Identity and access management (IAM) company Okta recently signed a definitive agreement to acquire Permiso Security, with the deal expected to close in Q3 of Okta’s 2027 fiscal year. While the exact terms of the deal have not been disclosed or confirmed by either company, it has been reported that the price is just under $200 million, almost all in cash. This deal will allow Okta’s identity strategy to grow beyond login and extend into behavior.
The Blind Spot Permiso Was Built to Close
The acquisition of Permiso fills an important gap in Okta’s existing functionality. Okta’s core products are designed to authenticate and authorize identities at login, not to monitor activity after access has been granted. This approach has lost effectiveness against rapidly evolving threats as technological trends in recent years have made the need for in-depth identity security even more acute. “As more organizations deploy and scale AI agents, security teams are facing an entirely new set of challenges that traditional defenses just weren’t built to handle,” says Nick Davis, Vice President of Product Management here at Okta.
Agentic AI tools introduce new risks after identity authentication, such as tool calls, sub-agents, and model context protocol (MCP) connections. The meteoric rise of AI agents and other non-human identities (NHIs) in enterprise environments has created a landscape that demands advances in identity security efforts. Permiso’s Universal Identity Graph links credentials to real-time activity across environments, offering more robust and thorough governance and monitoring.
What Okta Actually Gains
With this acquisition, Okta receives access to more than 2,500 research-derived signals across upwards of 70 identity partners. This will expand the company’s ability to discover risk factors including excessive privileges, anomalous behavior, violated policies, and potentially damaging actions. The company also benefits from gaining the SandyClaw sandbox, which enables the testing of agentic AI skills in an isolated environment in order to catch malicious behavior prior to deployment.
Autodesk, a provider of 3D design, engineering, and construction software, has already deployed Permiso Security for Identities and Agentic AI Identities. This early use of Permiso provides a proof point of the commercial use of the technology, though not independent validation of the product. A testimonial from Autodesk published by Permiso confirms the commercial deployment of the platform for agent discovery and monitoring, alongside other functions.
The Integration Question Mark
While this acquisition looks promising, much remains to be seen about how it plays out during closing and integration. Okta has not disclosed a timeline for merging Permiso’s detection capabilities into the existing stack. Okta’s AI Agents platform is still labeled as beta and early-access, presenting the question of how effectively the integration of Permiso’s technology will be carried out. The pricing, packaging, and status of Permiso’s availability as a standalone product all remain up in the air at this time.
A Category Racing Toward the Same Endpoint
Okta is not the only company making moves to consolidate identity and behavior security efforts. CrowdStrike’s recent addition of Continuous Identity for AI Agents is built on the capabilities gained in the company’s earlier acquisition of continuous identity leader SGNL. Similarly, Palo Alto Networks acquired CyberArk and folded it into the new Idira identity platform.
These three major vendors have all converged on real-time, behavior-based identity controls within months of each other. These moves are not isolated incidents, but strong indicators of security priorities and trends across the market.
What This Signals for Security Leaders
Defenders and security leaders can look to this growing trend to see that runtime identity monitoring is no longer a differentiator, but is becoming a minimum requirement for entry. Customers of these and similar companies should expect uncertainty regarding the roadmap as vendors continue to integrate rapid-fire acquisitions. The test over time will be whether these platforms are able to actually attribute and stop agent behavior in production.