Enterprise Software Watch: Platforms Gate Agents, Markets Bet on Incumbents
Watch Tech Series · Enterprise Software Watch | September 25, 2026
The latest enterprise software developments, such as agent access controls, market confidence, legacy security risk, and agent-trust infrastructure, move in parallel.
Enterprise software split into two stories this week: public markets gave incumbents a vote of confidence, while venture capital kept funding the infrastructure that must work before enterprises trust agents with anything that matters.
Six developments today — a platform opening its commerce APIs to a named AI agent, a rate-defying rally across four enterprise software majors, a zero-day breach tied to decades-old ERP infrastructure, and three funding rounds aimed at making agents safer to deploy — point to the same underlying tension. This edition covers what happened and what it means for the enterprise software stack. It complements recent's AI Watch and Infrastructure Software Watch coverage, keeping the focus on software business models, platform governance, and the enterprise application layer.
1. Amazon Opens Seller Tools to AI Agents, Starting With Claude
Source: GeekWire
At its Accelerate conference, Amazon said it is opening its seller tools to third-party AI agents, starting with Anthropic's Claude, in a beta limited to U.S. merchants.
The move is notable mainly for what came before it. Amazon had previously blocked Meta's Muse assistant from shopping on its platform, citing terms-of-service violations, security risk, and the absence of merchant consent. Opening the door selectively — to one named partner, on Amazon's own terms — is a different posture than either a blanket block or an open API.
That distinction matters more than the beta itself. Commerce platforms sit on transaction data, merchant relationships, and fraud-prevention infrastructure that took years to build. Letting an agent act inside that environment means extending trust an order of magnitude beyond letting a human browse it. Amazon choosing which agent gets that trust — rather than publishing an open standard any agent could use — sets a precedent other platforms holding equally sensitive data are likely to follow.
What It Means: Agent access to enterprise-grade commerce and data infrastructure is becoming permissioned, not open. Platforms are competing on which agent ecosystems they choose to trust rather than racing to expose the broadest possible API surface. For enterprise software vendors sitting on comparable troves of customer or transaction data, the Amazon-Claude beta is a template: pick a partner, gate access deliberately, and let the terms evolve before opening further.
The CODEW Lens: The next competitive axis in enterprise software isn't which agent is smartest — it's which agent gets let in the door.
2. Enterprise Software Stocks Defy the Rate Move
Source: 24/7 Wall St.
Long-dated Treasury yields reached their highest level in nearly two decades on Wednesday amid expectations of further Fed tightening — the kind of move that should hit hardest at companies whose value sits in distant future cash flows, the standard description of enterprise software names. Instead, Atlassian, monday.com, and Salesforce climbed roughly 3%, and ServiceNow nudged higher.
The comparison set is what makes the move worth flagging. The iShares Expanded Tech-Software Sector ETF rose while the Invesco QQQ Trust fell, meaning software moved against the broader tech complex rather than with it. All four names also outran the software ETF itself, pointing to a bid concentrated in large enterprise platforms specifically rather than a sector-wide lift.
No company-specific disclosure explains the Wednesday session for three of the four names. That absence is itself the story: investors appear to be repricing enterprise software as a group, on the thesis that platforms with deep customer relationships and data access are the ones positioned to monetize AI — not the ones AI displaces.
What It Means: Part of the investor base is now treating scaled enterprise platforms as the defensive corner of tech this cycle, not its highest-risk one — a direct rebuttal to the "SaaSpocalypse" thesis that agents cannibalize seat-based software revenue. Whether that holds through Q4 earnings, when Salesforce, ServiceNow, and peers report actual Agentforce and AI-monetization numbers, is the test that will validate or unwind this week's move.
The CODEW Lens: The market is starting to treat AI-monetization credibility as a hedge against duration risk, not just a growth narrative.
3. ShinyHunters Claim Oracle PeopleSoft Zero-Day Breach Tied to the FBI
Source: 404 Media
The extortion group ShinyHunters claims it used a zero-day vulnerability in Oracle PeopleSoft to breach FBI-related services, stealing employee and applicant data and defacing the FBI's own jobs site. A separate report indicates the stolen sample includes granular detail on officials' assignments across intelligence and counter-cartel work.
PeopleSoft remains widely deployed across government agencies and large enterprises for HR and financial management — software old enough to predate the cloud era, still running underneath operations that are supposed to be modern. This is less a one-off government story than a reminder of how much legacy infrastructure sits beneath the parts of the enterprise stack getting the AI investment.
Every AI agent an enterprise plugs into HR or finance data inherits the security posture of the systems those agents touch. A vulnerability in a decades-old ERP module doesn't stay contained to that module once an agent is reading from or writing to it as part of a broader workflow.
What It Means: Agent governance conversations tend to focus on the agent layer — permissions, guardrails, audit trails. This breach is a reminder that the layer underneath, the legacy systems of record most enterprises have no near-term plan to replace, is where a meaningful share of the actual risk still lives. Security reviews ahead of agent deployment need to extend past the agent's own scope into whatever system of record it touches.
The CODEW Lens: The weakest link in agentic AI security isn't the agent. It's the decades-old system of record sitting underneath it.
4. Cyera Raises $400M as Data Security Becomes an AI Prerequisite
Source: Wall Street Journal
Data security startup Cyera raised $400 million from Goldman Sachs in a Series G extension, bringing its total funding since June 2025 to $1.94 billion — one of the largest rounds of the year in the category.
Cyera's pitch centers on giving organizations visibility into where sensitive data actually lives across cloud and on-prem systems before that data gets exposed — whether to a breach, a misconfigured permission, or, increasingly, an AI agent with broader system access than any single human user would have.
The size and speed of the round — a $400M extension roughly a year after the company's last major raise — signals that boards are treating data classification and discovery as upstream infrastructure for AI deployment, not a parallel compliance spend.
What It Means: Enterprises are increasingly unwilling to grant agents broad data access without first knowing what that data is, where it lives, and who's supposed to see it. Data security vendors that can answer those questions quickly are positioned as gatekeepers for agent rollouts, not just breach-response tooling — a structurally different, and larger, market than the one data security sold into five years ago.
The CODEW Lens: Data security is no longer adjacent to the AI budget. It's becoming a line item inside it.
5. Snorkel AI Reaches $3.5B on an Agentic Data Platform
Source: Reuters
Snorkel AI raised $350 million at a $3.5 billion valuation for what it calls an "agentic data development platform," which pairs human reviewers with AI agents to create and vet the training data enterprise AI systems run on.
The round is a bet that data quality, not model access, is the real constraint on enterprise AI performance. Frontier models are now broadly available through APIs; what differentiates one company's AI deployment from another's is increasingly the quality, specificity, and governance of the data used to fine-tune and validate those models for a given workflow.
Using AI agents to help build and check the data that trains other AI systems is a recursive step worth noting on its own — data labeling, historically a manual and outsourced function, is becoming an agentic workflow in its own right.
What It Means: As frontier model access commoditizes, competitive advantage in enterprise AI shifts toward whoever controls the best domain-specific training and validation data. Expect more capital to move toward the unglamorous data-preparation layer of the AI stack, and more of that layer itself to be run by agents rather than outsourced labeling teams.
The CODEW Lens: Data labeling didn't disappear in the agent era. It became agentic too.
6. Raindrop Raises $35M to Catch Agent Failures Before Production
Source: Axios
Raindrop closed a $35 million Series A led by CRV to build monitoring tools that catch AI agent failures — hallucinations, tool misuse, silent errors — before they reach production systems.
The category Raindrop is building in — agent observability — mirrors how application performance monitoring became mandatory infrastructure once web applications moved to production at real scale. The difference is that agent failures aren't just performance problems; a hallucinated output or a misused tool call can take an irreversible action inside a connected system, not just render a broken page.
That distinction is why observability tooling for agents is arriving earlier in the adoption curve than APM did for web apps. Enterprises are asking for audit trails and failure detection before they grant agents write access to real systems, not after the first costly mistake.
What It Means: Agent monitoring is shaping up as a required layer of the enterprise AI stack rather than an optional add-on, closer in urgency to security tooling than to analytics dashboards. Vendors building this layer are effectively selling enterprises the confidence to deploy agents more aggressively elsewhere in the stack.
The CODEW Lens: Every category of software eventually needs a category of software that watches it. Agents are no exception — they just need it sooner.
The Enterprise Software Signal
Enterprise software isn't being disrupted by agents so much as being re-armored for them.
Every development this week, from a commerce platform gating agent access to a data-security round to an agent-monitoring raise, was about the same underlying question: what has to be true before an enterprise lets an agent act on real systems, real data, and real customers?
And the market's answer this week — a rally in the platforms that already hold the data and customer relationships, not a rotation toward pure-agent challengers — suggests investors think incumbents are better positioned to build that trust layer than anyone starting from zero.
| Development | Layer of the Stack |
|---|---|
| Amazon / Claude | Agent access & commerce permissions |
| Software stock rally | Capital markets confidence |
| PeopleSoft breach | Legacy system security risk |
| Cyera ($400M) | Data security & governance |
| Snorkel AI ($350M) | Training data quality |
| Raindrop ($35M) | Agent reliability & observability |
The CODEW Lens: The enterprise software market isn't choosing between incumbents and agents. It's building the trust infrastructure — access controls, data security, data quality, and observability — that determines how fast either one can actually be deployed.
Sources
→ GeekWire — Amazon opens seller tools to Claude
→ 24/7 Wall St. — Enterprise software stocks rally as tech tape slides
→ 404 Media — ShinyHunters claim PeopleSoft zero-day breach
→ Wall Street Journal — Cyera raises $400M from Goldman
→ Reuters — Snorkel AI valued at $3.5B
→ Axios — Raindrop raises $35M Series A
Next in Enterprise Software Watch
→ Agent Access Control: Who Gets to Plug Into Enterprise Commerce APIs?
→ The SaaSpocalypse Debate: Are Enterprise Platforms Actually the Safe Trade?
→ Legacy ERP Under Agentic AI: How Exposed Is Your System of Record?
The CODEW Stat
6 developments · $785M in disclosed capital · 0 acquisitions · 6 layers of the enterprise stack Today's enterprise software developments touched every layer of the trust infrastructure agents need before enterprises deploy them broadly: agent access and commerce permissions (Amazon/Claude), capital markets confidence (the software rally), legacy system security risk (the PeopleSoft breach), data security and governance (Cyera, $400M), training data quality (Snorkel AI, $350M), and agent reliability and observability (Raindrop, $35M). Together they point to a single structural read: enterprise software isn't losing to agents or winning against them — it's being re-armored, layer by layer, to make agent deployment safe enough to trust.
Editorial Note
The Enterprise Software Watch examines the developments reshaping enterprise software and AI agent platforms, including agentic architectures, SaaS pricing models, AI control planes, enterprise data and governance, non-human identity security, M&A across the agentic stack, and the competitive dynamics among software companies.
Educational content only. Not investment or business advice. Analysis is based on company announcements, official product disclosures, investor relations releases, and reporting from GeekWire, 24/7 Wall St., 404 Media, the Wall Street Journal, Reuters, and Axios. Metrics referenced are labeled as reported, calculated, or CODEW-derived. Some products referenced may be affiliate partners — see our Affiliate Disclosure for full details. Platform coverage, data sources, and methodologies can change as the intelligence platform evolves.
Reviewed by Erwin Castro
on
Friday, September 25, 2026
Rating:
