Companies

Okta Pays About $200M for Permiso to Secure AI Agents

Okta is acquiring Permiso Security for roughly $200 million, betting that non-human identity security becomes the dominant enterprise problem as agents spread.

Faruk TalmaçJuly 30, 20263 min read4 views
Okta Pays About $200M for Permiso to Secure AI Agents

Forty-five to one. That is how far non-human identities already outnumber human ones in the average enterprise, and agentic AI is widening the gap faster than identity teams can govern it. Okta just put roughly $200 million behind the view that this ratio is the next major security problem.

The identity management company announced on July 30 that it has signed a definitive agreement to acquire Permiso Security, an AI identity security startup, in a deal that is almost entirely cash.

The numbers behind the deal

Permiso is based in Palo Alto and had raised roughly $29 million in total. Its $18.5 million Series A in April 2024, led by Altimeter Capital, valued the company at about $80 million post-money.

Going from an $80 million valuation to a just-under-$200 million exit in a little over two years is a strong outcome for a company at that funding stage. The transaction is expected to close in the third quarter of Okta's fiscal 2027.

What Okta is actually buying

Technically, Permiso brings identity threat detection: spotting when an identity starts behaving differently from its established pattern across cloud environments. Okta gets that capability folded into its existing identity fabric.

Strategically, the target is not employee accounts. Okta's bet is that as companies deploy autonomous software across their operations, most of the identities worth protecting will not belong to people. Agents, service accounts and machine credentials are multiplying, and each one holds permissions.

The governance gap is structural. When an employee leaves, an offboarding process closes their account, and that process is decades old and well understood. An AI agent never joins and never leaves. It gets spun up for a pilot, issued an API key, wired into a few systems, and then forgotten. The permissions stay live indefinitely.

Agents also behave differently from the service accounts that identity tools were built around. A service account performs a fixed, predictable task. An agent plans, picks tools, moves across several systems, and adapts as the job changes. That makes its access pattern hard to model in advance, and it means a single compromised credential has a much wider blast radius.

Should a smaller team care about a $200M acquisition?

Not for the price tag. Read it for the direction instead.

One of the largest vendors in enterprise identity is spending real money to state that agent identity is where the risk is heading. That forecast holds whether or not you have the budget to buy the resulting product. Survey data points the same way: a large majority of organizations report their current identity tooling cannot manage AI agent identities at all.

What we see repeatedly in deployments is simpler and more fixable than any of this suggests. Chatbots, document processing pipelines and integration agents very often run on a single shared administrator key. The agent can technically reach far more than its job requires, and nothing in the logs distinguishes one agent's actions from another's.

None of the fixes need a nine-figure product:

  • Give every agent its own credential. Shared keys make attribution impossible the moment something goes wrong.
  • Scope permissions to the actual task. An agent that reads invoices has no business holding delete rights on a customer database.
  • Keep an inventory. If there is no written answer to which agents are running against which systems, that is not a security posture.
  • Revoke credentials when a pilot ends. A finished pilot with a live key has not finished.

Most of that is an afternoon of work. Okta paying $200 million is a reasonably direct signal of what it costs when nobody does it.

Sources: TechCrunch, Okta Press Release, Techzine, Security Boulevard

Share This Article

Faruk Talmaç

Written by

Faruk Talmaç

Co-Founder & Editor

Co-founder of YZ Uzman, with 20+ years of experience in web design and software development.

More news

Want to put this technology to work in your business?

Let's talk