Decawork

Decawork

24/08/2026
Sponsored Link

Decawork Investment Report

Category: Enterprise AI agent security, identity, and governance

Company Stage: Pre-seed / accelerator-stage

Founder or Founders: Aman Raj (CEO) and Sarthak Aggarwal (CTO)

Headquarters: San Francisco, California

Funding: Y Combinator S26; total funding and terms not publicly disclosed

Business Model: Enterprise SaaS; pricing not publicly disclosed

Product Hunt Launch Date: August 24, 2026

Report Date: August 27, 2026

Investment MetricAssessment
Venture Potential63/100
Unicorn PathConditional
Valuation AttractivenessNot Assessable
Evidence Confidence57/100
Final DecisionWatch

Executive Summary

Decawork is an IT control plane for employee-built AI agents. It gives agents individual identities, scopes access, requires approval before deployment, and logs actions through a gateway. It targets IT and security teams managing “shadow agents” built with tools such as ChatGPT, Claude Code, n8n, Microsoft Copilot, OpenAI SDKs, LangGraph, Gemini, Codex, and Cursor (official website; security).

The problem is timely: employees can create agents that act on corporate systems faster than IT can inventory and govern them. Decawork’s cross-tool position is attractive because enterprises will use multiple agent frameworks. Its strongest signal is founder-market fit: YC identifies a two-person S26 team with company-reported enterprise AI and compliance experience at Barclays, NVIDIA, and Ema (YC profile).

Product Hunt showed 336 points, 959 followers, and a #2 daily rank at review time, but this demonstrates launch interest rather than revenue, retention, or product-market fit (Product Hunt). No reliable public evidence was found for paid customers, production deployments, revenue, retention, gross margin, or repeatable acquisition.

Competition is material. Microsoft offers agent identity, lifecycle, access control, observability, and governance through Entra Agent ID and Agent 365, including third-party agents (Microsoft). Decawork must win through neutral cross-platform coverage, deployment speed, and proprietary policy or activity intelligence.

Final decision: Watch. The problem and founders merit monitoring, but commercial evidence is too thin for DD. Upgrade requires referenceable enterprise pilots, recurring revenue, sustained production use, verified security assurance, and a defensible cross-platform advantage.

Product Overview

Internal agents may inherit broad human credentials, operate without independent identity, and leave fragmented audit trails. Decawork proposes a registry and enforcement layer: IT approves agents, assigns task-specific access, sets spending or action limits, and routes tool calls through an attributed gateway. The company says agents never hold raw credentials and sensitive actions can require approval (security).

Initial users are security, identity, platform-engineering, and IT teams where employees build agents across frameworks. The benefit is centralized control without mandating one stack. Alternatives include spreadsheets, service accounts, secrets managers, IAM tools, internal API gateways, and prohibiting agent creation.

No self-serve plan or public price was found. The site discusses pilots and paid deployments governed by separate agreements, indicating enterprise sales but not verified contracts (terms). Product maturity and production availability cannot be independently verified.

Founder and Team Assessment

YC lists Aman Raj as CEO and Sarthak Aggarwal as CTO. Raj’s company-reported biography cites an AI compliance platform at Barclays; Aggarwal’s cites AI systems at NVIDIA and enterprise-agent work at Ema. These backgrounds fit the product, but detailed outcomes were not independently verified (YC profile).

YC reports two team members; LinkedIn displays three associated employees, a minor discrepancy likely caused by timing or role status (LinkedIn). No open roles were found. The small team creates key-person and execution risk across integrations, security, support, and sales.

Founder Assessment: Strong technical founder-market fit, but commercial capability remains unproven.

Market Opportunity

The initial segment is mid-market and enterprise organizations allowing employee-built agents to access internal SaaS, data, or financial workflows. An analyst scenario—not a verified market statistic—of 5,000 organizations at $50,000 annual contract value yields $250 million in potential ARR. Expansion into 20,000 organizations at broader $100,000 contracts would imply $2 billion, but neither customer count nor willingness to pay is verified.

Demand should be strongest where agent actions create compliance, access, or financial risk. Adjacent modules could cover machine identity, MCP governance, runtime threat detection, incident response, data-loss prevention, and audit reporting. Geography is broad, though data residency and regulation add cost.

The market can support venture revenue if Decawork becomes a neutral control plane across heterogeneous stacks. A simple approval dashboard is unlikely to do so.

Traction and Growth Signals

Product Hunt’s 336 points, 959 followers, and #2 daily rank are positive discovery signals. Comments support the need for centralized controls, but remain qualitative. The site is current; privacy and terms became effective July 12, 2026, and the footer identifies Scale Technologies Inc. (privacy; terms).

YC participation is institutional validation, not commercial traction. No reliable public data was found for ARR, customers, pilots, active agents, retention, case studies, reviews, GitHub adoption, partnerships, hiring, or post-launch momentum. A secondary database’s financing figure was not corroborated and is excluded.

Traction Assessment: Strong launch interest but commercially unverified.

Competitive Position

Competitors include Microsoft Entra Agent ID/Agent 365, IAM providers such as Okta/Auth0, non-human-identity security vendors, agent-security platforms, API gateways, and observability tools. Free alternatives include cloud service accounts, secrets managers, approval tickets, spreadsheets, and internal proxies.

Decawork combines cross-framework identity, approval, scoped credentials, and action logging. Policies, inventories, and audit history could create switching costs, but no proprietary dataset, network effect, patent position, or distribution moat is public.

If the largest platform launched the same feature within six months, customers would stay only if Decawork governed mixed Microsoft, Google, OpenAI, Anthropic, open-source, and custom stacks more deeply while integrating with incumbent IAM. That advantage is plausible but unproven.

Defensibility Assessment: Low to Medium.

Business Model and Economics

The likely model is annual enterprise SaaS priced by organization, managed agents, connectors, or tool-call volume. Pricing, free plan, contract length, and ACV are unknown. Security software can support attractive ACV, but no range can responsibly be attributed to Decawork without quotes or contracts.

Gateway architecture creates compute, logging, storage, support, and reliability costs that scale with use. Security reviews and custom integrations may make early deployments services-heavy. Decawork must show subscription and expansion revenue outpacing infrastructure and support costs.

Founder-led sales will likely precede partnerships with agent builders, IAM providers, and consultancies. Diligence must verify gross margin, implementation labor, sales cycles, pilot conversion, customer concentration, and liability allocation.

Unicorn Path

Assume a 10× ARR multiple for fast-growing, high-retention enterprise security SaaS; this is an analyst assumption, not Decawork’s valuation. A $1 billion valuation would require approximately $100 million ARR. At $50,000 ACV, that is 2,000 customers; at $200,000 ACV, 500 customers.

Reaching this scale requires repeatable enterprise distribution, high retention, expansion revenue, global reach, and evolution from registration into identity, runtime policy, observability, threat detection, and compliance. Decawork must coexist with incumbent IAM and maintain security-grade uptime and likely above-70% gross margins.

Unicorn Path: Conditional

Valuation Assessment

Verified financing is limited to YC S26 participation. Capital raised, current round, SAFE cap, valuation, ownership, liquidation preferences, and fundraising status are not public. Revenue and growth are also unknown.

Valuation Attractiveness: Not Assessable

Assessment requires ARR, growth, gross margin, retention, burn, runway, round size, financing terms, and pro forma ownership. Product Hunt attention cannot support a valuation range.

Key Risks

  1. Commercial validation: No verified revenue, customers, retention, or production usage.
  2. Incumbent bundling: Microsoft already markets overlapping controls.
  3. Security liability: A credential and action gateway is a high-value attack target.
  4. Integration burden: Rapidly changing frameworks may overwhelm a small team.
  5. Weak defensibility: No verified proprietary data, network effects, or distribution moat.
  6. Enterprise friction: Security review and procurement may lengthen cycles.
  7. Reliability: Downtime or bad policy decisions could block critical workflows.
  8. Team concentration: Two founders cover engineering, compliance, support, and sales.
  9. Market timing: Enterprises may delay broad production agent deployment.
  10. Unknown economics: Gross margin, burn, runway, and financing terms are unavailable.

Final Assessment

Venture Potential: 63/100

CategoryScore
Market Size and Expansion Potential17/20
Traction and Growth Evidence4/20
Founder and Team13/15
Product Strength8/10
Distribution Potential9/15
Business Model and Economics6/10
Defensibility6/10
Total63/100

Market timing, founder fit, and a coherent cross-platform thesis are strengths. Missing commercial evidence, incumbent exposure, and unproven defensibility are weaknesses.

Evidence Confidence: 57/100

Verified information covers the launch, official positioning, YC participation, named founders, legal policies, and company footer. Founder achievements are mainly company-reported. Market sizing, ACV, and unicorn calculations are analyst scenarios. Revenue, customers, retention, margin, funding terms, burn, runway, valuation, and fundraising status remain unknown.

Final Decision: Watch

The category may be venture-scale and the founders appear relevant. However, the 63/100 score, Conditional unicorn path, unassessable valuation, and limited evidence do not support DD. Product Hunt attention is not production adoption.

Upgrade Conditions

  • Five referenceable enterprise pilots converting into annual contracts.
  • At least $500,000 verified ARR with credible pipeline.
  • Material production agent volume and six-month retention.
  • Gross margin above 70% after gateway and support costs.
  • Verified security assurance and SOC 2 status.
  • Demonstrated multi-platform advantage with incumbent IAM integration.

Downgrade Conditions

  • Pilots fail to convert or usage remains shallow.
  • An incumbent wins the cross-platform layer through bundling.
  • A material security incident or misleading claim emerges.
  • Gateway costs or implementation prevent attractive margins.
  • Founder commitment changes or product activity declines.

Questions for Further Diligence

  1. How many pilots, paid customers, and production deployments exist, and what ARR/MRR do they represent?
  2. What are 30-, 90-, and 180-day organization and agent retention?
  3. How many agents and tool calls does the median customer manage?
  4. What are pilot conversion, sales-cycle length, ACV, and net revenue retention?
  5. Which channels create qualified opportunities beyond Product Hunt and YC?
  6. What gross margin remains after gateway compute, logs, implementation, and support?
  7. How are credentials isolated and rotated, and what is the validated SOC 2 status?
  8. Which frameworks and IAM integrations are production-grade today?
  9. Why does Decawork outperform Agent 365/Entra in mixed-stack enterprises?
  10. What are burn, runway, cap table, current valuation or SAFE cap, and round terms?
  11. What customer-action liabilities and insurance arrangements exist?
  12. What can the current team deliver over the next 12 months?

Sources