Skip to content
Video

Closing Identity Governance's Last Mile: Sinan Eren on Opnova's Black Hat Win

Opnova CEO Sinan Eren tells theCUBE how imitation learning turns 6-month IGA connector builds into hours, and eliminated 15,000 tickets for one bank.

A typical US bank runs hundreds, sometimes thousands, of applications. Some are still AS/400 mainframes behind green-screen terminals with no API layer, no SCIM support, nothing a modern identity governance platform can talk to. Getting a systems integrator to build a custom connector for one of those applications takes about six months. Do the math across a few hundred applications and a bank can burn through three to five million dollars and still only cover 20 to 30 percent of its footprint.

 

That gap is what Opnova was built to close. Fresh off winning Black Hat's Startup Spotlight Competition for both the US and Global tracks, co-founder and CEO Sinan Eren sat down with theCUBE's Krista Case to walk through it.

 

A 15-year-old problem

 

"This is also known as the last mile integration challenge," Eren said. "Disconnected applications."

 

It's not a new problem. Identity governance and administration platforms have existed for well over a decade, and the long tail of applications they can't reach has been a known gap for most of that time. The reason it persists goes beyond technical difficulty. Legacy applications were built to run a bank's operations, not to feed a governance platform. Many depend on flat files or CSV exports instead of granular APIs, and the vendors behind them have little reason to change that. Governance isn't their problem to solve.

 

It becomes someone else's problem the moment an audit fails. "Any organization that might have failed an audit will know painfully well that this long tail of disconnected applications is where the real risk lies," Eren said.

 

Compliance first, speed second

 

Two things are forcing customers to finally act. The first is Sarbanes-Oxley. Public companies run quarterly account recertification, where business unit managers sign off on every employee's entitlements. An application that's disconnected from the governance platform can't be recertified the way it's supposed to be, and a failed audit tied to that gap is usually what gets a project funded.

 

The second is speed. A new banker or loan officer can wait weeks, sometimes months, to get full system access if provisioning depends on manual work across disconnected applications. That's no longer acceptable in a market where onboarding speed is a competitive edge.

 

"We're not saying rip and replace"

 

Opnova's pitch to CISOs starts with what it isn't. It isn't a new platform positioned to replace the IGA system already in place. "We wrote a thesis document once we identified the problem: we're going to be a better-together solution," Eren said. "We're not saying rip and replace. We're not saying your IGA platform is from the on-prem era, now it's AI native. That's the typical Silicon Valley narrative, and I think that playbook has run its course."

 

That framing is doing real work in sales conversations. Eren said it's part of why Opnova nearly always walks away from a customer engagement with a proof of concept. The reason CISOs say yes comes down to one thing: "The low TCO," Eren said. Lower total cost of ownership for the platform they already bought, a faster path back into audit compliance, tighter provisioning SLAs, and for IT service desk teams, a meaningfully better mean time to resolution.

 

How six months becomes six hours

 

The technical core is what Eren calls imitation learning. When an IGA platform hits an application it can't automate, that work usually falls to a service desk employee clicking through an admin console or a green-screen terminal by hand. Opnova records that process and turns it into a standard operating procedure, written in plain language, available in multiple languages including Japanese, ready for an identity engineer to review and push to production.

 

"What is typically a six-month process for a GSI to build a custom connector could be done in under six hours," Eren said. "We onboard applications on a daily basis, not monthly, not yearly."

 

Screenshots, not browsers

 

Opnova calls itself a computer-use model specialist, and Eren was careful to draw a line between that and browser automation. The underlying models are multimodal and trained on screen understanding: what a scroll bar is, where a label sits, where to type. That understanding doesn't depend on a browser. "We can do that for an AS/400 terminal," Eren said. "If a human can interact with the application, we can learn from that interaction and repeat it."

 

The obvious follow-up question, and one Eren said design partners asked from day one, is what happens when the model hallucinates or the workflow doesn't behave the same way twice. Opnova's answer is a caching layer the team built specifically to preempt that objection. As long as execution stays on the recorded "happy path," there's no inference call at all, the system just replays the recorded steps. Inference only gets invoked when something deviates: an unexpected screen, a slowdown, a crash. The model figures out the next best step, gets execution back to the happy path, and the recorded replay picks back up from there.

 

That's also where Eren sees the human role holding steady. Judgment about what to prioritize and how much organizational context a given workflow needs doesn't go away. "There's a lot of tacit knowledge in every organization," he said. "AI cannot understand if there's not enough context." Humans stay in the loop as the ones an agent turns to the moment it loses the happy path.

 

The leaderboard nobody wanted

 

The clearest example Eren gave was a banking customer stuck between two bad options. Every ticket the IGA platform couldn't automate had to go somewhere: either the security team handled it manually, or the work got handed off to business unit application owners. The CISO didn't want to lose control by outsourcing it, so the security team absorbed the load instead. They even kept an internal leaderboard tracking who resolved the most tickets.

 

"It's not their job," Eren said. "It's not the most efficient way of using their time." Opnova automated that workload and eliminated 15,000 manual tickets for the bank in its first year.

 

AI-native, not AI-bolted-on

 

Across the Startup Spotlight field, Eren noticed a real commitment to building around AI rather than adding it on top. "It's not a bolt-on," he said. "It's not a bot that answers questions from stored documentation. There's a use case that is supported and enhanced and made better by AI, at the core." For Opnova, that's computer use applied to disconnected applications. Among the companies he saw, other examples spanned deception technology and systems built to learn and replay SOC workflows, essentially SOAR reimagined with AI underneath it.

 

What's next

 

Eren's read on the next 12 months starts with the obvious pressure point: security teams are already drowning in AI-generated code, so code review, auditing, and pentesting are the immediate opportunity. "If we're generating code at machine speed, we need to protect it at machine speed too," he said.

 

After that, he expects AI agents to take on the repetitive work security teams inherit by default, patching, triage, and remediation of misconfigurations and vulnerabilities, with the same combination Opnova has already put into production: autonomous execution, real guardrails, and a human who stays in the loop.