Way Security, which uses AI-driven automation and agentic workflows to help organizations deploy identity and access management systems, has raised a $20 million seed round from Insight Partners and Glilot Capital. The round size places it well above the typical seed for the category, and the investor pairing — a large growth firm alongside an Israeli early-stage specialist with a strong security track record — is the familiar structure for Israeli cybersecurity companies that intend to scale into the American enterprise market quickly.
Identity and access management is a mature category with established vendors and well-understood value. The persistent failure is implementation. IAM projects are notorious for running long, exceeding budget, and stalling partway through, leaving organizations with partial deployments that create their own risk surface.
The reason is that identity work requires mapping every application, every role, every entitlement, and every exception across an estate that nobody fully documents, then reconciling that map against how people actually work. That is labor-intensive discovery, and it does not scale with headcount because the bottleneck is understanding rather than execution.
Applying agentic automation to that discovery and configuration work is a credible thesis. It targets services labor rather than replacing a product, which means the buyer is an organization already committed to a platform and struggling to finish the rollout.
The round lands as the National Vulnerabilities Database records more than 45,000 software flaws so far in 2026, on pace to roughly double last year, and as Microsoft markets a security-specific model alongside an agentic system for identifying and patching vulnerabilities.
Identity is the control that determines blast radius when any of those flaws is exploited. An organization with tight entitlement scoping contains an intrusion that an organization with accumulated permission sprawl does not. As the finding rate accelerates, the value of getting identity deployed correctly rises with it, which is the macro case behind a seed round of this size.
Glilot’s participation follows a consistent pattern in the Israeli security sector: technical founders with signals-intelligence or defensive backgrounds, early local capital with deep category knowledge, and rapid pairing with American growth investors who supply the go-to-market path.
The category concentration is not accidental. Identity, cloud security, and detection engineering are the areas where Israeli firms have repeatedly reached scale, and the operator network from prior exits functions as both talent pipeline and customer introduction for each new cohort.
The technical claim is that agentic workflows can perform discovery and configuration work reliably enough to reduce a deployment from quarters to weeks. The commercial question is whether enterprise buyers accept automated configuration of the control that governs access to everything else.
Identity is the highest-consequence system to automate. A misconfiguration grants access rather than merely failing, and it fails silently. Adoption will depend less on how fast the automation runs than on what audit trail and rollback capability it provides — which is the part of the pitch that will be scrutinized in every procurement conversation the company enters.
Leave a Reply