Okta’s Permiso Deal Signals a Shift Toward AI Agent Identity Security
Lead
Okta is moving deeper into the emerging market for securing AI agents and machine identities. The company has agreed to acquire Permiso Security, an AI identity security startup focused on detecting suspicious activity inside cloud environments. Okta did not disclose financial terms, but TechCrunch reports, citing a source familiar with the transaction, that the deal is valued at just under $200 million and is structured as an almost all-cash acquisition.
The transaction is expected to close in the third quarter of Okta’s fiscal 2027, subject to customary closing conditions. While the headline is an acquisition, the bigger story is the changing definition of identity security. Enterprises no longer need only to verify who logs in; they increasingly need to understand what authorized users, applications, and AI agents do after they gain access.
Key points
- Okta is adding identity threat detection and response: Permiso’s software helps security teams identify suspicious behavior in cloud environments, especially attacks that use stolen or compromised identities to move through infrastructure.
- The target is broader than human users: As companies deploy autonomous software, they must secure service accounts, applications, scripts, AI agents, and other non-human identities that can act across enterprise systems.
- Permiso has already expanded into AI agent security: In April, the startup introduced SandyClaw, a platform designed to analyze AI agent skills in a sandboxed environment and detect potentially malicious behavior before deployment.
- The valuation reflects demand in a rising category: Permiso has raised about $29 million to date. Its Series A round in April 2024 reportedly valued the company at about $80 million post-money, making the reported sub-$200 million acquisition price notable.
Why it matters
For Okta, the acquisition strengthens its push beyond access management and into a broader identity security layer. Traditional identity platforms have focused on authentication, single sign-on, and access policies. But in cloud environments, many breaches involve the misuse of valid credentials rather than a simple failure at the login gate.
AI agents make this challenge more urgent. They may hold permissions to call APIs, access cloud resources, or perform actions across multiple enterprise systems. Their behavior can be faster, more frequent, and less predictable than that of human users. If companies only verify access at the start of a session, they may miss harmful activity that occurs later under an apparently legitimate identity.
Permiso gives Okta additional capabilities in continuous monitoring and threat detection for both human and non-human identities. The deal also suggests that AI agent security is becoming a commercial priority for identity vendors. As autonomous tools move from pilots into production workflows, the market is likely to reward platforms that can not only authenticate identities, but also interpret and constrain what those identities do.
Source: TechCrunch AI
Comments
Checking sign-in status...
Loading comments...