Okta is set to acquire cloud-native identity security platform Permiso, adding threat detection for human, non-human and AI agent identities across the identity lifecycle.

Okta has signed a definitive agreement to acquire Permiso Security, a cloud-native identity security platform that detects and defends against threats to human, non-human and agentic identities across multi-cloud environments. The deal is intended to extend Okta’s platform with dedicated capabilities for identifying and responding to identity-based threats throughout the identity lifecycle.

According to the company, Permiso’s identity risk signals, behavioral analytics and threat detection capabilities will be integrated into the Okta platform, giving organizations broader tools to uncover identity-related risks, remediate vulnerabilities and excessive permissions, and defend against attacks across their technology stacks.

The acquisition comes as the rapid growth of human, non-human and AI agent identities creates new security challenges for enterprises. Citing its own research, Okta said 58 percent of executives reported experiencing an AI-related security incident or near-miss over the past year. As attackers increasingly rely on post-authentication techniques to bypass conventional defenses, the company argues that security teams need a unified approach to identity in order to protect their organizations.

“We are excited to welcome Permiso to Okta. Together, we will help organizations secure their ‘agentic enterprises,’ where humans, applications, service accounts and AI agents work side by side,” said Ely Kahn, Chief Product Officer at Okta. He added that Permiso will extend Okta’s identity security architecture with proven identity threat detection and response capabilities, and that its threat research and security team will further advance Okta’s ability to detect and prevent threats.

Jason Martin, co-founder of Permiso, said the company’s work has been driven by a single goal: helping customers stay ahead of identity-based threats in an increasingly complex security landscape. “Joining the leading, neutral identity provider means our work will now reach far more organizations than we could have on our own,” Martin said.

With the acquisition, Okta is expanding its reach beyond identity management into the core security operations center, or SOC, positioning the company to work more closely with enterprise CISOs on evolving SecOps challenges. Permiso’s P0 Labs research unit will add to Okta’s research capacity, providing insight into suspicious post-authentication behavior across cloud and AI environments. Combined with Okta Threat Intelligence, these capabilities are expected to strengthen the platform’s detection and threat-hunting functions as well as its product roadmap across the identity lifecycle.

Okta expects the transaction to close in the third quarter of its fiscal year 2027, subject to customary closing conditions. The company said the deal is not expected to affect the financial guidance it issued on May 27, 2026.

The move underscores a broader trend among identity and access management vendors to fold threat detection and response capabilities directly into their platforms, as enterprises grapple with securing a growing and increasingly diverse population of digital identities — including those generated by autonomous AI agents.

Permiso has focused on monitoring identities after they have already authenticated into corporate systems — an area security teams have historically struggled to cover with conventional identity and access management tools. Its platform is designed to correlate activity across cloud infrastructure, SaaS applications and AI services to flag anomalous or malicious behavior tied to a given identity, whether that identity belongs to an employee, a machine, a service account or an autonomous software agent.

For Okta, the acquisition represents a further step in a strategy of extending its identity platform into adjacent security disciplines. Rather than positioning itself purely as an access and authentication provider, the company has been building out capabilities that overlap with security operations, threat intelligence, and detection and response — areas traditionally associated with SOC-focused vendors. By absorbing Permiso’s technology and research team, Okta aims to offer customers a single vantage point spanning the full identity lifecycle, from provisioning and authentication through ongoing monitoring and incident response.

The transaction also reflects wider pressure across the enterprise security market to address identity as a primary attack surface. Credential theft, session hijacking and privilege escalation have repeatedly featured as elements in major breaches, while the rise of generative AI tools and autonomous agents has added a new category of non-human identities that require oversight. Okta’s emphasis on what it calls “agentic enterprises” — organizations in which people, applications, service accounts and AI agents operate side by side — signals how the company expects identity security requirements to evolve in the coming years.

Terms of the acquisition, including the purchase price, were not disclosed. Okta said further details on product integration timelines will be shared closer to the deal’s expected close.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner