The gap between what an employee is permitted to do and what an employee does has always had a buffer built into it: hesitation, a second thought, a colleague asking a question before someone hits send. Agents remove that buffer. Cyera's argument, launched today at Black Hat 2026, is that permission and execution now happen in the same instant, and that most enterprise security programs were never built to watch that instant closely.
Cyera introduced two products in response. Agent Guardian tracks every tool call, database query, and reasoning step an agent makes, beyond the prompt and the final response. Cyera Endpoint extends that same monitoring to employee devices, where developer agents such as Claude Code and Cursor increasingly run without ever touching the corporate network.
Discovery Was Never the Hard Part
Data security posture management tools have inventoried cloud data stores for years. Agent Guardian applies the same instinct to a harder target: it inventories every AI application and agent across endpoints, software as a service platforms, and cloud environments, including shadow agents and Model Context Protocol servers a security team never approved, then maps what data each one can reach.
The four stages Cyera built around that inventory, discover, govern, protect, validate, describe a lifecycle rather than a single scan. Governance sets what an agent is allowed to do and flags drift from its original purpose. Protection operates inline, evaluating tool calls in real time and blocking unauthorized data transfers before they complete. Validation red-teams the defenses continuously against prompt injection and privilege escalation, and generates the audit trail that frameworks like the EU AI Act now require.
In practice, that inventory renders as a graph for each agent: who has access to it, which channels and knowledge bases it draws from, which tools, skills, and Model Context Protocol servers it calls, and how much token consumption it runs up along the way. Security teams get the same object model for an agent that they already expect for a server or a database.
"The gap between permission and execution has disappeared."
Tamar Bar-Ilan, cofounder and CTO, Cyera
That line reframes the identity problem agentic AI creates. It is not that enterprises suddenly have more identities to track.
Each identity now acts faster than any review process can follow.
The Trust Layer Follows Agents Onto the Laptop
Cyera Endpoint is the more consequential of the two announcements for how the platform will be judged over the next year. Cloud and software as a service coverage protects data that crosses a network boundary Cyera can see. A developer running Claude Code locally, or an employee copying a file into a personal AI account on their own machine, never crosses that boundary at all. Cyera Endpoint classifies and protects sensitive files at the device level before they are accessed or leave the machine, and blocks transfers to unauthorized personal AI accounts.
That puts Cyera on ground long occupied by endpoint detection and response vendors and browser security tools built for a different threat model. Cyera is not claiming to replace those categories. It is claiming visibility into a specific failure mode neither was built to catch: an approved agent, running on an approved device, doing something the person who deployed it never intended.
The Pace Is the Strategy
In April, Cyera's acquisition of Ryft and its new Model Context Protocol server extended the platform from data classification into natural-language query access for security analysts. Agent Guardian and Cyera Endpoint extend it again, from knowing where data sits to controlling what happens to it in motion. Neither move is isolated. Cyera closed five acquisitions in the past 18 months, most recently Ryft and Genie, and shipped more than 100 product capabilities across data security posture management, privacy, identity, data loss prevention, and agentic security in the past year alone (Cyera, 2026).
That velocity is what quadrupled Cyera's valuation to $12 billion on a $600 million raise in June (Cyera, 2026). It also tells CIOs something the launch announcement leaves unsaid: Cyera is betting that enterprises will consolidate around one vendor for a problem currently split across half a dozen tool categories, and it is buying and building fast enough to make that bet before a rival endpoint or identity vendor closes the gap.
What Happens Next
Three questions will determine whether Agent Guardian earns budget beyond the Black Hat booth. Does Cyera Endpoint's device-level monitoring create a separate conversation with employees about what is being watched on their own machines, distinct from the data-at-rest conversation Cyera has run for years? Do the audit reports built for the EU AI Act hold up against an actual regulatory review, or only against Cyera's own interpretation of the framework? And does a security team already running endpoint detection and response tooling absorb Cyera Endpoint as additive coverage, or as budget competing for the same renewal cycle?
Cyera. "Cyera Launches Agent Guardian to Secure the Autonomous Workforce." Cyera, 3 Aug. 2026, cyera.com.
Cyera. "Cyera Raises $600 Million at $12 Billion Valuation to Continue Building the Trust Layer for the AI Era." Cyera, 10 June 2026, cyera.com.
