Oak raises $60M: every AI agent is an identity you forgot
Oak's $60M seed targets AI agent identity sprawl — the permissions you grant automations and never revoke. Here's how to audit yours this week.
Every AI agent you deploy is a new identity with permissions attached — and almost nobody revokes them. That's the gap Oak just raised $60 million to close, and it's worth your attention even if you'll never be their customer. The AI agent identity problem scales down to a five-person shop faster than most security problems do.
What actually happened
Oak came out of stealth on July 15 with a $60 million seed round co-led by Accel, CRV, and Greylock Partners, with participation from AlphaDrive Ventures and Hetz Ventures. Founded in December 2025 by CEO Shai Morag — formerly Tenable's CPO, who sold Ermetic to Tenable for $265 million in 2023 — and CPO Tal Marom.
The product is a control plane that governs every identity in an organization: human, machine, and AI agent. Per TechCrunch, it maps granted access against actual application usage and strips unnecessary permissions in real time — instead of waiting on a quarterly access review. Morag's framing of the status quo: "there's no trigger when an employee logs in from an unusual location."
That a seed round this size went to identity governance tells you where the sophisticated money thinks agent risk actually lives. Not in the model. In the credentials.
Why AI agent identity matters for your business
Here's the version that applies to you. Every automation you've built in the last year got credentials. The Zapier connection that reads your inbox. The scraper with a Shopify admin token. The support bot with database access. The n8n workflow someone spun up in March and stopped using in April.
None of those show up in an org chart. None get offboarded. Most were scoped generously because narrowing permissions is annoying and it was easier to grant admin and move on. And unlike an employee, an agent never mentions that it still has the keys.
You don't need a $60M platform to fix this. You need a list. Open every tool holding an API key or OAuth grant on your behalf and answer three questions: what does this still do, what can it reach, and does anyone still use it. Kill what fails question three. Narrow what fails question two.
That audit takes an afternoon. It is the highest-return security hour a small business will spend this quarter.
Key takeaways
- Oak emerged from stealth July 15 with a $60M seed co-led by Accel, CRV, and Greylock, founded by ex-Tenable CPO Shai Morag
- The product governs human, machine, and AI agent identities in one control plane, revoking unused permissions in real time rather than at quarterly review
- Seed money at this scale flowing to identity governance signals where agent risk really sits: in credentials, not models
- Your version is an afternoon: inventory every API key and OAuth grant, kill what's unused, narrow what's over-scoped
Not sure what your automations can actually reach? We build agent workflows with scoped credentials and revocation built in from day one — not bolted on after an incident. Tell us what's running and we'll help you map it.
Sources: TechCrunch, PR Newswire.
- #ai-agents
- #identity
- #security
- #permissions
- #automation
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Pilot Protocol's $4.5M: a directory isn't a standard
A seed-stage AI agent network wants to be where agents discover each other. Useful, but know the difference between an open spec and someone else's front door.
Read itNvidia backs Safe Superintelligence, discloses no terms
Nvidia's Safe Superintelligence partnership names no dollar figure and no term length. Reported at $5B. Here's how to read AI deals that omit the numbers.
Read it