at more than $12 billion. Cyera said it completed its purchase of Oasis Security on September 3 to add non-human identity management, meaning control over the credentials used by software, machines and agents. On September 24, Island, known for its enterprise browser, raised a $400 million Series F at a $6.4 billion valuation, led by Evolution Equity Partners, and pitched itself as a control plane for both people and AI agents.

Identity governance vendors are adapting too. On September 24, Omada said it acquired EmpowerID, whose software authorizes agent actions in real time rather than finding violations in later audits. Omada chief executive Jakob H. Kraglund said AI agents are already at work inside enterprise systems, moving faster than most security teams can monitor. Earlier, on September 17, Comp AI raised $34 million for AI agents that automate security compliance work such as policy drafting and audit evidence, TechCrunch reported.

The numbers

Cyera Series G extension / valuation
$400 million / more than $12 billion
Island Series F / valuation
$400 million / $6.4 billion
Comp AI Series A
$34 million
Salesforce agent registration window
Three months after availability notice

Why CEOs should care

CISOs should start with an inventory. List every AI agent, copilot connector and automation bot that touches production systems, who deployed it, what data it reads and what actions it can take. Expect to find some agents running under a person's login or a shared integration account. Those are the first to fix: give each agent its own identity, a named human owner, least-privilege permissions and logs that tie every action back to the agent.

CIOs should treat vendor registration deadlines as project dates. Salesforce's three-month window will start when it announces availability, and other platforms may follow with their own rules. Registering agents also affects cost, since Salesforce plans to meter calls by registered agents through Flex Credits. Build one registration process across platforms rather than a new one per vendor, and decide which team approves new agents.

Boards and audit committees should ask two questions at the next review: how many AI agents operate in production, and who is accountable for each? Also ask whether current identity, data security and browser tools overlap. Cyera, Island and Omada each now claim part of agent governance from different starting points, and buying all three without a plan will leave gaps and duplicate spend.

The bigger picture

Identity security is expanding from people to software actors. For two decades, enterprises managed employee accounts and, less carefully, service accounts. AI agents behave like both: they act on a person's behalf but run continuously and at machine speed. Platforms such as Salesforce are responding by making agents first-class identities with their own permissions and meters. Security vendors are converging from data security, identity governance and the browser. Island's chief technology officer, Dan Amiga, argued that because agents span many parts of the technology stack, governing them from any one point will fall short.

What’s next

Salesforce's help article says it is targeting November for agentic registration, new security controls and a new billing model; that is a target, not a confirmed release date. Watch for other software platforms to publish agent registration rules, for Cyera and Omada to integrate their acquisitions, and for agent governance to appear in audit and compliance frameworks. Companies that finish an agent inventory before the first deadline will set policy rather than react to it.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

SalesforceCyeraIslandOmadaAI security

Earlier coverage of Salesforce

All Salesforce coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.