Last Updated: 4 June 2026

Opal Security, a San Francisco company that helps enterprises manage and control access across every type of identity, has raised $23 million in new funding. The round comes alongside five senior leadership hires, including a new Chief Product Officer. Opal's platform covers human employees, software service accounts, and autonomous AI agents, giving security teams a single view of who and what can access sensitive systems.
The funding arrives as companies are deploying AI agents faster than their security teams can track them. These agents are software programs that act independently, making decisions and accessing data without a human directing each step. In most organizations, they inherit the same access permissions as the employees they were built to assist. That creates a real problem. A January 2026 study by ManageEngine found that machine identities outnumber human users at a ratio of at least 100:1 in most organizations, with some sectors reaching 500:1, and only 12% of organizations have automated systems in place to manage that at scale. Many of these machine accounts run with more access than they need, and most go completely unmonitored.
The $23 million round was led by Greylock and Battery Ventures, with outside participation from Cambium Capital. Opal's total funding now stands at $59 million.
Identity and access management has always been built around people. Someone joins a company, receives a set of permissions, and those permissions get reviewed or adjusted over time. It is an imperfect system, but it broadly functions when the users are human. When the users are software, it largely does not.
Static service accounts have been a governance headache for years. AI agents make it worse. They can trigger workflows, pull data, and interact with external services at a speed no access review committee can match. McKinsey research published in March 2026 found that companies expect the share of fully deployed agentic AI solutions to more than double over the next 12 months, which means the problem is getting bigger, not smaller.
Opal's position is that the right answer is not a separate tool for AI agents. Instead, it argues that agents should sit inside the same access framework already used for employees and service accounts. The same review processes, the same policy rules, the same ownership structure. Treating AI agents as a distinct security category, Opal's argument goes, is what creates gaps in the first place.
"I've spent my career in identity and security, and it's rare to see a platform this aligned with where the market is heading in the era of AI. Access used to be a one-time decision. Today it's a continuous, high-volume problem across humans, services, and AI agents at machine speed. The real problem is control. Where most solutions stop at visibility or governance, what excites me about Opal is that they're defining the control plane for identity, enforcing access decisions in real time across every system."
Sameer Mehta, Chief Product Officer, Opal Security
Most of the new capital is going toward hiring. Opal has grown quickly: more than 60% of its current staff joined in 2026 alone, with headcount expanding across engineering, product, and go-to-market roles. The five executives announced alongside the round fill out a leadership team that arrived largely blank when CEO Howard Ting took over in December 2025.
The new hires are Sameer Mehta as Chief Product Officer, Alex Pien as Chief Technology Officer, John Clark as Vice President of Field Engineering, Michael Kwon as Vice President of Marketing, and Christine Ooley as Head of Product and Solutions Marketing. Pien was promoted from within after coming from Meta. The others arrived from outside: Mehta from identity security company Veza, Clark from Cisco where he led AI security engineering, Kwon from Clumio and Redis, and Ooley from Salesforce where she worked on MuleSoft's API and agentic product marketing.
In March, Opal also launched what it calls an industry first: a unified platform that can detect, encode, and enforce access rules for every identity type in a single system.
The platform includes an AI engine called Paladin, which reviews incoming access requests and only sends the ones that genuinely require human judgment up the chain.
Opal was built around a conviction that most access management tools were designed for a simpler time, when most corporate systems were accessed by people with managers and email addresses. Today's environments include thousands of automated processes, cloud services, and increasingly, AI agents that act on their own.
The core of Opal's model is just-in-time access. Rather than assigning permanent permissions, the platform grants access for a specific task and revokes it automatically when the task is done. Security teams can also write policy rules in code, so access decisions are enforced consistently rather than depending on manual reviews that slow teams down and often rubber-stamp requests without real scrutiny.
Databricks runs 86,000 just-in-time access requests through Opal. Mercari uses it to manage automated reviews of more than 5,000 Okta entitlements. Other clients include Notion, Cloudflare, Scale AI, CoreWeave, and Superhuman.
Ting, who has previously held roles at Cyberhaven, Nutanix, Palo Alto Networks, and Redis, arrived as CEO in December 2025 and quickly promoted Alex Pien to CTO to anchor the engineering side of the business as it scales.
"Great operators don't chase markets—they pick the biggest problem and the best team to solve it with. Sameer, John, Michael, and Christine have each built category-defining products, and they came to Opal for the same reason: governing access across every identity—human, service, and AI agent—is becoming one of the defining problems in security. The new funding gives us the resources to go solve it."
Howard Ting, CEO, Opal Security
Opal's $59 million in total funding has come from Greylock Partners, Battery Ventures, Box Group, SVCI, and Cambium Capital. Greylock and Battery Ventures led the current round, with Cambium Capital participating alongside them.
The company was recently added to Notable Capital's Rising in Cyber 2026 list, which names the 30 most promising private cybersecurity companies as chosen by 150 CISOs. The list reflects where experienced security leaders think attention and investment need to go as AI agents become a standard part of enterprise infrastructure.