
Okta has agreed to acquire Permiso Security, an AI-focused identity security startup, in a deal that underscores the growing importance of protecting machine identities and AI agents in enterprise environments. The transaction is valued at just under $200 million, according to a person familiar with the matter, and is structured as an almost all-cash deal. Okta did not disclose the terms publicly, and a spokesperson declined to comment on the specific valuation when reached.
The acquisition is expected to close in the third quarter of Okta's fiscal 2027, subject to customary closing conditions. By bringing Permiso into its portfolio, Okta is positioning itself to extend its identity management capabilities beyond the traditional login moment, moving into continuous monitoring of what users, applications, and AI agents do after they have been granted access to a network.
Identity management has long centered on verifying who a user is at the point of access. But enterprises are increasingly realizing that authentication alone is not enough. Once credentials are compromised, attackers can move laterally through cloud environments, using legitimate identities to hide their activity. Permiso was founded to address this gap, specializing in identity threat detection and response, or ITDR. The startup emerged from stealth in 2022 and has built a platform that helps security teams identify suspicious behavior in cloud infrastructure after access has been granted.
Permiso was co-founded by Paul Nguyen and Jason Martin, both former FireEye executives. Their experience in threat intelligence and incident response is reflected in the startup's focus on detecting attacks that rely on stolen or compromised identities. Instead of only protecting the perimeter, Permiso's technology continuously analyzes identity activity and flags anomalies that could indicate a breach.
The Rise of AI Agents and Machine Identities
The acquisition comes at a time when enterprises are rapidly deploying AI agents and automation tools across their operations. These software-based entities operate with machine identities that must be managed, secured, and monitored just like human identities. But the scale and behavior of machine identities differ significantly from human users, creating new challenges for security teams.
AI agents can execute tasks autonomously, access sensitive data, and interact with other systems. If an agent's credentials are stolen or its behavior is hijacked, the potential for damage is significant. Traditional identity tools are not always equipped to understand what normal behavior looks like for an AI agent, making it easier for malicious actors to abuse those identities without detection.
Permiso has been expanding its platform to address this emerging risk. In April 2026, the startup introduced SandyClaw, a platform designed to analyze AI agent skills in a sandboxed environment. The goal is to identify malicious behavior before an agent is deployed into a production environment. This proactive approach is intended to give security teams visibility into what an AI agent is designed to do, and whether it contains hidden instructions or dangerous capabilities.
SandyClaw represents a growing category of security tools focused on AI supply chain risk. As more enterprises integrate third-party AI agents and large language models into their workflows, they need ways to verify that these components are safe. Permiso's approach of analyzing agent skills in an isolated environment provides a layer of protection that is increasingly essential.
Okta's Strategic Bet on Non-Human Identities
Okta's decision to acquire Permiso is part of a broader strategy to secure non-human identities, a category that includes bots, service accounts, APIs, and AI agents. Okta has been investing heavily in this area, as the number of machine identities in enterprise environments now outnumbers human identities by a significant margin. Managing these identities requires a different set of controls, particularly when it comes to detecting anomalies and responding to threats.
The company's chief product officer, Ely Kahn, said in a prepared statement that Permiso will extend Okta's identity security fabric with proven identity threat detection and response capabilities. He also praised Permiso's threat research and security team, saying the team will advance Okta's threat detection and prevention capabilities.
Founders and Funding Background
Permiso has raised approximately $29 million to date. In April 2024, the startup announced an $18.5 million Series A round led by Altimeter Capital. According to people familiar with the financing, that round valued the Palo Alto-based company at around $80 million on a post-money basis. The acquisition price of just under $200 million therefore represents a significant multiple over that valuation, reflecting the growing demand for AI identity security solutions.
The company's founders bring deep expertise in cybersecurity. Paul Nguyen previously served as vice president of engineering at FireEye, where he worked on cloud security and threat detection products. Jason Martin, the other co-founder, was a senior director of engineering at FireEye and led the development of the company's network security and forensics platforms. Their combined experience informed Permiso's early focus on cloud identity threats, a space that was still relatively nascent when the company was founded.
Permiso's platform is designed to work across major cloud providers, including AWS, Microsoft Azure, and Google Cloud. It ingests identity logs and activity data from multiple sources, then applies behavioral analytics and threat intelligence to identify risky actions. The platform also supports automated response actions, allowing security teams to revoke access or isolate compromised identities quickly.
Market Context and Competitive Landscape
The identity threat detection and response market is becoming increasingly crowded. Legacy security vendors and identity providers are all looking to add ITDR capabilities to their platforms. Okta's acquisition of Permiso is a clear signal that the company intends to be a leader in this space, rather than relying solely on partnerships or homegrown development.
The move also reflects a broader industry shift toward integrating security and identity functions. As organizations adopt zero-trust architectures, the ability to continuously verify identity and behavior becomes critical. ITDR tools play a central role in this model, helping organizations detect and respond to identity-based attacks in real time.
Analysts have noted that the rise of generative AI is accelerating the need for machine identity security. AI agents often require broad permissions to perform their tasks, making them attractive targets for attackers. If an AI agent is compromised, it can be manipulated into performing unauthorized actions, exfiltrating data, or disrupting business processes. The ability to monitor and secure these agents is not a luxury but a necessity for enterprises that want to adopt AI safely.
Integration Plans and Customer Impact
Okta has not yet shared detailed integration plans for Permiso's technology and team. However, the company has said that Permiso's capabilities will be folded into Okta's identity security fabric. This suggests that Okta customers will eventually have access to Permiso's ITDR functionality as part of their existing Okta deployments, rather than needing to purchase a separate product.
The acquisition could also give Okta a stronger foothold in the rapidly growing market for AI security. By acquiring a startup that has already built purpose-built tools for AI agent monitoring, Okta is positioning itself as a one-stop shop for identity, machine identities, and AI agent security.
Okta's existing product suite includes workforce identity, customer identity, and access management solutions. Adding Permiso's ITDR technology would allow Okta to offer continuous monitoring and threat detection across the entire identity lifecycle. This is particularly important as organizations move away from legacy VPNs and perimeter-based security models toward cloud-first architectures.
The deal is expected to close in the third quarter of Okta's fiscal 2027. Until then, Permiso will continue to operate as an independent company, serving its existing customers. The founders and employees are expected to join Okta once the transaction closes, bringing their specialized knowledge in cloud and identity security to the larger company.
Okta's acquisition of Permiso is a significant development in the identity security space. It underscores the growing importance of protecting not just human users, but also the increasingly complex ecosystem of AI agents, bots, and machine identities that are being deployed across enterprises. With the deal, Okta is making a clear bet that the future of identity security will be defined by continuous intelligence, automated response, and the ability to understand and protect the behavior of every identity in a network.
Source:TechCrunch News
