In short
Okta has agreed to acquire Permiso Security for a reported just-under-$200 million, adding cloud threat detection and AI agent monitoring to its identity platform. The deal reflects rising concern over machine identities as enterprises deploy more autonomous software.
- Okta agreed to buy Permiso Security in a deal reported at just under $200 million.
- Permiso focuses on detecting suspicious activity after access is granted in cloud environments.
- The startup has expanded into monitoring AI agents and other machine identities.
- Okta says the acquisition will strengthen its identity security and threat response capabilities.
- The deal highlights growing enterprise concern about autonomous software and machine-identity risks.
Okta has agreed to buy AI identity security startup Permiso Security in a deal TechCrunch says is worth just under $200 million, underscoring how quickly enterprise security is shifting toward protecting AI agents and other machine identities. The acquisition is designed to help Okta monitor what authorized users, applications and autonomous systems do after they enter a network, not just verify who they are at the door.
The transaction, announced Thursday, is expected to close in the third quarter of Okta’s fiscal 2027, pending customary closing conditions. Okta did not disclose financial terms, but a source familiar with the matter told TechCrunch that the deal is structured as an almost entirely cash purchase.
Why this acquisition matters
The Permiso deal is a sign that identity security vendors are racing to keep up with a new reality in corporate computing: software is no longer just something people use, but something that acts on its own. As companies deploy AI agents to perform tasks across cloud systems, the question for security teams is changing from “Who signed in?” to “What is this identity doing right now?”
Okta, best known for login and access management, has increasingly been positioning itself as a broader identity security platform. Permiso gives it a way to extend that pitch into continuous monitoring and threat detection, especially in environments where machine-to-machine activity can blend into normal cloud traffic.
What Okta is buying
Permiso Security, which came out of stealth in 2022, builds software that helps security teams identify suspicious behavior in cloud environments after access has already been granted. That focus is increasingly important because many modern attacks do not begin with an obvious breach of the front door. Instead, attackers may hijack legitimate credentials and then move quietly through cloud infrastructure using authorized pathways.
More recently, the startup expanded its platform to cover AI agents and other non-human identities. It also introduced SandyClaw in April, a system that evaluates AI agent capabilities in a sandbox before deployment to uncover potentially harmful behavior before the software is turned loose in production.
Permiso was founded by former FireEye executives Paul Nguyen and Jason Martin, both of whom bring experience in enterprise threat detection and incident response. The company’s core value proposition is straightforward: find signs of identity abuse early, while cloud access is active and before attackers can fully exploit it.
How the deal fits into the security market
Identity security has traditionally centered on authentication, permissions and access governance. But that model is no longer enough on its own, because cloud systems and AI tools can continue acting long after an initial login. That has pushed security vendors toward what industry watchers often describe as “post-authentication” visibility — constant monitoring of activity rather than a one-time gate check.
For Okta, acquiring Permiso is a way to deepen its technical stack in one of the fastest-growing corners of cybersecurity. The company is not just adding another product; it is buying expertise in detecting identity-based threats that are increasingly common in cloud-first workplaces.
That shift is especially relevant as enterprises adopt AI agents to handle internal workflows, data retrieval and cross-platform actions. Each agent needs credentials, permissions and oversight. Each of those requirements creates another point of risk.
How does Permiso’s technology work?
Permiso’s technology watches for behavior that deviates from expected patterns once an identity has access to cloud resources. In practice, that means tracking signs of misuse such as unusual privilege escalation, anomalous movement across systems, or activity consistent with compromised credentials.
The company has also moved into agent-specific monitoring because AI systems introduce a new type of operational challenge. An AI agent may be given broad permissions to complete tasks autonomously, but broad permissions also create opportunities for misuse, whether by design flaws, prompt manipulation or malicious repurposing.
Permiso’s sandboxing approach through SandyClaw adds another layer: it allows teams to inspect an agent’s skill set and potential behavior in isolation before deployment. That kind of pre-release analysis is becoming more attractive as organizations try to balance automation gains with containment.
What Okta said about the purchase
Okta framed the acquisition as an expansion of its broader identity security strategy. In a prepared statement, chief product officer Ely Kahn said Permiso would add identity threat detection and response capabilities to Okta’s security fabric and strengthen the company’s ability to identify and stop threats.
“Permiso will extend Okta’s identity security fabric with proven identity threat detection and response capabilities, and an incredible threat research and security team that will advance Okta’s threat detection and prevention capabilities,” Kahn said.
The emphasis on both technology and personnel is notable. In cybersecurity acquisitions, teams with deep research expertise can be as valuable as the products themselves, especially when threat models are changing as quickly as they are in AI security.
How much did Okta pay?
The companies did not publicly disclose a price, but TechCrunch reported that the acquisition value is just under $200 million. A source with knowledge of the deal said the structure is almost entirely cash, and a spokesperson for Okta did not dispute that figure when asked, while declining to discuss the terms.
For context, Permiso had raised roughly $29 million prior to the deal. Its latest known financing was an $18.5 million Series A in April 2024 led by Altimeter Capital. People familiar with that round said the company was valued at around $80 million post-money, which suggests Okta is paying a substantial premium to secure the startup and its capabilities.
Permiso’s funding and valuation history
Permiso’s fundraising profile helps explain why the acquisition is drawing attention. The startup raised relatively modest capital by cybersecurity standards, then appears to have achieved a sizable exit in a market where identity security remains a strategic priority.
| Milestone | Date | Details |
|---|---|---|
| Stealth launch | 2022 | Permiso emerged as an identity security startup focused on cloud threat detection |
| Series A | April 2024 | $18.5 million led by Altimeter Capital |
| Post-money valuation | April 2024 | About $80 million, according to people familiar with the round |
| Acquisition announcement | July 2026 | Okta agreed to acquire Permiso |
| Reported purchase price | July 2026 | Just under $200 million, according to a source |
| Expected close | Q3 fiscal 2027 | Subject to closing conditions |
Why AI agents are now a security priority
AI agents are becoming a security priority because they combine autonomy with access. Unlike a simple chatbot, an agent can take actions across tools, systems and cloud services, often using credentials that let it read data, move files or trigger business processes.
That makes the old perimeter model less useful. Security teams can no longer rely only on blocking unauthorized logins. They also need to know whether an authenticated machine identity is behaving in a way that matches its purpose.
What makes machine identities risky?
Machine identities are risky because they are often granted broad permissions, used at scale, and hard to distinguish from legitimate automation once they are inside a system. If attackers steal a token or compromise an account used by software, they can exploit that identity to move laterally with less friction than they would face against a human user.
That is why the market is shifting toward identity threat detection and response tools that can recognize abnormal behavior patterns in real time.
Who benefits from this shift?
Enterprises benefit if they can identify malicious automation before it causes damage. Security vendors benefit if they can provide broader visibility across users, workloads and AI systems. And platform providers such as Okta benefit if they can move up the stack from access management into threat detection and response.
How Okta is positioning itself
Okta’s core business has long been centered on identity and access management, but the company has been expanding its security ambitions for several years. Buying Permiso helps it reach beyond the login event and into continuous inspection of identity behavior.
That is important because modern enterprises are not just managing employees anymore. They are managing contractors, applications, scripts, service accounts and AI agents — all of which may need access, all of which may be abused, and all of which can produce security blind spots.
The acquisition also reflects a broader industry trend: identity is increasingly being treated as the control plane for cybersecurity. If a company can understand and govern identities well, it can often detect threats earlier and reduce the blast radius of an intrusion.
What happens next?
The deal still needs to clear standard closing steps before it becomes final in Okta’s third fiscal quarter of 2027. After that, the practical challenge will be integration: folding Permiso’s threat detection capabilities and research team into Okta’s product line without losing the speed and focus that made the startup attractive in the first place.
If the integration goes well, Okta could emerge with a stronger offering for customers who want one platform to manage both access and post-access monitoring. That would put the company in a better position as AI agents become more common across enterprise workflows.
The acquisition also signals that the cybersecurity market is already moving beyond the novelty of AI adoption and into the harder work of controlling it. Enterprises may be eager to automate, but they are equally aware that every new autonomous system widens the attack surface.
Key facts at a glance
- Buyer: Okta
- Target: Permiso Security
- Reported price: Just under $200 million
- Deal structure: Almost all cash, according to a source
- Expected closing: Third quarter of fiscal 2027
- Permiso funding: About $29 million total
- Latest round: $18.5 million Series A in April 2024
- Latest known valuation: About $80 million post-money
The bigger cybersecurity picture
Acquisitions like this are increasingly about anticipation rather than reaction. Buyers are not simply shopping for current revenue; they are looking for capabilities that will matter more as AI systems become embedded in ordinary work. The companies that can identify, govern and defend machine identities may have a major advantage in the next phase of enterprise security.
For Okta, the Permiso acquisition suggests a deliberate bet: that the next wave of identity spending will not just be about humans signing in, but about every software entity that can act, decide or move data inside a company’s environment. That is a larger market, a more complex market, and potentially a far more important one.
As enterprises deploy AI agents more broadly, security teams will need new tools to inspect behavior continuously and respond quickly when something looks wrong. Okta is now paying to be part of that answer.
Frequently asked questions
What is Okta buying Permiso for?
Okta is buying Permiso to expand its identity security platform into continuous threat detection and response. The goal is to help customers monitor what users, applications and AI agents do after they gain access, which is becoming more important as autonomous software spreads.
How much is Okta paying for Permiso?
Okta is reportedly paying just under $200 million. TechCrunch said the acquisition is mostly cash, and Okta did not confirm the exact figure but also did not dispute the reported valuation when asked.
Why is AI identity security becoming important?
AI identity security is becoming important because AI agents and machine accounts can act inside enterprise systems with real permissions. If those identities are stolen, misconfigured or abused, attackers may move through cloud environments using legitimate access rather than obvious malware.
What does Permiso do?
Permiso builds software that detects suspicious behavior in cloud environments after access has already been granted. It also monitors AI agents and other machine identities, and it launched SandyClaw to test agent behavior in a sandbox before deployment.
When will the Okta-Permiso deal close?
The deal is expected to close in the third quarter of Okta’s fiscal 2027, assuming customary closing conditions are satisfied. That means the transaction still needs to pass the usual legal and operational steps before it is finalized.









