CEO Hasan Imam Says AI Agents Are Already Modifying and Deleting Enterprise Data

Michael Novinson (MichaelNovinson) •
August 10, 2026    

Obsidian Secures $85M to Control AI Agents in SaaS Apps
Hasan Imam, CEO, Obsidian Security (Image: Obsidian Security)

A security vendor led by an ex-Shape Security executive raised $85 million on a $1.1 billion valuation to protect data in SaaS and other third-party applications from autonomous artificial intelligence agents.

See Also: Why Healthcare Leaders Are Rethinking Their Data Strategy Before Scaling AI

The Crescent Cove Advisors-led Series D financing will help Silicon Valley-based Obsidian Security securely give AI agents direct access to applications such as Google Drive, Notion, Slack, Salesforce, Snowflake, Databricks, GitHub and GitLab, said CEO Hasan Imam. Agentic security needs to address not simply whether an agent has access but exactly what it does after gaining that access.

“More than 65% of the enterprises we are protecting have given agents access to data inside third-party applications,” Imam told ISMG. “So, we are now seeing agents operating inside third-party applications, modifying data, deleting data and we have built capability to be able to allow these enterprises to be able to monitor that and prevent bad things from happening.”

Obsidian, founded in 2017, employs 262 people and has raised $205 million, having previously closed a $90 million Series C round in April 2022 led by Menlo Ventures, Norwest Venture Partners and IVP. The company has been led since January 2021 by Imam, who was serving as Shape Security’s chief revenue and customer officer when the company was bought by F5 in January 2020 for $1.01 billion (see: Obsidian Security Raises $90M to Safeguard More SaaS Apps).

Why Agents Must Be Able to Modify Data

An agent that can only retrieve information but cannot modify data or complete an action has limited value, but Imam said allowing agents to act inside apps means they can modify or delete sensitive information, creating a different risk profile from traditional human access. Organizations need to provide this access if they expect agents to complete meaningful work and enable productivity gains.

“To unlock the potential of the agentic investment, you need to give it access,” Imam said. “Now, what are the security implications? If you think about what has happened with OpenAI-Hugging Face, one was a testing environment that was misconfigured, and the second thing was there was weak passwords that allowed these agents to get into these organizations.”

Obsidian already monitors agent activity associated with platforms including Claude Code, ChatGPT, Copilot and Salesforce Agentforce, and it plans to extend to Snowflake Cortex and Databricks Agent Bricks. Obsidian wants to see what agents do when they enter third-party apps and perform real-time enforcement when an action creates unacceptable risk to control actions performed by autonomous systems.

“If you think about the third-party applications, we cover 300 of the most significant third-party applications around the world, but we are also building out infrastructure and capability to be able to go from 300 to 3,000, or even 10,000, to be able to cover all third-party applications that contain sensitive data and need to be protected as agents are given access to these applications,” Imam said.

Obsidian finds that 75% of applications have an administrator without multifactor authentication and that enterprises have applications that permit local account access rather than requiring users to authenticate via centralized identity access management, Imam said. And information that may be difficult for a human attacker to locate across numerous apps could potentially be discovered much more efficiently by an AI model.

“If the admin doesn’t have MFA, you now have Mythos-like models breaking the admin’s authentication,” Imam said. “They can do that.”

Why Enterprises Must Know What Agents Are Doing Inside Apps

Defensive systems need to identify malicious or dangerous behavior and intervene in near real time rather than generate an alert that requires a human analyst to investigate and respond, Imam said. Obsidian is applying agentic and autonomous capabilities to this problem so its technology can react to attacks as they occur. Imam said he expects the broader security industry to move in the same direction.

“You need agentic capabilities to defend against agentic capabilities,” Imam said. “One of the things that we believe in is that we have to move into a world of prevention and real-time enforcement, and a lot of our capabilities in the product right now are agentic, are autonomous to be able to react to an attack near real time and act on it and prevent it.”

Depending on the application, an agent could add or modify information, delete a row or table, remove a repository or even delete an entire instance, and Imam’s preferred approach is granular visibility and control rather than blanket restrictions. Security systems should understand the precise action an agent is attempting and stop actions that are catastrophic, violate policy or breach compliance requirements.

“What we need is capabilities that would allow enterprises to see what the agents are doing at a very granular level, not at a macro level, and we need others to be able to provide that level of visibility,” Imam said. “And if we can provide that level of visibility, we can also provide the real-time controls to be able to prevent actions that are potentially catastrophic.”

Enterprises can’t control AI agents unless they first understand what those agents are doing inside third-party applications. Organizations need insight into actions taking place inside applications containing valuable corporate data, not merely visibility into network activity. Once they have that, organizations can create controls determining which agent actions are acceptable and which should be prevented.

“The first step is having that visibility, and if you have that visibility, then you can actually enable agents in a way such that you have a chance of having a level of control in terms of what the agents can do inside,” Imam said. “With either Obsidian or some other technology, they need to get visibility in terms of what’s happening inside these third-party apps where some of their most valuable data resides.”