AI News

Okta has agreed to acquire Permiso Security, a startup focused on identity threat detection in cloud environments, in a move that shows how quickly enterprise security is adapting to AI agents and other non-human identities. Okta did not disclose the price, but TechCrunch reported, citing a source with knowledge of the deal, that the transaction is valued at just under $200 million and is structured as an almost all-cash deal.

The strategic logic is clearer than the undisclosed purchase terms. According to TechCrunch’s reporting and Okta’s own statement to the outlet, the acquisition is meant to strengthen Okta’s ability to detect suspicious behavior after access has been granted, particularly across cloud infrastructure where AI agents, service accounts, and applications now act with growing autonomy. For builders and enterprise buyers, that matters because the old identity model of authenticating a user once at login is no longer enough when software entities can continuously take actions, chain tools, and move across systems.

Okta said the deal is expected to close in the third quarter of its fiscal 2027, subject to customary closing conditions. That timeline suggests the companies are still early in the integration process, but the direction is unmistakable: identity vendors are racing to secure not only people, but also the expanding population of machine-controlled actors inside enterprise environments.

Why Okta wants Permiso now

The deal lands at a moment when identity security is broadening from access control into ongoing behavior monitoring. Okta’s core business has long centered on verifying users and managing access. Permiso, by contrast, focuses on spotting suspicious actions after access is already in place, especially in cloud environments where attackers may use stolen credentials or compromised identities to move laterally.

That distinction is important in the AI era. As enterprises deploy AI agents to automate workflows, those agents often receive credentials, API access, and permissions to interact with internal tools. In practice, an AI agent can look less like a chat interface and more like a machine identity with meaningful operational power. If that identity is over-permissioned, hijacked, or behaves unexpectedly, the risk is not limited to an unauthorized login event. It becomes a continuous detection problem.

TechCrunch reported that Permiso has expanded its platform more recently to monitor AI agents and other machine identities. That gives Okta a way to position itself beyond workforce identity and deeper into runtime security for automated systems. Okta chief product officer Ely Kahn said in a prepared statement cited by TechCrunch that Permiso will extend the company’s “identity security fabric” with identity threat detection and response capabilities and add a threat research team.

The phrasing matters. Identity threat detection and response, often shortened in the market to a category like runtime identity monitoring, is increasingly where vendors are trying to differentiate as authentication and single sign-on become more mature. For Okta, buying Permiso appears to be a faster route into that segment than building all of the capability internally.

What Permiso brings to the deal

Permiso emerged from stealth in 2022, according to TechCrunch, and was co-founded by former FireEye executives Paul Nguyen and Jason Martin. The startup’s main pitch has been that modern attacks frequently rely on valid credentials rather than obvious malware signatures, making it necessary to detect abnormal use of trusted identities inside cloud systems.

That focus aligns with a broader industry shift toward monitoring cloud entitlements, service accounts, and machine activity rather than treating identity as a one-time gate. Permiso’s reported strength is in detecting attacks that use stolen or compromised identities to traverse infrastructure after gaining some form of legitimate access.

TechCrunch also pointed to a newer Permiso product called SandyClaw, introduced in April, which is designed to analyze AI agent skills in a sandboxed environment before deployment. The idea, as described in the report, is to identify malicious or risky behavior before an AI agent is released into production systems.

For product teams building agentic software, that is one of the more notable details in the acquisition. Much of the current enterprise AI market is focused on what agents can do: connect to apps, call tools, query data, and take actions. SandyClaw suggests a more security-centered question: what exactly has an agent been allowed to do, how can that behavior be tested in advance, and what controls exist once it is live?

If Okta integrates SandyClaw-like capabilities into its broader platform, it could offer enterprises a more complete stack spanning identity, access, behavior monitoring, and pre-deployment analysis for AI agents. That would be especially relevant for companies trying to operationalize AI agents without opening a new identity attack surface.

The price tag and what it says about the market

The acquisition price has not been officially confirmed by Okta. The strongest reporting available in this story comes from TechCrunch, which said a source with knowledge of the deal pegged the value at just under $200 million. TechCrunch added that an Okta spokesperson did not dispute the figure when asked, but the company declined to comment on specific terms.

That makes the financial details credible but still not formally disclosed by the buyer. The same report said Permiso has raised about $29 million to date, including an $18.5 million Series A round in April 2024 led by Altimeter Capital. People familiar with that financing told TechCrunch the round valued the startup at about $80 million post-money.

If those figures are accurate, the sale would represent a significant markup from the last reported valuation, though not an extreme one by historic security-market standards. More importantly, it shows there is real acquisition demand for startups that can tie cloud detection to identity and AI-specific controls.

The deal also underlines how AI security is fragmenting into subcategories. Some vendors are focused on model security, prompt injection, and data leakage. Others are concentrating on application governance. Permiso sits in a different but increasingly important layer: securing AI agents as operational identities inside enterprise systems.

Evidence, claims, and what remains unverified

This story rests primarily on TechCrunch’s reporting, supplemented by Okta’s comments to that outlet. The confirmed elements, based on the available evidence, are that Okta agreed to acquire Permiso Security, the companies expect the deal to close in the third quarter of Okta’s fiscal 2027, and Okta says the acquisition will add identity threat detection and response capabilities.

Several other points should be treated more cautiously. The roughly $200 million valuation is source-based reporting from TechCrunch, not an announced figure from Okta. The claim that the deal is almost all-cash also comes from that same source-based reporting. Likewise, the $80 million post-money valuation attached to Permiso’s 2024 Series A is attributed by TechCrunch to people familiar with the financing, not to public company filings in the evidence provided here.

Permiso’s positioning around AI agents and SandyClaw is drawn from TechCrunch’s description of the startup’s product line. Those are product claims and company positioning statements, not independently verified performance benchmarks. There are no adoption metrics, customer counts, revenue numbers, or third-party test results in the source material provided.

That absence matters. The strategic rationale for the acquisition is plausible and consistent with enterprise security trends, but buyers should not read the available evidence as proof that Permiso has already become a dominant platform for AI agent protection. The current record supports a more limited conclusion: Okta believes the capability is strategically important enough to buy.

What this means for enterprise AI and security teams

For enterprise buyers, the headline is not just that Okta is buying a startup. It is that identity security is being redefined around machine action, not just human authentication. As AI agents become embedded in finance, support, engineering, and operations workflows, they increasingly need access to systems such as cloud consoles, developer tools, collaboration suites, and internal APIs.

That changes procurement priorities. Security teams evaluating enterprise AI deployments will likely ask harder questions about how AI agents are permissioned, monitored, and investigated. Builders may need to design workflows where AI agents receive narrower scopes, shorter-lived credentials, stronger logging, and clearer approval boundaries before taking sensitive actions.

For Okta customers, the acquisition could eventually mean a more integrated way to connect identity controls with cloud investigation and response. That is especially relevant if enterprises want a single policy layer across employees, contractors, applications, and AI agents. However, until the deal closes and product plans become clearer, it is too early to assume deep platform integration or near-term roadmap delivery.

The competitive signal is broader. Vendors across enterprise AI, cloud security, and identity management will see this as confirmation that AI agents are becoming a first-class security object. Startups building around AI agents, machine identities, or cloud detection may find a more receptive market among large platform companies looking to fill gaps quickly.

What to watch next

First, watch for Okta to explain how Permiso Security will be integrated into the broader Okta platform. Product packaging, telemetry integration, and whether capabilities are embedded or sold separately will determine how meaningful the acquisition is for current customers.

Second, look for more concrete disclosures about support for AI agents and machine identities. Enterprises will want details on which agent frameworks, cloud environments, and workflow tools are covered, and whether protections extend from detection into policy enforcement.

Third, monitor whether SandyClaw remains a distinct product or becomes part of a broader Okta security workflow. Pre-deployment testing for agent skills could become a useful control point if enterprises continue moving from chatbots toward operational automation.

Finally, keep an eye on competitors. If identity and cloud security vendors respond with acquisitions or partnerships of their own, that would reinforce the idea that this is becoming a defined segment inside enterprise AI security.

Creati.ai perspective

This acquisition makes sense less as a conventional security tuck-in and more as a sign that AI deployment is changing the meaning of identity. In enterprise software, AI agents are turning permissions into active execution power. That creates a security problem that sits between IAM, cloud detection, and application governance. Okta appears to be buying into that intersection before it becomes table stakes.

The bigger lesson for builders is operational: every useful AI agent becomes a security principal. Teams that treat agents as simple UX features will miss the harder design work around scopes, observability, and abuse detection. Okta’s move on Permiso Security suggests that those controls are moving from niche concern to core platform requirement across enterprise AI.

Featured

Okta to acquire Permiso as identity security shifts toward AI agents and machine accounts

Okta is acquiring Permiso in a deal TechCrunch reports is worth about $200 million, adding identity threat detection for AI agents and machine accounts.