Saviynt launches Zuma as AI identity security platform
Tue, 28th Jul 2026 (Yesterday)
Saviynt has launched Zuma, an AI identity security platform for enterprises, and has surpassed USD $300 million in annual recurring revenue.
The platform is designed to help organisations identify, govern and protect AI agents, large language models, AI-based applications and non-human identities as their use expands across businesses. It combines discovery, runtime access controls and governance tools in one system.
The launch comes as Saviynt reported bookings growth of more than 80% and a customer retention rate of 96%, which it said reflect rising demand for identity security products as companies grapple with the operational and security implications of broader AI deployment.
At the centre of Zuma is a focus on non-human identities, including software agents and automated systems that can request access to data and applications without direct human action. Many organisations, Saviynt argues, lack clear oversight of who created these identities, what systems they can access and who is accountable for their actions.
The platform has three parts. Zuma Insights is intended to discover AI agents, large language models, AI applications and non-human identities across an organisation, and show ownership, access patterns and lifecycle changes.
Zuma Access is designed to control what an AI agent can do at the point of action. It evaluates an agent's intent, context, permissions and risk at runtime so that only approved actions are allowed for a given task.
The third element, Zuma Governance, is designed to set ownership rules, lifecycle controls, policy guardrails, access reviews and audit records for AI agents and non-human identities. Saviynt says this is meant to address unmanaged or orphaned agents that fall outside traditional identity processes.
Saviynt developed the product after working with large organisations trying to expand AI use across multiple business functions while retaining visibility and control. It contends that existing identity and security tools do not answer basic operational questions about AI systems, including where they are deployed, what they are doing and which data or applications they can access.
"AI is fundamentally changing the identity security equation," said Sachin Nayyar, Chief Executive Officer, Saviynt. "Enterprises are no longer securing only human users. They are now responsible for AI agents and non-human identities that can decide and access systems at machine speed. Saviynt's momentum reflects the urgency we are seeing from customers around the world, and Zuma represents a major step forward in helping them embrace AI with confidence and control."
Customer demand
Companies adopting AI are increasingly questioning whether older identity management processes can cope with autonomous software entities. That has sharpened attention on access control, accountability and auditability as AI systems are given greater latitude to act inside corporate environments.
One customer described the issue as a practical gap between older processes and newer forms of digital identity. Cytiva, part of Danaher, is examining how to expand AI use while maintaining oversight of the systems involved.
"Like many large enterprises, we are looking at how to safely scale AI across the business without losing visibility or control," said Sarita Dsouza, IAM leader, Cytiva, a Danaher company. "The challenge is that AI agents and non-human identities don't fit neatly into legacy identity processes. Saviynt is bringing the right pieces together - discovery, ownership, runtime controls, and governance, in a way that maps to how security teams actually need to manage this risk."
The issue is also drawing attention from technology leaders and investors as AI deployment widens. Identity controls are increasingly being treated as a key layer in managing how autonomous systems interact with internal networks, applications and sensitive information.
"As AI adoption and automation accelerate, enterprise security teams are under increasing pressure to secure both human and non-human identities while enabling the business to adopt AI responsibly," said Ruchir Swarup, Chief Information Officer at KKR. "Identity has emerged as a vital control point that will define security in the AI era. The organisations that move fastest will be those that give cyber leaders the visibility, governance, and control needed to manage AI-driven risk while supporting innovation and growth."
Real-time controls
A central part of Saviynt's argument is that security teams need controls that act during an AI agent's activity rather than after an event has been logged. Zuma is intended to make access decisions in real time, based on the task being attempted and the level of risk involved.
Nayyar said customers want direct oversight rather than retrospective reporting tools. "Customers are telling us they need more than another dashboard," he said. "They need a control plane that can help them see every AI and non-human identity, govern it with accountability, and protect the business in real time. That is the problem Zuma was built to solve."