Cymphony Wants to Secure the New AI Workforce

Companies are hiring a new type of worker that doesn't have an employee ID, doesn't sleep and can potentially access thousands of files in seconds.
That worker is the AI agent.
Cybersecurity startup Cymphony has launched publicly with $30 million in total funding to help enterprises understand exactly what those agents can access.
The financing includes a $25 million Series A co-led by Sequoia Capital and SMBC Fin Atlas Beyond Fund, following an earlier seed round. The startup's post-investment valuation is reported at more than $100 million.
The funding is notable.
The problem Cymphony is targeting may be more important.
Enterprise security was built around people
Traditional corporate identity systems make a relatively simple assumption.
A person has an account.
That person belongs to a department.
The account receives permissions.
Security software monitors what it does.
AI agents break that model.
An agent might work across multiple applications.
It can operate continuously.
It may inherit a human user's permissions.
It may dynamically call other tools.
And it can process information much faster than any employee.
Sequoia describes controlling what agents can access as a major constraint on enterprise AI adoption.
The challenge isn't simply identifying whether an AI agent exists.
It's understanding what that agent can reach.
Cymphony is building a map of the workforce
The startup's core product uses what it calls a workforce graph.
Instead of treating identities, data and activity as separate security problems, Cymphony attempts to map them together.
Employees.
Agents.
Machine identities.
Applications.
Sensitive files.
Permissions.
Activity.
Security teams can then see the relationships between them and identify situations where access has become too broad.
Cymphony says its platform is designed to provide a unified view of how both people and autonomous software interact with enterprise data.
That approach reflects an important shift.
AI security isn't only about securing the model.
It's about securing what the model is allowed to touch.
Permissions could become AI’s biggest vulnerability
Companies accumulate permission problems over time.
An employee moves teams but keeps access to old folders.
A contractor receives access for one project.
Shared drives slowly become visible to more people than originally intended.
Humans may never notice those permissions.
An AI agent can discover them very quickly.
That creates a new type of risk.
An agent doesn't necessarily need to break into a system.
It may simply use access that already exists.
TechCrunch reported that Cymphony found roughly 85,000 files exposed to AI tools and agents at one U.S. public company, according to the startup. Cymphony said it helped close the exposure before those files were accessed through the AI systems.
That example illustrates why old permission mistakes become more dangerous in an agentic environment.
AI security is becoming crowded fast
Cymphony isn't alone.
Large cybersecurity vendors and startups are all moving toward agent security, nonhuman identity management and AI governance.
Microsoft.
Okta.
CyberArk.
Wiz.
Varonis.
And a growing list of specialized startups.
That creates a difficult question for companies such as Cymphony.
Is AI-agent security a standalone market?
Or will it eventually become another feature inside existing security platforms?
Sequoia is betting on the former.
Its argument is that AI fundamentally changes enterprise access enough to require a new security layer.
Security may determine how quickly agents get deployed
There is an important commercial consequence here.
Companies are interested in AI agents because they promise automation.
But enterprises are unlikely to give autonomous software broad access to financial systems, customer databases and confidential files without understanding the risk.
That means security isn't simply protecting the agent revolution.
It may determine how quickly the revolution happens.
Better security can unlock more access.
More access makes agents more useful.
More useful agents encourage companies to deploy more of them.
What happens next?
Enterprise AI is moving from employees using chatbots to organizations deploying autonomous software workers.
Cybersecurity architecture will have to move with it.
The question for security teams is changing from:
Which employee can access this file?
to:
Which humans, machines and AI agents can access it — and what can they do once they get there?
Cymphony's $30 million bet is that this question will become important enough to create an entirely new category of enterprise security.
Given how quickly agents are gaining access to corporate systems, that doesn't look like a difficult problem to find.
