Investment thesis · Live
The AI Agent Paradox: Rather Than Killing Software, Agents Multiply Machine Identities and Drive Security Spend
Every AI agent is a new non-human machine identity requiring authentication and governance, structurally benefiting identity security software vendors.
Published July 19, 2026 · 150-day horizon · technology
Basket return
+10.6%
equal weight, since publication
The market over the same window
+3.5%
benchmark for this basket
Edge over the market
+7.1%
in percentage points
Causal chain: Mass enterprise deployment of autonomous AI agents → Machine identity explosion: each agent requires dedicated entitlements → Expanding attack surface: OAuth tokens, API keys, service credentials → Cybersecurity budgets shift toward non-human identity security → Per-identity monetization: billable units multiply alongside agent counts → Okta, SailPoint, Palo Alto (CyberArk), Zscaler
What this thesis rests on
Each one is a statement that has to be true. When a filing says otherwise, the thesis is in trouble, and this is where we say so.
-
○
SailPoint reports annual recurring revenue growth of at least 20% year over year in each quarterly report filed within the 150 days after 19 July 2026.
financial · Unverified
-
○
Zscaler reports calculated billings growth of at least 20% year over year in the quarterly results covering the horizon.
financial · Unverified
-
○
Okta's disclosed dollar-based net retention rate stays at or above 105% in every quarterly report filed during the horizon.
competitive · Unverified
-
○
Palo Alto Networks closes the roughly $25bn CyberArk acquisition and consolidates CyberArk privileged access revenue in its reported results within the horizon.
operational · Unverified
-
○
Okta states in a filing during the horizon that its agent identity offering, including Cross App Access, is generally available and sold as a paid product.
operational · Unverified
For two years, enterprise software has been valued under a single reductive narrative: autonomous AI agents will displace knowledge workers, eroding per-seat subscription models across SaaS. This fear compressed valuation multiples across the entire sector, including subsegments where the underlying economic logic operates in reverse. Identity security software is not billed per human head count; it is monetized per identity, per workload, and per network flow. AI agents do not reduce addressable identity units—they multiply them exponentially. Every deployed agent represents a new service account, new API keys, non-human OAuth tokens, and elevated permissions that enterprise IT must provision, restrict, rotate, and audit.
The scale of non-human exposure was severe even prior to agentic workflows: CyberArk research indicated that enterprises average over 80 machine identities per human employee, with the vast majority holding access to sensitive data stores without programmatic governance. The 2025 Salesloft Drift breach demonstrated the systemic consequence: compromised OAuth tokens from a single integration provided unauthorized access to data across ~700 organizations, including leading cybersecurity firms themselves. The vulnerability was not human phishing, but unmanaged machine credentials—precisely the attack surface that AI agents are expanding at scale.
Open the interactive thesis
Interactive causal map, the basket charted against its market, and the full timeline.
Open in Invesaro →
This is analysis, not investment advice and not a recommendation to buy or sell anything. We publish it and track it in public, mistakes included. Any decision is yours and yours alone.