Obsidian Security announced an $85 million Series D on August 4, 2026, led by Crescent Cove Advisors, at a $1.1 billion valuation. Existing investors Greylock Partners and Menlo Ventures also participated.
Reuters reported that roughly 70% of Obsidian customers already allow AI agents to interact with business data. Obsidian separately says it serves 60 Fortune 500 companies, has more than 100 customers spending over $100,000 annually, and more than 14 spending over $1 million. Those customer figures are company-reported.
For B2B operations teams, the funding headline is not the procurement case. The useful signal is that security spending is moving closer to the point where agents read, write, approve, and delete inside CRM, data, collaboration, and developer systems. Buyers now need evidence that a security layer can see every execution path and stop unsafe actions before impact.
Direct answer — What does Obsidian Security’s $85 million round mean for enterprise AI buyers?
The round signals growing demand for a dedicated control layer around AI agents that act inside third-party applications. Obsidian says its platform combines agent, MCP-server, and model inventory with access governance and runtime blocking. Buyers should treat those as claims to test across real workflows, not as proof supplied by the $1.1 billion valuation.
Key Takeaways
- Obsidian Security raised $85 million in Series D financing at a $1.1 billion valuation.
- Crescent Cove Advisors led the round; Greylock Partners and Menlo Ventures also participated.
- Obsidian says roughly 70% of its customers already let agents into third-party applications.
- The company announced Claude access governance, runtime protection, MCP-server inventory, and LLM inventory.
- Funding validates investor demand, not product coverage; buyers still need path, enforcement, and recovery evidence.
What Obsidian Security Actually Announced
Obsidian positioned the financing around securing non-human identities and AI agents across third-party applications. The company says the capital will support research and development and expansion among Fortune 500 and Global 2000 enterprises. Reuters reported that Obsidian expects the funding to last until it reaches positive cash flow.
The release pairs the round with four product claims. Obsidian says it can govern what Claude Code and Cowork agents access, block privilege escalation and policy violations during execution, inventory MCP servers and the agents invoking them, and track the large language models powering agents. Its wider platform coverage names Microsoft Copilot Studio, Salesforce Agentforce, n8n, Amazon Bedrock, Google Vertex, OpenAI, and Anthropic environments.
Why the Round Matters Beyond the Valuation
The category is forming around a practical change in enterprise software: agents no longer stop at generating text. They call tools and alter records across business systems. Cordial’s cross-system permission test shows the application-side problem clearly: an external agent can gain more useful context and a larger blast radius through the same set of connections.
Identity is part of the answer, but not the whole answer. Barndoor’s agent-level operating record focuses the buyer on ownership, credentials, permissions, activity, and spend. Obsidian’s announcement pushes the question further into execution: can the control layer discover an unapproved route, detect excessive authority, and prevent a destructive action while it is happening?
Our read: the round does not prove that Obsidian will win the category. It does show that agent security is becoming a budget and architecture decision rather than a late compliance review. Once agents can change customer, employee, financial, or source-code data, login controls and retrospective logs are not enough.
The Hidden Catch: Funding Does Not Prove Coverage
Obsidian’s product pages describe continuous discovery, effective-permission mapping, and execution-time guardrails. The buyer still has to verify where those controls operate. A dashboard can look complete while missing a direct API key, a shadow MCP server, a sub-agent, a fallback tool, or a model substitution that appeared after the original review.
The same distinction applies to authority. Pipefy’s authority-matrix approach separates read, draft, submit, and approve rights before an assistant executes a workflow. A security platform should be able to observe and enforce those boundaries without converting every low-risk action into a manual approval queue.
Buyers should ask what happens when the security service is unavailable, which actions can be blocked rather than merely alerted on, and how evidence is exported for incident review. Funding and an integration list do not answer those questions.
The AI Agent Security Buyer Test
- Prove inventory completeness. Map every agent, owner, model, credential, MCP server, direct API, connected tool, sub-agent, and fallback route. Add an unapproved path and confirm the platform discovers it.
- Measure effective authority. Compare configured permissions with what the agent can actually do. Separate read, draft, write, submit, and approve rights, then verify least privilege survives role changes and reused credentials.
- Test runtime enforcement. Attempt a high-risk but reversible action in a sandbox. Confirm the control blocks it before execution, records the reason, and routes a valid exception to the correct human approver.
- Reconstruct one incident. The evidence should identify the agent, human sponsor, model, prompt or instruction source, tool path, credential, accessed data, attempted action, policy decision, and final system state. The Workspace Agents audit-trail gap shows why a run log without cross-application attribution is incomplete.
- Run revocation and recovery. Disable the agent, rotate its credentials, remove an MCP connection, and confirm access ends everywhere without disabling the sponsoring employee. Then prove the team can reverse or contain the resulting business change.
Obsidian’s round shows investors expect enterprises to buy this control layer. Procurement should turn on whether the platform produces complete, execution-level evidence for the agents and applications the business actually uses.
Frequently Asked Questions
Obsidian Security announced $85 million in Series D financing on August 4, 2026. Crescent Cove Advisors led the round, with Greylock Partners and Menlo Ventures participating. The company and Reuters reported a $1.1 billion valuation, and Obsidian said the funding will support expansion.
Obsidian says the platform discovers agents and connected components, maps access, inventories MCP servers and models, and enforces runtime guardrails against excessive access or policy violations. These are vendor claims that buyers should verify in their own application and agent environment.
Agents can act across multiple systems after authentication, often using inherited credentials and broad tool access. That creates risks traditional login controls do not fully address. Teams need agent-level identity, effective-permission mapping, continuous path discovery, execution-time policy enforcement, and evidence that supports recovery.
Test inventory completeness, least privilege, runtime blocking, audit reconstruction, revocation, and rollback on a real workflow. Include direct APIs, MCP connections, sub-agents, model changes, and fallback routes. A platform should prove what it sees, what it can stop, and what happens when controls fail.






