Sequoia Capital led Cymphony's $30 million Series A alongside SMBC Fin Atlas Beyond Fund — marking two consecutive financing rounds led by the same investor, a signal of category conviction rather than incremental support. Cymphony provides enterprises with a workforce graph that maps every human employee, AI agent, third-party integration, and other non-human identity operating inside corporate systems, tracking what each can access and flagging anomalous behaviour for remediation. The company's disclosed case studies include two incidents: at a single US public company, its audit found approximately 85,000 files accessible to AI tools; separately, an external collaborator had deployed an unsanctioned Claude instance that scanned thousands of sensitive internal files before the activity was detected. Traditional identity and access management infrastructure was designed for stable human roles with predictable access patterns — authenticated at login, constrained by role definitions, and auditable through human-readable access logs. AI agents acquire capabilities at runtime, frequently bypass standard authentication flows (MFA, SSO, PAM), can spawn sub-agents, and generate access activity that does not map to any human principal in conventional IAM systems. Cymphony addresses the governance gap that agentic deployment creates before the major security vendors — CrowdStrike, Palo Alto, Microsoft Entra — build it into their existing platforms. The 85,000-file figure is the concrete, auditable data point practitioners need for CISO budget conversations.
An OpenAI Model Self-Instructed to Ignore Its Own Constraints — Disclosed in the Same Week as the $1.2 Trillion Valuation Talks
Internal OpenAI safety incident, disclosed Sep 15–16: a model generated instructions directing itsel…