Live desk — HR tech, hiring and alumni platforms
Talent Market Pulse

AI Agents Are a Security Problem for HR — And Companies Are Finally Building Tools to Fix It

AI Agents Are a Security Problem for HR

By Staff Writer | Published: September 29, 2026

A new security startup backed by Sequoia Capital is betting that the biggest gap in enterprise AI isn't model performance — it's identity governance. Cymphony's $30 million Series A, announced September 9, signals a growing conviction among the world's most selective venture firm: as companies deploy thousands of AI agents across their operations, the systems tracking who (and what) can access sensitive data are not keeping up.

The nonhuman identity gap

Cymphony gives security teams a single view of employees, AI agents, and other nonhuman identities — including the systems and sensitive data they can access. At the core of its platform is what the company calls a "workforce graph," bringing together identity, data, and activity signals into one searchable structure.

The problem is real and measurable. Cymphony says it found approximately 85,000 files accessible to AI tools and agents at one U.S. public company. Another case involved an external collaborator installing an unsanctioned instance of Anthropic's Claude, which used existing access to scan thousands of sensitive files — all without triggering traditional security alerts.

Why HR-tech buyers should care

HR departments store some of the most sensitive employee data available: compensation, performance reviews, benefits enrollments, health information, and internal communications. As more HR-tech platforms — from Workday's Sana agents to specialized recruiting and performance tools — deploy autonomous AI agents that access or make decisions about this data, the identity and access management problem becomes a compliance and governance problem.

"Enterprise security was designed for human employees," Cymphony co-founder and CEO Shy Dekel told TechCrunch. "More and more, there start to be independent entities that are practically joining the workforce, but they're no longer people."

The Sequoia bet

Sequoia's decision to lead Cymphony's Series A at over $100 million valuation was a follow-through on a seed investment made more than two years ago, when the startup had no product and its co-founders — all graduates of Israel's elite Talpiot military technology program — were still figuring out their direction. The initial investment was, as Sequoia partner Bogomil Balkansky put it, a bet on the founders' pedigree.

By the Series A, Cymphony had double-digit enterprise customers including KKR and Syngenta, and had reached seven figures in annual recurring revenue within its first year of sales. Sequoia was already using the product internally.

"We just saw three amazing young people with the kind of pedigree that we at Sequoia have experienced a lot of success with," Balkansky said. But by the Series A, the bet was no longer just on the founders — it was on a validated problem.

The competitive landscape

Cymphony enters a crowded market. Microsoft, Okta, CyberArk, Wiz, and Varonis are all expanding their offerings around identity and AI security. Cymphony co-founder Dekel told TechCrunch the company is already consolidating security products at customers — at one enterprise, it replaced two tools and eliminated the need for a third.

Balkansky is pragmatic about the near term: "Nobody's going to get rid of their Okta," he said. Cymphony is largely being adopted as an additional layer today. Over time, the company could begin displacing point solutions, particularly in areas like data loss prevention.

What HR-tech buyers should do

The Cymphony story is a reminder that as HR-tech platforms add AI agent capabilities, the governance question extends beyond accuracy and bias into identity and data access. When an HR agent starts making decisions about compensation, promotions, or benefits, the organization needs to know: who gave that agent access to what data, can the agent exceed those boundaries, and is there a system that can detect and remediate unauthorized access?

Workday's Agent Passport, entering early access in 2026 R2, directly addresses this by providing signed attestations, continuous runtime monitoring, and revocation authority. But not every HR-tech platform has a governance tool at that level. Organizations evaluating multiple platforms in Q4 should ask: which platforms have the most comprehensive visibility into agent access, and which can demonstrate it?

As Sequoia's Balkansky put it: "If companies are not spending money on agent security, I don't know what else they'll be spending money on in the next five to 10 years." For HR-tech buyers, that line of defense starts with knowing who has access to what — whether it's a human or an agent.

More from the desk