THANK YOU FOR SUBSCRIBING


Benny Porat, Co-Founder and CEOCloud adoption, remote work models, and the rapid proliferation of AI tools have fueled an unprecedented surge in cyber threats. In response, organizations are investing heavily in advanced security infrastructure. Yet the human capacity required to operate, manage, and govern these systems has not kept pace. At the same time, many organizations still depend on highly manual processes to run security tools and coordinate workflows. This reliance on human intervention makes operations time-intensive and expensive, slowing response times, increasing the risk of error, and limiting the ability to scale defenses effectively.
The result is a widening execution gap.
Twine was founded to address this imbalance. Rather than adding another dashboard or workflow tool to the stack, the company introduced a new operating model for cybersecurity teams: AI digital employees that work alongside human teams to complete security objectives end to end. Its first AI digital employee, Alex, focuses on identity and access management (IAM) and is designed to operate as a member of the IAM team.
“Identity has become one of the most critical attack surfaces,” says Benny Porat, co-founder and CEO. “Most breaches ultimately abuse access, and most security programs struggle not because they lack tools, but because they lack the capacity to operate them continuously.”
This insight forms the foundation of Twine’s approach.
Reimagining Identity and Access Management
How does Twine’s AI digital employee transform traditional identity and access management workflows?
IAM sits at the core of enterprise security, governing who has access to what, under which conditions, and for how long. Yet daily IAM operations remain fragmented and labor-intensive, layered on top of complex systems of record.
Traditional IAM platforms such as Microsoft Entra and SailPoint provide strong governance and control frameworks. They act as authoritative sources of identity data. However, day-to-day execution often requires significant human intervention. Teams must configure policies, process tickets, conduct user access reviews, investigate anomalies, and coordinate across HR and IT systems. In large enterprises or organizations with high employee turnover, this operational burden can become overwhelming.![]()
Traditional IAM platforms are powerful. “But organizations have enough powerful tools. Their real problem is not being able to execute their cybersecurity programs properly and fully. Twine’s first AI digital employee, Alex, understands your cybersecurity program, identifies gaps, and autonomously fixes them end to end.
Twine’s AI digital employee, Alex, was built to shift this model from periodic and manual to continuous and proactive. Based on a multi-agent system architecture, Alex is designed to learn, understand, and execute IAM tasks in the same way a skilled human team member would. It sits on top of existing IAM systems, using them as the source of truth while driving the operational workflows already in place, including:
It sits on top of existing IAM systems, using them as the source of truth while driving the operational workflows already in place, including: IAM ticket automation, which reduces manual workloads and streamlines how teams manage access requests by evaluating contextual signals to determine which requests are legitimate and how they should be processed autonomously; provisioning and deprovisioning, which automates access lifecycle management by integrating with HR systems, ensuring new employees receive timely access to required resources and that departing employees are promptly removed from critical systems, thereby reducing security risk in dynamic organizations; MFA enforcement, which strengthens identity assurance by verifying multi-factor authentication usage and assessing contextual factors such as location, time, and device type before granting access; user access reviews, which simplify compliance processes by providing clearer context and actionable insights, enabling more informed approvals and reducing the likelihood of superficial sign-offs; and reporting and visualization, which deliver real-time visibility into identity activity, generate audit-ready documentation, and help teams detect anomalies or unauthorized behavior and identity issues - then fix them.
The impact is measurable. Routine identity operations become faster and more consistent. Governance cycles are streamlined, compliance evidence is easier to compile, and, most importantly, risk exposure tied to access mismanagement is reduced.
Closing the Execution Gap in Cybersecurity
How does Twine’s approach address talent shortages and operational inefficiencies in cybersecurity teams?
The cybersecurity execution gap stems partly from the industry’s growing talent shortage. This is not merely a hiring challenge; it is an operational risk. Organizations may own advanced security tools, yet without sufficient expertise and bandwidth, those tools remain underutilized.
Twine positions Alex as a response to this structural issue. Alex augments existing IAM and cybersecurity teams by taking ownership of repetitive and context-heavy identity tasks: it investigates identity issues, gathers missing information, maps findings to organizational policies, and drives resolution through established workflows.
A defining feature of Alex is its ability to manage edge cases and ambiguity, which are common in IAM environments. Identity data is often incomplete or inconsistent, policies may include exceptions, and human judgment is frequently required. Alex addresses these realities through a combination of multi-agent investigation and guardrails.
Under Twine’s Trust by Verify framework, Alex operates autonomously when confidence levels are high. When an edge case requires managerial input, it escalates appropriately while maintaining a detailed audit trail of what it identified, what actions were taken, and the rationale behind them. This approach balances automation with oversight, preserving trust and compliance integrity.
With Alex on a cybersecurity team, professionals can focus less on administrative tasks and reactive triage and more on architectural improvements, threat modeling, and strategic risk management.
Real-world deployments demonstrate the potential impact. In one case, a global food and beverage enterprise with more than 80,000 employees faced fragmented Active Directory (AD) and Entra processes, recurring audit flags, and an overloaded service desk. After deploying Alex, integrated with its identity governance, directory, and IT service management systems, the organization automated 60 percent of its identity-related help desk volume. Privileged MFA coverage reached 95 percent within 60 days.
Stale and privileged accounts were reduced by 85 percent, delivering more than $250,000 in annual savings alongside measurable risk reduction.
In another example, a regulated financial institution that had invested heavily in SailPoint still struggled with reactive IAM operations and audit readiness. By integrating Alex into its IAM, directory, and service management stack, the organization reduced the average time to detect and begin resolving SailPoint failures to approximately 7.5 minutes. As a result, manual triage time dropped by 40 percent. New-hire provisioning was reduced to under a day, and audit preparation effort decreased by 68 percent through continuous identification and remediation of segregation-of-duties issues and overdue certifications.
These outcomes reflect a broader shift. Instead of accumulating more tools, organizations are beginning to explore AI digital employees that actively execute work and close operational gaps.
Building the Agentic Cyber Workforce of the Future
What is Twine’s long-term vision for AI digital employees in cybersecurity operations?
For Twine, Alex is the first step in a larger vision. The company sees AI digital employees as domain experts that collaborate across security functions, enabling organizations to improve measurable security outcomes without constantly expanding headcount.
The focus on end-to-end ownership distinguishes AI digital employees from automation scripts or workflow accelerators. The goal is efficiency, accountability, and continuous improvement.
In the near term, Twine plans to deepen Alex’s identity capabilities, expand integrations, and strengthen closed-loop governance so that identity becomes a continuous discipline rather than a periodic exercise. Over time, Alex will be joined by additional AI digital employees with expertise in other cybersecurity domains.
The broader narrative centers on enabling teams to move from reactive operations to proactive risk management. Organizations need execution at scale.
By embedding AI digital employees into existing stacks and workflows, Twine offers a model in which cybersecurity teams gain capacity without sacrificing control. In an industry defined by complexity and scarcity, that combination may prove essential to securing the digital enterprise of the future.
Company
Twine
Management
Benny Porat, Co-Founder and CEO
Description
Twine is a cybersecurity company pioneering AI Digital Employees to close the industry’s execution gap. Its agentic AI teammate, Alex, operates within Identity and Access Management environments to automate provisioning, access reviews, MFA enforcement and compliance workflows. By embedding autonomous execution into existing security stacks, Twine enables organizations to reduce risk, improve efficiency and scale operations without expanding headcount.