ooligo

Zenity

ai-agent-governance agent-governance · ai-security-posture-management · runtime-enforcement · mcp-security
AI-NATIVE API
RevOpsLegal OpsRecruiting & TACustomer Success
7.5 /10

What it is

Zenity finds the AI agents already running in your company, scores what each one can reach, and then stands in front of every action an agent takes and decides whether to allow it, change it, or kill the run. Founded in 2021 by CEO Ben Kliger and CTO Michael Bargury, with R&D in Tel Aviv and go-to-market in New York, it came into the category from the low-code side — Power Platform and Copilot Studio, where the person shipping the agent is a RevOps analyst rather than an engineer. That origin is the reason it belongs in an ops catalog at all.

The platform is three layers. Surface covers AI Observability, AI Security Posture Management and AI Exposure Management — the inventory and the ranked list of attack paths. Enforce covers Runtime Boundaries and Agentic Identity & Access Management. Protect covers AI Detection & Response, MCP Security and Guardian Agents. Exposure Management and Runtime Boundaries both shipped on 27 July 2026; Runtime Boundaries reads intent, identity, the requested action, the data touched, the tools called, prior activity in the same run and your policy, then permits, blocks or terminates the agent before the action executes.

Coverage spans Copilot Studio, Salesforce Agentforce, ChatGPT Enterprise, Claude Code, Cursor, Amazon Bedrock, Azure AI Foundry, Google Vertex AI and agents your team built itself. Zenity raised a $125M Series C led by Norwest on 3 August 2026 — Qumra Capital, SoftBank Vision Fund 2, Hitachi Ventures and LG Technology Ventures joined alongside Vertex Ventures, Third Point Ventures, DTCP and Intel Capital — taking total funding to about $180M against more than 230 employees, with revenue tripled in each of the two prior years.

Why ops teams end up here

The trigger is an agent nobody chartered. A CSM builds a Copilot Studio agent that reads the ticket queue and drafts replies. A recruiter wires one that summarizes candidate notes. Each authenticates as its builder, inherits that person’s access, and appears on no list. The question that lands on the ops leader is not “is this secure” but “who approved the one that can email customers,” and the honest answer is usually nobody.

Zenity’s argument for why a generic security tool cannot answer that: the agent’s permissions are legitimate. It is doing exactly what its builder’s account is allowed to do. What changed is that a paragraph of text buried in an inbound email, a resume, or a support ticket can now steer those permissions. Zenity Labs demonstrated the shape of this at Black Hat USA 2025 with AgentFlayer, a set of zero-click exploit chains presented by Bargury and researcher Tamir Ishay Sharbat against ChatGPT, Copilot Studio, Cursor with the Jira MCP server, Salesforce Einstein and Gemini. OpenAI and Microsoft patched. Several vendors declined, on the grounds that the behavior was intended.

In Copilot Studio specifically, Zenity’s controls run inside each agent at the step where a tool is invoked — a connector write, an MCP call, an outbound email — rather than watching from outside. That step-level position is what lets a policy read “block a connector write that carries more than N PII fields out of the tenant” instead of “alert someone afterward.”

Pricing reality

Zenity publishes nothing on its own site; zenity.io routes to a demo booking. The only listed rates are on AWS Marketplace, which sells it as three independent usage dimensions on one invoice, with a 30-day trial and no end date on the subscription:

  • Zenity Observability — $130.00 per resource per month, where a resource is a discovered agent or related item.
  • Zenity Runtime Protection — $16.00 per million tokens per month.
  • Zenity Guardrails for AWS — $2.00 per million tokens per month.

Run the arithmetic before the demo. Twenty governed agents on Observability alone is $2,600/month, $31,200/year. Fifty is $78,000/year. Two hundred is $312,000/year. Add runtime: an agent processing 16 million tokens a month across prompts, retrievals, tool calls and responses adds $256/month per that dimension’s rate. Direct enterprise contracts are negotiated privately through partners@zenity.io, so treat the Marketplace numbers as the ceiling you argue down from, not the price you will pay.

The unit is the thing to fight about. Zenity bills against agent-side resources; Microsoft Agent 365 bills $15 per human user per month. Those curves cross. At 400 employees and 15 agents, Agent 365 costs $72,000/year and Zenity’s Marketplace list runs $23,400. At 400 employees and 150 agents, Agent 365 is unchanged and Zenity’s list is $234,000. Agent count is the variable that decides which invoice hurts.

Best for

The security-minded ops or IT leader in an enterprise where non-engineers are already shipping agents on Copilot Studio or Agentforce, across more than one department, and a regulator, auditor or customer is about to ask for the list. The scoped case where Zenity wins outright: a Fortune-500-scale org with agents in Copilot Studio and Agentforce and a few homegrown ones on Bedrock, that needs one runtime policy applied across all three rather than three native consoles that each govern only their own.

Not for

A team under about 200 people running three to five agents. At that size the inventory fits in a spreadsheet, and the control you actually need — a named owner per agent, a human approval gate on writes, an execution log — comes from the AI agent ops stack and a CRM agent access audit for a fraction of a $31,200 floor. It is also the wrong purchase if your problem is authorizing agent tool calls per user rather than policing them: that is what Arcade and Composio do, and Zenity does not replace the auth layer. And it will not govern a developer’s personal API key against a model endpoint that never touches a managed platform.

Versus the alternatives

  • Microsoft Agent 365 — the default in a Microsoft-first tenant, generally available 1 May 2026, $15/user/month on top of an E5 or Business Premium prerequisite. Pick it when the agents that matter live inside Copilot Studio, Foundry and Teams, and Entra, Purview and Conditional Access are already the enforcement points. Its ceiling is the tenant boundary; agents on Bedrock or Vertex are outside it.
  • Noma Security — the closest independent, at $132M raised including a $100M Series B led by Evolution Equity Partners, with AI-SPM, access control, adversarial testing and runtime detection, plus native hooks into Copilot Studio, Agentforce, ServiceNow and AWS Security Hub. Noma arrived from the ML pipeline and model-posture side. Pick it when the assets to govern are models, training data and pipelines owned by a data-science team. Pick Zenity when they are business agents built by business users.
  • WitnessAI — the fastest-growing entrant, past $85M total funding after a $58M round backed by Sound Ventures, Qualcomm Ventures and Samsung Ventures, focused on employee AI usage policy and visibility. Pick it when the question is which AI apps your staff are using and what they paste into them, not what autonomous agents do with write access.

If none fit — under five agents, one platform, no auditor — the correct spend is zero. Write the owner column, turn on the platform’s native audit log, and put a human in front of writes.

Watch-outs

  • “Resource” is the billing unit and Zenity’s own material cites 150,000+ resources in a single tenant. Discovery is designed to find everything, and the same word covers a governed agent and an incidental discovered item. Guard: before signing, get the billable-resource definition in the contract with an example list, a cap on billable count, and confirmation in writing that discovered-but-ungoverned resources do not bill.
  • Runtime Boundaries can terminate an agent mid-run, and the agent it terminates may be the one drafting your renewal emails. Guard: run the first 60 days in monitor mode, export the would-have-blocked set weekly, and only promote a rule to blocking after it produces zero false positives across a full billing cycle for that agent.
  • Zenity is a control plane over platforms that are shipping their own controls monthly. Microsoft, Salesforce and AWS each have an incentive to close the gap Zenity sells into, and Agent 365 already covers part of it inside the tenant. Guard: hold the contract to 12 months rather than 36 at the first renewal, and write a re-evaluation trigger for the point where more than half your agents sit on one platform.
  • Analyst recognition is not a control test. A Gartner Cool Vendor listing in Agentic AI TRiSM tells you the category is real, not that the product blocks your attack. Guard: make the proof-of-value a red-team exercise on your own agents — plant an injection payload in a real inbound email, resume or ticket and require Zenity to stop the exfiltration path before you count the evaluation as passed.