Shai Morag doesn't do things quietly. After selling two cybersecurity companies for a combined $365 million—first to Palo Alto Networks, then to Tenable—and a brief stint as Tenable's chief product officer that ended following the sudden death of CEO Amit Yoran, Morag went into stealth mode in December 2025.
Seven months later, he re-emerged with Oak, a new identity platform, $60 million in seed capital from Accel, CRV, and Greylock, and a claim that might have sounded absurd just two years ago: enterprises now have more AI agents than human employees. By a factor of 100 to 1, according to a Greylock investor blog—though the firm provided no underlying data to support that ratio.
Those agents—software entities that can read documents, trigger workflows, interact with customers—need to be governed, Morag argues. And most chief information security officers haven't figured out how.
The July launch positions Oak not as another vendor in the already-crowded identity governance market, but as something more ambitious: an operating system for identity itself. One control plane to see and govern human users, service accounts, and that mushrooming population of autonomous agents, all in real time.
Whether CISOs are ready to buy that vision is another question entirely.
The Identity Problem Just Got Weirder
Identity has become the new perimeter, a phrase now so common it borders on cliché. But the cliché exists because it's true.
Gartner flagged identity-based attacks as a top CISO priority back in March 2026. A market report from July projected the Identity Threat Detection and Response sector ballooning from $12.4 billion in 2025 to $55.3 billion by 2032. Companies are spending billions on a fragmented stack: SailPoint for governance, Okta for access management, separate tools for privileged accounts, cloud entitlements, just-in-time access.
Morag's bet—and it is very much a bet at this stage—is that stack can collapse into a single AI-native platform. More than that, he believes the same system that manages when Sarah from Marketing can access Salesforce should also manage when an AI agent queries Snowflake or pulls customer records from Datadog.
The pitch arrives at a curious moment. Most legacy identity governance platforms were architected for a world where "identity" meant people. Maybe service accounts, if you were sophisticated. They weren't built for entities that spawn dynamically, operate with delegated permissions, and make autonomous decisions without a human in the loop.
Oak is betting that's about to change. Fast.
What's Under the Hood

According to the company's website, Oak's architecture rests on three core components. They work together to create what Oak calls an "Identity Intelligence Layer," though that's the kind of branding that could mean almost anything.
First: a live identity graph. A continuously updated map of every identity in an enterprise—people, service accounts, AI agents. Oak connects through what it calls "ConnectAny," a connector engine that supposedly integrates with any system in days rather than quarters. The site displays logos from Okta, Microsoft Entra, GitHub, GitLab, Oracle. These appear illustrative rather than formal partnerships, though the company hasn't clarified.
The second piece targets a pain point familiar to anyone who's ever conducted a user access review. Oak doesn't just catalog who has access to what; it continuously compares granted permissions against actual usage. Permission granted but never used? Behavior deviating from baseline? The system can trigger automated remediation in real time, not in the next quarterly review cycle.
That's a meaningful shift, if it works as advertised.
Third is the agent governance layer—what Oak calls "Agentic Identity Governance." The platform can discover AI agents, map ownership, and enforce posture controls with the same rigor applied to human identities. Or so the company claims. Whether that's solving a genuine pain point today or preparing for a problem that's still a year or two out depends largely on how quickly enterprises deploy autonomous agents at scale.
The answer to that question remains fuzzy in mid-2026.
Serial Founder, Proven Track Record
Morag has credibility, at least on paper. He co-founded Secdo, an incident response platform that Palo Alto Networks acquired in 2018 for roughly $100 million. Then came Ermetic, a cloud infrastructure entitlement management company that Tenable bought in 2023 for $265 million.
After that acquisition, Morag became Tenable's chief product officer in August 2024. He left following Yoran's unexpected death in January 2025—a loss that sent ripples through the security community—and founded Oak barely eleven months later, according to Startup Nation Finder listings.
His co-founder, Tal Marom, held product leadership roles at Tenable and Salesforce. Together they assembled a 50-person team split between Tel Aviv and San Francisco before going public with the company. According to TechCrunch, plans call for shifting the majority of staff to the U.S. as the go-to-market operation scales.
The $60 million seed round—structured as approximately $60 million across two funding rounds according to an earlier Calcalist report while the company was in stealth—gives Oak considerable runway. With Accel, CRV, and Greylock as co-leads, plus participation from Hetz Ventures and AlphaDrive, the investor network alone provides credibility.
Still. Credibility isn't the same as proof.
The Gaps in the Story

For all the product detail on Oak's site and in July launch coverage, key questions remain unanswered.
The company says the platform is in general availability and deployed at unnamed Fortune 500 enterprises. But there are no customer names. No case studies. No quantified outcomes. No customer quotes beyond brief framing from investors.
Pricing details? Absent. Packaging options? Unclear. Compliance certifications? Oak's site shows "born certified" badges for GDPR and CCPA, but there's no mention of SOC 2 or ISO 27001—the kinds of attestations procurement teams typically require before signing contracts.
Oak offers something called "White Gloves" implementation—up to 500 hours of support for qualifying Fortune 500 organizations—which signals the company is targeting large, complex deployments rather than mid-market land-and-expand. But without reference customers or public proof points, CISOs evaluating Oak will need to take much of this on faith.
Or wait for validation to emerge.
According to the company's site, Oak planned to have a booth at Black Hat USA in August, which may provide the first chance for security practitioners to see live demos and ask pointed questions. Until then, Oak remains more vision than verified reality.
Consolidation or Wishful Thinking?
Oak enters an identity market that's simultaneously mature and maddeningly fragmented. Incumbents like SailPoint, Saviynt, and Microsoft Entra ID Governance have established positions. Newer entrants like ConductorOne and Iden have built modern architectures that chip away at legacy vendors. Adjacent categories—privileged access management, identity threat detection, cloud entitlements—each have their own vendor ecosystems and acronyms.
Morag's thesis is that this fragmentation is expensive, operationally complex, and about to get worse as AI agents become first-class identities. He sees an opportunity to rethink the entire stack.
Whether enterprises are ready to rip out multiple incumbent tools and consolidate on a new platform from a seed-stage company—even one with pedigree and $60 million in the bank—is the real question. Replacing identity infrastructure is the kind of high-risk, high-effort project that CISOs typically avoid unless the pain is unbearable or the competitive advantage undeniable.
Oak needs to prove it offers both.
For now, Oak is a well-capitalized bet on a specific future: one where AI agents outnumber humans, where real-time intelligence matters more than quarterly access reviews, and where identity governance needs to be rebuilt from scratch. That future may be arriving faster than most CISOs realize. Or it may take longer than venture capitalists hope.
The coming quarters will clarify which scenario is closer to the truth—assuming Oak can produce the customer references and proof points that are conspicuously missing from the July launch. Until then, Morag's latest venture remains equal parts promise and question mark.
