
Okta on Thursday agreed to acquire AI identity security startup Permiso Security, betting that demand for protecting AI agents and other machine identities will grow as enterprises deploy autonomous software across their operations. The identity management company did not disclose the terms of the transaction, but TechCrunch has learned that the acquisition is valued at just under $200 million and is structured as an almost all-cash deal, according to a source with knowledge of the deal. A spokesperson for Okta did not dispute the $200 million figure when Okta CEO Todd McKinnon was asked for comment, but the company would not comment on specifics of the deal terms.
The deal is expected to close in the third quarter of Okta&8217;s fiscal 2027, subject to customary closing conditions. That timeline suggests the company is moving quickly to integrate Permiso&8217;s technology and team ahead of what industry analysts expect to be a surge in enterprise adoption of AI-driven workflows and machine identities.
Why Okta is buying Permiso
Okta&8217;s move to buy Permiso comes as identity management companies seek to expand beyond verifying users at login to continuously monitoring what users, applications, and AI agents do once they gain authorized access to a network environment. That shift has intensified competition to secure machine identities as enterprises embed AI deeper into everyday operations.
Traditional identity and access management tools have largely focused on authentication at the perimeter&8212;ensuring that the person or service requesting access is who and what they claim to be. But with the rise of cloud-native architectures and AI agents that operate autonomously, security teams increasingly need visibility into what happens after access is granted. Permiso addresses this gap by providing identity threat detection and response, or ITDR, capabilities that continuously analyze activity across cloud environments and detect anomalous behavior that could indicate a compromised identity or a malicious insider.
By adding Permiso&8217;s capabilities, Okta is positioning itself to offer a more comprehensive identity security fabric that spans the entire lifecycle of an identity, from initial authentication to ongoing behavior monitoring. This is particularly important for AI agents, which are often granted broad permissions to execute tasks and may be exploited by attackers to move laterally within an organization&8217;s infrastructure.
Permiso&8217;s origins and technology
Permiso, which emerged from stealth in 2022, develops software that helps security teams spot suspicious activity in cloud environments after users or applications have been granted access. More recently, the startup has expanded its platform to monitor AI agents and other machine identities.
The company was co-founded by Paul Nguyen and Jason Martin, both former FireEye executives. FireEye is known for its advanced threat intelligence and incident response capabilities, and Nguyen and Martin brought that expertise to bear on the identity security problem. Permiso specializes in detecting attacks that use stolen or compromised identities to move through cloud infrastructure, a technique often referred to as “identity-based attacks.”
In April, the startup introduced SandyClaw, a platform designed to analyze AI agent skills in a sandboxed environment to identify malicious behavior before those agents are deployed into production. This is a growing concern for enterprises: AI agents are being given access to sensitive data and systems, and if those agents are compromised or maliciously configured, they could cause significant damage. SandyClaw aims to give security teams a way to test AI agents without putting their organization at risk.
Permiso&8217;s technology is built on a foundation of deep visibility into cloud identity behavior. It can ingest data from a wide range of sources, including cloud service provider logs, identity provider logs, and application logs, then apply machine learning and analytics to identify anomalies. This approach enables security teams to respond to threats in real time rather than after the fact, which is critical in a landscape where attackers are increasingly using automated tools to compromise identities.
Funding and valuation
Permiso has raised about $29 million to date, including an $18.5 million Series A round in April 2024 led by Altimeter Capital. People familiar with the financing said the Series A valued the Palo Alto-based startup at about $80 million on a post-money basis. That means the $200 million acquisition price represents a significant return for investors, reflecting the strategic premium that Okta is willing to pay to gain a foothold in the emerging AI identity security market.
The company&8217;s previous funding includes a seed round that was not publicly announced in detail, but the combination of seed funding and the Series A has been sufficient to build out a robust product portfolio and attract enterprise customers. Permiso&8217;s customer base is said to include large organizations in the technology, financial services, and healthcare sectors, though the company has not publicly disclosed a comprehensive customer list.
Okta&8217;s product integration plans
Okta&8217;s chief product officer, Ely Kahn, said in a prepared statement that the acquisition will advance the company&8217;s threat detection and prevention capabilities. “Permiso will extend Okta&8217;s identity security fabric with proven identity threat detection and response capabilities, and an incredible threat research and security team that will advance Okta&8217;s threat detection and prevention capabilities,” Kahn said.
We expect that Permiso&8217;s technology will be integrated into Okta&8217;s existing identity cloud platform, which already offers a range of solutions including single sign-on, multi-factor authentication, and lifecycle management. The addition of Permiso&8217;s ITDR capabilities will likely enable Okta customers to monitor for suspicious activity across their AWS, Azure, and Google Cloud environments, as well as on-premises infrastructure, all from a single console.
Okta has been investing heavily in AI-driven security features in recent quarters. The company has rolled out machine learning-based risk scoring and adaptive authentication capabilities, but Permiso brings a more specialized and enterprise-grade set of detection and response tools. By folding Permiso&8217;s threat research team into Okta, the company will gain the ability to stay ahead of emerging attack techniques that target machine identities and AI agents.
The broader market for AI identity security
The identity security market is undergoing a significant transformation as organizations increasingly rely on non-human identities, such as service accounts, APIs, and AI agents. Some industry analysts estimate that machine identities now outnumber human identities by significant margins in large cloud environments, and each of those machine identities represents a potential vector for attack.
Traditional security tools were not designed to handle the scale or behavior patterns of machine identities. For example, an AI agent that is tasked with processing invoices may interact with dozens of other services and databases, creating a complex web of activity that would be difficult for a human security analyst to review manually. Automating the monitoring and analysis of these interactions is essential, and that is exactly what Permiso&8217;s platform is built to do.
Okta is not the only company moving into this space. Major cloud providers and security vendors have been expanding their own identity threat detection offerings, and startups in the ITDR space have attracted significant venture capital investment in recent years. But Okta&8217;s acquisition of Permiso gives it a differentiated position because it combines the breadth of its identity management platform with the depth of Permiso&8217;s specialized detection engine.
Furthermore, the timing of the deal appears strategic. Many enterprises are currently in the early stages of deploying generative AI and AI agents across their operations, and they are realizing that securing these new workloads is different from securing traditional applications. AI agents often require broad permissions to perform tasks, and they may act in ways that are difficult to predict. This creates a need for security controls that can adapt to changing behavior patterns and that can detect when an agent has been hijacked or misused.
Permiso&8217;s SandyClaw product is particularly well-suited to this challenge, as it allows organizations to simulate AI agent behaviors in a controlled environment and analyze the underlying skills that agents are equipped with. This can help identify malicious or flawed capabilities before they cause harm, effectively serving as a security testing tool for AI deployments.
With the acquisition, Okta is also gaining a team of threat researchers who have deep experience in identity-based attacks and cloud security. This team will likely work alongside Okta&8217;s existing security research organization to develop new detection rules and threat intelligence feeds for customers.
As the deal awaits regulatory and shareholder approval, Okta is positioning itself to be a leader in what is becoming a critical area of enterprise security. The company has traditionally been known for its customer-facing identity products, but this acquisition signals an ambition to be a deeper security provider, one that protects the entire identity infrastructure of an organization, including the rapidly growing number of machine identities and AI agents.
Source:TechCrunch News
