A data security company buying a non-human identity company is a wager that "who is accessing this" and "how sensitive is it" stop being separate questions.

Cyera has signed a letter of intent to acquire Oasis Security for approximately $1 billion, making a substantial move into the identity space.
Cyera is primarily a data security company. Oasis specialises in non-human identities and agent access. The plan is to combine Oasis' identity and access capabilities with Cyera's ability to understand the context and sensitivity of the data being reached, producing a combined identity and data security platform aimed at AI agents.
Note the deal stage
One piece of housekeeping before the analysis. This is a letter of intent, not a definitive agreement. Letters of intent are usually non-binding and deals at this stage do occasionally change shape or fall over. Treat the billion-dollar figure as the current intention rather than a settled number.
The thesis is more interesting than the price
The reason to pay attention is what the deal implies about where the control problem sits.
Identity teams have historically answered one question: should this principal be allowed to access this system. Data security teams answered a different one: how sensitive is what lives in that system. The two disciplines bought different tools, reported to different people and met mainly during incidents.
An agent with read access to a share is a routine grant. An agent with read access to the share holding customer records is an incident waiting for a trigger. Same permission, different problem, and identity tooling alone cannot tell the two apart.
That distinction was tolerable when the principals were humans doing recognisable jobs. It is much less tolerable when the principal is an agent that can be pointed at anything, acts quickly, and does not pause to wonder whether it should be reading a particular file.
Cyera's bet is that the useful unit of control for agents is the combination: which identity, reaching what data, of what sensitivity. That is a coherent thesis, and it is the same conclusion the Okta and Permiso deal reaches from the opposite side of the market.
What this means for identity teams
Data classification becomes an identity dependency. If your access decisions are going to be informed by data sensitivity, someone has to actually maintain the classification. In most organisations that programme is either stalled or owned by a team you rarely speak to.
Expect the NHI category to keep consolidating. Oasis is a specialist being absorbed into a platform. If you are running a point solution for non-human identity, plan for the possibility that it becomes a module inside something larger.
The pitch you will hear next. Combined identity and data platforms will be sold as the answer to agent governance. They address a real gap. They do not remove the need to know which agents exist and who owns them, which remains the unglamorous prerequisite.
Two billion-dollar-scale moves into non-human and agent identity inside a fortnight, from a pure identity vendor and a pure data vendor respectively, is a reasonable signal about where the next few years of tooling are heading.