Obsidian Expands into Agent Governance
Obsidian Security
This expansion turns Obsidian from a settings checker into an in line control point for how work actually gets done inside SaaS. The original SSPM market was about finding risky app configs and excess access after the fact. The larger category is about watching agents and users as they call tools, touch data, and trigger workflows across Salesforce, Workday, Slack, and other apps, then blocking dangerous actions before they complete.
-
The product shift is concrete. Obsidian now positions itself around discovering agents, mapping each one to its real permissions, connected MCP servers, and downstream apps, then enforcing runtime guardrails on actions, not just auditing posture. That moves it closer to an execution layer than a reporting layer.
-
This also expands budget scope. SSPM is a relatively narrow SaaS security line item, while agent governance touches identity, data access, compliance, and AI program rollout. That matters because more than 75% of enterprise apps are now third party apps, which is where agents create value and where security teams need control.
-
The competitive set gets bigger and tougher. CrowdStrike has brought SSPM into Falcon through Adaptive Shield and added AI security through Pangea. Palo Alto Networks is extending SaaS security into AI access and runtime controls. Obsidian is betting that deep app level context inside third party software can still be a distinct advantage.
The next step is for SaaS security vendors to become policy engines for the invisible workforce of agents and service accounts. If Obsidian keeps moving earlier into agent discovery and deeper into live enforcement, it can grow with enterprise AI adoption and sell into a much larger control plane than SSPM ever allowed.