THE IDENTITY FILE
31.03.26 LINX RAISES $50M SERIES B18.03.26 AUTOPILOT LAUNCHESTHE QUESTION WHO STILL HAS ACCESS?

Company / Identity security

Linx Security and the employee who never quite left

An employee leaves. Their access stays. Linx Security turns that small administrative oversight into a map of enterprise risk - and a case for automation that can explain itself.

The employee had already left. Their access to a client’s code repository had not. In a product example Linx Security disclosed at its 2024 debut, the company connected an account to its former owner and found that the account remained active and unsecured. There was no elaborate trick to admire. The mistake was ordinary enough to be embarrassing: a person’s departure and a permission’s departure had become two different events.

The story in 30 seconds
  • Linx connects identities, owners and permissions across enterprise systems.
  • Its customers include financial services and technology companies.
  • Autopilot adds continuous monitoring and policy-bound action.
  • The practical lesson: automate a narrow task, then earn wider trust.

That loose end helps explain the business. A company can know who works there and still struggle to know who can enter its applications. An employee has several accounts. A contractor has another handful. A service account belongs to no person in the payroll system. The tidy organization chart and the untidy access map describe the same company, with remarkably different casts.

01 / The map behind the mistake

Linx sells identity security and governance software to the teams responsible for reconciling those casts: security, identity and access management, IT operations, and compliance. Its starting point is the Identity Graph. The platform gathers and correlates data from connected cloud services, SaaS, on-premises systems and custom applications, mapping identities through accounts, groups and roles to the resources they can reach.

A list tells you an account exists. A relationship tells you whose account it is, what it can reach, and how it acquired that privilege. Linx uses those connections to expose dormant accounts, excessive permissions and incomplete offboarding. From the same platform, teams can revoke entitlements, adjust access or trigger a remediation workflow. The map is intended to shorten the journey between noticing a problem and doing something about it.

How an access question becomes a decision
01IdentityWho or what?
02Access pathAccount · role · resource
03ActionReview · revoke · escalate
A conceptual diagram of Linx’s approach. Follow the permission, then decide what belongs.

02 / A familiar team, an overlooked seam

CEO Israel Duanis and chief product officer Niv Goldenberg founded Linx in 2023. They had met in Israel’s Unit 8200 and arrived with experience in cybersecurity and enterprise software. Duanis had led Check Point’s threat-prevention business and co-founded Fleetonomy, the fleet-management company acquired by Via in 2020. Goldenberg’s background included Transmit Security.

The company’s expertise sits at the seam between security detection and administrative housekeeping. Who owns this credential? Is this access still justified? What happens when a person changes departments? These questions lack the glamour of an attacker’s exploit, but answering them requires understanding systems that were never designed to tell one coherent story.

The Linx team standing outside a building in matching black Linx shirts
Matching shirts; mismatched permissions are the day job. Linx’s team in the photograph accompanying its 2024 public debut.

03 / The buyer has a queue

The customer roster puts the problem in perspective. Linx publishes stories featuring lender New American Funding, financial-services company Achieve, security-screening company Evolv and work-platform company monday.com. Its customer page reports five million digital identities protected. That figure is Linx’s own measure of reach, rather than a count of paying organizations.

For these buyers, governance includes access requests, onboarding and offboarding, periodic reviews, and evidence for auditors. Linx’s agentless collection approach reduces the need to install additional software on connected systems. Its proposition is operational: bring scattered evidence together, give reviewers useful context, and automate repetitive work. A successful deployment should make the queue smaller and the decisions easier to defend.

Linx product illustration showing user access reviews, reviewer completion and approval decisions
Permission slips for grown-ups. Linx’s access-review illustration shows the decisions and the people still expected to make them. Displayed numbers are illustrative.

04 / Autopilot needs a flight recorder

Linx announced Autopilot on March 18, 2026. It monitors changes such as newly granted privileged access and shifts in responsibilities, evaluates them in context, and either acts or escalates. The product description says automated actions are scoped by policy and logged. Ambiguous or consequential changes can go to a human with the relevant context assembled.

By May, Duanis described a lesson from buyer conversations: enterprises wanted action and a defensible record of its reasoning. Teams were choosing a staged rollout themselves - recommendations first, pre-approved classes of action next, then autonomy for bounded tasks. Early examples included monitoring unjustified admin elevation and suggesting access-review decisions. This was a refinement of how to earn trust, rather than a disclosed reversal of the company’s strategy.

“We make autonomy boring.”

Israel Duanis, writing about Autopilot, May 2026

There is a useful idea to copy here, even without buying Linx: choose a task with clear success criteria, inspect the evidence, and expand authority only after the results justify it. A machine that acts faster also makes an incorrect decision faster. Logging and escalation belong in the design from the beginning.

05 / What the money buys

Linx’s July 2024 debut came with $33 million in accumulated funding: a $6 million seed investment and a $27 million Series A. In March 2026, Insight Partners led a $50 million Series B alongside Cyberstarts and Index Ventures. Total announced financing reached $83 million, earmarked for product development, enterprise sales and international expansion.

The business model is enterprise SaaS under contract. The AWS Marketplace listing displays a $1 million platform line item for twelve months. Read that as a listed contract dimension, not a typical customer invoice; the listing says terms depend on the vendor agreement. Buyers also need to account for integration work and their own staff’s time when judging the economics.

06 / The application matters more than the slogan

Linx competes in a market that includes SailPoint, Saviynt and Veza. Its pitch combines governance, risk visibility and remediation around shared identity context. Yet Linx’s own comparison guide acknowledges narrower on-premises application coverage than vendors with decades of connector history. It also says organizations needing credential vaulting will retain a dedicated privileged-access product.

Those qualifications matter. For an enterprise dependent on older applications, connector coverage can decide the purchase. For a security team without agreed ownership or policies, automation still needs decisions someone is authorized to make. The sensible evaluation starts with actual accounts and actual systems: find the departed employee, trace the surviving access, and see whether the proposed fix can be explained. That is a much more revealing demonstration than another dashboard.