One sentence
Oasis issues the seat and scopes the access. Cyphrex proves the act: who approved, what was touched, and what stayed blocked.
Who each is for
Oasis
Agentic Access Management / NHI
Oasis issues scoped, ephemeral access so agents can act without standing privilege, and keeps a prompt-to-action record from intent through policy, session, and action. Oasis is now part of Cyera Identity.
Intent → ephemeral access → session audit.
Cyphrex
Compliance infrastructure for agents
A decide-and-prove layer for teams who will instrument an agent or route its MCP traffic, and who need each decision kept as tamper-evident evidence.
Enforce the action → tamper-evident evidence.
Capability comparison
| Capability | Oasis | Cyphrex |
|---|
| Intent-based / ephemeral agent access (JIT, least privilege) | Strong fit (AAM) | Not the primary job |
|---|
| NHI discovery + credential lifecycle | Strong fit | Per-agent identity you register |
|---|
| PAM-style elevation for agent workflows | Strong fit | Policy profiles / check() on instrumented path |
|---|
| Runtime allow / block on agent actions | AAM policy before data access | check() + MCP gateway before execution |
|---|
| Tamper-evident, independently verifiable decision record | Session audit: prompt → intent → policy → action | Ed25519-signed packages + public /verify |
|---|
| Who approved / what touched / what stayed blocked | Access + session custody for identity teams | Compliance receipt for auditors, insurers, legal |
|---|
When Oasis is the better fit
- The pain is standing privilege and long-lived tokens for agents and non-human identities.
- You need ephemeral, intent-scoped access issued per session.
- The buying center is IAM, NHI, or PAM, not compliance evidence packaging.
- You want a prompt-to-action chain of custody inside an access platform.
- You are standardizing on Cyera and Oasis for data and identity together.
When Cyphrex is the better fit
- Legal, risk, or compliance asks for a receipt: who approved the step, what was touched, and whether a blocked action stayed blocked.
- You need evidence a third party can verify without trusting the vendor UI.
- Builders will instrument agents or route MCP through a gateway and want decide, enforce, and prove in one path.
- You already have, or will buy, NHI and agentic access management elsewhere. The missing piece is the durable decide-and-prove trail.
- Regulated buyers want a signed, hash-bound action history, not only access telemetry.
Better together
Oasis answers what access the agent got, and for how long. Cyphrex answers what that actor was allowed to do on each step, and proves it.
What Cyphrex evidence proves
What a signed report contains
- Agent
- Action and resource
- Allowed or blocked
- Rule and violations
- Timestamp
How verification works
Every Cyphrex evidence package is signed with Ed25519 and bound with SHA-256. On /verify, someone can check it without a Cyphrex login.
Compliance mapping
Evidence artifacts map toward SOC 2 / EU AI Act / HIPAA / SR 26-2 style reporting — not certification; details on Trust.
Limits
Cyphrex signs what flows through the SDK check() or the MCP gateway. It does not invent coverage for a path it never saw. Cyphrex is not your auditor.
Frequently asked
Is Cyphrex an Oasis alternative or a complement?▾
Often a complement. Oasis issues the seat and scopes the access. Cyphrex records what that actor was allowed to do, and proves it. Cyphrex does not replace Oasis.
Does Cyphrex do full NHI discovery?▾
No. Discovery and credential lifecycle for non-human identities is Oasis’s job. Cyphrex registers a per-agent identity and checks policy on the path you instrument or route.
Are blocked actions recorded as blocked?▾
Yes. Allowed or blocked is part of the decision record, with the agent, action type, resource, rule, and timestamp.