enterprisesecuritymag

Enterprise Security Magazine

Twine
Operationalizing Cybersecurity with Agentic AI

Benny Porat, Co-Founder and CEO, TwineBenny Porat, Co-Founder and CEO
What factors are contributing to the growing execution gap in cybersecurity operations today?

Cloud adoption, remote work models, and the rapid proliferation of AI tools have fueled an unprecedented surge in cyber threats. In response, organizations are investing heavily in advanced security infrastructure. Yet the human capacity required to operate, manage, and govern these systems has not kept pace. At the same time, many organizations still depend on highly manual processes to run security tools and coordinate workflows. This reliance on human intervention makes operations time-intensive and expensive, slowing response times, increasing the risk of error, and limiting the ability to scale defenses effectively.

The result is a widening execution gap.

Twine was founded to address this imbalance. Rather than adding another dashboard or workflow tool to the stack, the company introduced a new operating model for cybersecurity teams: AI digital employees that work alongside human teams to complete security objectives end to end. Its first AI digital employee, Alex, focuses on identity and access management (IAM) and is designed to operate as a member of the IAM team.

“Identity has become one of the most critical attack surfaces,” says Benny Porat, co-founder and CEO. “Most breaches ultimately abuse access, and most security programs struggle not because they lack tools, but because they lack the capacity to operate them continuously.”

This insight forms the foundation of Twine’s approach.

Reimagining Identity and Access Management

How does Twine’s AI digital employee transform traditional identity and access management workflows?

IAM sits at the core of enterprise security, governing who has access to what, under which conditions, and for how long. Yet daily IAM operations remain fragmented and labor-intensive, layered on top of complex systems of record.


Traditional IAM platforms are powerful. “But organizations have enough powerful tools. Their real problem is not being able to execute their cybersecurity programs properly and fully. Twine’s first AI digital employee, Alex, understands your cybersecurity program, identifies gaps, and autonomously fixes them end to end.

Traditional IAM platforms such as Microsoft Entra and SailPoint provide strong governance and control frameworks. They act as authoritative sources of identity data. However, day-to-day execution often requires significant human intervention. Teams must configure policies, process tickets, conduct user access reviews, investigate anomalies, and coordinate across HR and IT systems. In large enterprises or organizations with high employee turnover, this operational burden can become overwhelming.

Twine’s AI digital employee, Alex, was built to shift this model from periodic and manual to continuous and proactive. Based on a multi-agent system architecture, Alex is designed to learn, understand, and execute IAM tasks in the same way a skilled human team member would. It sits on top of existing IAM systems, using them as the source of truth while driving the operational workflows already in place, including:

It sits on top of existing IAM systems, using them as the source of truth while driving the operational workflows already in place, including: IAM ticket automation, which reduces manual workloads and streamlines how teams manage access requests by evaluating contextual signals to determine which requests are legitimate and how they should be processed autonomously; provisioning and deprovisioning, which automates access lifecycle management by integrating with HR systems, ensuring new employees receive timely access to required resources and that departing employees are promptly removed from critical systems, thereby reducing security risk in dynamic organizations; MFA enforcement, which strengthens identity assurance by verifying multi-factor authentication usage and assessing contextual factors such as location, time, and device type before granting access; user access reviews, which simplify compliance processes by providing clearer context and actionable insights, enabling more informed approvals and reducing the likelihood of superficial sign-offs; and reporting and visualization, which deliver real-time visibility into identity activity, generate audit-ready documentation, and help teams detect anomalies or unauthorized behavior and identity issues - then fix them.

“Traditional IAM platforms are powerful,” says Porat. “But organizations have enough powerful tools. Their real problem is not being able to execute their cybersecurity programs properly and fully. Twine’s first AI digital employee, Alex, understands your cybersecurity program, identifies gaps, and autonomously fixes them end to end.”

The impact is measurable. Routine identity operations become faster and more consistent. Governance cycles are streamlined, compliance evidence is easier to compile, and, most importantly, risk exposure tied to access mismanagement is reduced.
Closing the Execution Gap in Cybersecurity

How does Twine’s approach address talent shortages and operational inefficiencies in cybersecurity teams?

The cybersecurity execution gap stems partly from the industry’s growing talent shortage. This is not merely a hiring challenge; it is an operational risk. Organizations may own advanced security tools, yet without sufficient expertise and bandwidth, those tools remain underutilized.

Twine positions Alex as a response to this structural issue. Alex augments existing IAM and cybersecurity teams by taking ownership of repetitive and context-heavy identity tasks: it investigates identity issues, gathers missing information, maps findings to organizational policies, and drives resolution through established workflows.

A defining feature of Alex is its ability to manage edge cases and ambiguity, which are common in IAM environments. Identity data is often incomplete or inconsistent, policies may include exceptions, and human judgment is frequently required. Alex addresses these realities through a combination of multi-agent investigation and guardrails.

Under Twine’s Trust by Verify framework, Alex operates autonomously when confidence levels are high. When an edge case requires managerial input, it escalates appropriately while maintaining a detailed audit trail of what it identified, what actions were taken, and the rationale behind them. This approach balances automation with oversight, preserving trust and compliance integrity.

With Alex on a cybersecurity team, professionals can focus less on administrative tasks and reactive triage and more on architectural improvements, threat modeling, and strategic risk management.

Real-world deployments demonstrate the potential impact. In one case, a global food and beverage enterprise with more than 80,000 employees faced fragmented Active Directory (AD) and Entra processes, recurring audit flags, and an overloaded service desk. After deploying Alex, integrated with its identity governance, directory, and IT service management systems, the organization automated 60 percent of its identity-related help desk volume. Privileged MFA coverage reached 95 percent within 60 days.
Stale and privileged accounts were reduced by 85 percent, delivering more than $250,000 in annual savings alongside measurable risk reduction.

In another example, a regulated financial institution that had invested heavily in SailPoint still struggled with reactive IAM operations and audit readiness. By integrating Alex into its IAM, directory, and service management stack, the organization reduced the average time to detect and begin resolving SailPoint failures to approximately 7.5 minutes. As a result, manual triage time dropped by 40 percent. New-hire provisioning was reduced to under a day, and audit preparation effort decreased by 68 percent through continuous identification and remediation of segregation-of-duties issues and overdue certifications.

These outcomes reflect a broader shift. Instead of accumulating more tools, organizations are beginning to explore AI digital employees that actively execute work and close operational gaps.

Building the Agentic Cyber Workforce of the Future

What is Twine’s long-term vision for AI digital employees in cybersecurity operations?

For Twine, Alex is the first step in a larger vision. The company sees AI digital employees as domain experts that collaborate across security functions, enabling organizations to improve measurable security outcomes without constantly expanding headcount.

The focus on end-to-end ownership distinguishes AI digital employees from automation scripts or workflow accelerators. The goal is efficiency, accountability, and continuous improvement.

In the near term, Twine plans to deepen Alex’s identity capabilities, expand integrations, and strengthen closed-loop governance so that identity becomes a continuous discipline rather than a periodic exercise. Over time, Alex will be joined by additional AI digital employees with expertise in other cybersecurity domains.

The broader narrative centers on enabling teams to move from reactive operations to proactive risk management. Organizations need execution at scale.

By embedding AI digital employees into existing stacks and workflows, Twine offers a model in which cybersecurity teams gain capacity without sacrificing control. In an industry defined by complexity and scarcity, that combination may prove essential to securing the digital enterprise of the future.

Deep Dive

Digital Identity Management in the Age of Autonomous Cybersecurity

Identity has emerged as the central control layer of modern enterprise security. Cloud infrastructure, SaaS adoption and distributed workforces have dramatically increased the number of users, devices and services requesting access to corporate resources. Each new identity introduces potential risk. Security leaders responsible for digital identity management face the challenge of maintaining tight control over permissions while supporting business speed and scale. Most organizations already operate sophisticated identity governance and access management platforms. The challenge lies less in the availability of technology and more in the ability to execute identity operations consistently. Provisioning, access reviews, ticket handling and termination workflows often remain dependent on manual coordination between IT, security and business teams. These fragmented processes slow response times and introduce gaps that attackers can exploit. The cybersecurity workforce shortage intensifies this problem. Millions of unfilled security roles worldwide have forced organizations to stretch existing teams across an expanding attack surface. Security professionals frequently spend large portions of their time resolving access tickets, correcting directory errors and performing periodic reviews rather than addressing broader risk management priorities. The result is a reactive identity program where governance cycles struggle to keep pace with enterprise change. Modern digital identity management, therefore, depends on sustained execution rather than periodic oversight. Organizations must be able to grant access quickly when employees join or change roles while ensuring that permissions are removed immediately when responsibilities shift or employment ends. Continuous identity hygiene is essential to prevent privilege accumulation and dormant accounts that create exposure. Effective platforms increasingly distinguish themselves by automating identity work in context. Access decisions rarely follow simple rules. Security teams must account for business roles, compliance policies, device context and location signals when evaluating requests. Systems that correlate identity data across HR platforms, directory services and governance tools help teams make accurate access decisions while reducing manual effort. Transparency and accountability remain equally critical. Identity governance intersects directly with compliance obligations and internal audits. Security leaders must demonstrate that access decisions follow established policy and that reviews occur regularly. Solutions capable of producing detailed records of approvals, investigations and remediation activity help organizations maintain audit readiness while lowering administrative overhead. Integration across the identity ecosystem also plays a decisive role. Enterprises rarely replace existing identity systems entirely. Instead, they rely on multiple technologies, including directory services, identity governance platforms and service desk tools. Platforms that operate across these systems to coordinate identity workflows provide greater value than tools that function in isolation. Twine addresses these challenges through an AI-driven digital employee designed specifically for identity management. Its system, Alex, works alongside cybersecurity teams by executing routine identity tasks while using existing IAM platforms as the system of record. The platform connects to infrastructure such as Microsoft Entra SailPoint HR systems and service management tools, then performs identity operations across those workflows. Alex analyzes identity context across enterprise systems to automate activities such as access request processing, provisioning user access reviews and identity hygiene. When encountering incomplete data or policy exceptions, it gathers additional context and proposes the appropriate course of action while maintaining a documented audit trail. Organizations deploying the platform have reported measurable improvements in identity operations, including reductions in help desk workload, faster remediation of identity issues, stronger MFA coverage and improved governance outcomes. For executives evaluating modern identity management solutions, Twine offers a compelling approach that enhances the operational capacity of cybersecurity teams without requiring additional specialized headcount. ...Read more

Company
Twine

Headquarters
.

Management
Benny Porat, Co-Founder and CEO

Description
Twine is a cybersecurity company pioneering AI Digital Employees to close the industry’s execution gap. Its agentic AI teammate, Alex, operates within Identity and Access Management environments to automate provisioning, access reviews, MFA enforcement and compliance workflows. By embedding autonomous execution into existing security stacks, Twine enables organizations to reduce risk, improve efficiency and scale operations without expanding headcount.

© 2026 Enterprise Security Magazine. All rights reserved. Headquartered in Fort Lauderdale, FL, USA.