Okta Acquires Permiso for ~$200M to Secure AI Agents and Non-Human Identities
Okta is acquiring cloud identity security startup Permiso for approximately $200 million, adding identity threat detection capabilities focused on AI agents and non-human identities to its platform.
Original sourceOkta has agreed to acquire Permiso, a startup specializing in identity threat detection and response, for roughly $200 million. The deal is aimed squarely at the growing problem of securing non-human identities — service accounts, API keys, OAuth tokens, and increasingly, autonomous AI agents — that now vastly outnumber human users in enterprise cloud environments.
Permiso built its platform around detecting anomalous behavior tied to these non-human identities across cloud providers including AWS, Azure, and GCP. Rather than focusing on perimeter defense, Permiso monitors identity-layer activity to surface things like credential abuse, privilege escalation, and lateral movement that traditional security tools miss because they're designed around human login patterns.
The acquisition reflects a broader shift in enterprise security posture as AI agents get provisioned with real permissions and access to production systems. When an AI agent can read customer data, write to databases, or call external APIs autonomously, the identity it acts under becomes a critical attack surface. Okta, whose core business is identity management, is betting that owning the detection layer — not just the provisioning layer — is where the next wave of security budget flows.
The deal is expected to integrate Permiso's capabilities into Okta's Identity Security Posture Management offerings. For enterprises already on Okta, the pitch is consolidation: one platform that both manages and monitors identities, human or otherwise. The $200 million price tag is modest by recent acquisition standards, suggesting Okta moved quickly on a capability gap before a competitor could.
Panel Takes
The Skeptic
Reality Check
“The non-human identity security space is real — CrowdStrike, Wiz, and SentinelOne all have or are building plays here, and Permiso was a legitimate technical player, not vaporware. The risk is that Okta's acquisition track record is mixed: Auth0 took years to actually integrate and still feels like two products wearing the same badge. If Permiso's detection engine gets absorbed into Okta's roadmap bureaucracy, the answer to 'what kills this in 12 months' is straightforward: enterprise procurement teams will just wait for the Wiz version.”
The Futurist
Big Picture
“The falsifiable bet here is: by 2028, non-human identities will be the primary attack surface in enterprise cloud environments, and the company that owns identity provisioning will be expected to own identity threat detection too. That thesis is already stress-tested — Gartner flagged NHI security as a top priority two years running, and every major breach story now involves a compromised service account or stolen API token. The second-order effect worth watching is how this shifts SIEM and SOAR vendors: if Okta can correlate identity events natively, it starts eating the log-aggregation layer that companies like Splunk have owned. Okta isn't just buying a detector — it's positioning for the identity data moat.”
The Founder
Business & Market
“The buyer here is the CISO, and the budget comes from cloud security — one of the few lines that didn't get cut in 2025. At $200M, Okta is paying a reasonable multiple for a capability that would otherwise take two-plus years to build credibly, and the moat is real: Permiso's detection models are trained on identity behavior data that Okta's provisioning pipeline will now feed at scale, creating a data flywheel competitors can't easily replicate. The stress test is whether Okta can actually sell this as an add-on to existing customers without re-platforming them — if it requires a new SKU with a six-month procurement cycle, the expand revenue story falls apart before it starts.”
The PM
Product Strategy
“The job-to-be-done is precise and currently underserved: detect when a non-human identity — an AI agent, a service account, an OAuth token — is behaving anomalously before it causes a breach. Okta already owns the provisioning half of that workflow, so the completeness argument is strong: customers won't need to dual-wield Okta plus a separate NHI security tool if the integration actually ships. The product risk is that 'detect' without 'respond' is half a job — if Permiso's capabilities land as dashboards and alerts inside the Okta console but don't close the loop into automated remediation, security teams will still reach for a separate workflow tool and the consolidation pitch collapses.”