Technology

Okta to Acquire Permiso Security for Roughly $200 Million, Adding Cloud Identity Threat Detection and AI Agent Security

Martin HollowayPublished 16h ago4 min readBased on 4 sources
Reading level
Okta to Acquire Permiso Security for Roughly $200 Million, Adding Cloud Identity Threat Detection and AI Agent Security

Okta has signed a definitive agreement to acquire Permiso Security, a Palo Alto-based startup that detects when hackers use stolen or hijacked login credentials inside cloud environments. The deal is valued at just under $200 million, according to a source with knowledge of the transaction. TechCrunch

Okta's official press release did not disclose financial terms. Okta An Okta spokesperson declined to comment on specifics when asked by TechCrunch but did not dispute the approximately $200 million figure. The transaction is structured as almost all-cash and is expected to close in the third quarter of Okta's fiscal year 2027, subject to customary closing conditions. TechCrunch

Permiso emerged from stealth in 2022, co-founded by former FireEye executives Paul Nguyen and Jason Martin. The company builds software that helps security teams catch suspicious activity in cloud environments involving compromised identities. The key distinction here is that these attacks use valid credentials that have been hijacked or abused, rather than breaking in through an external vulnerability. Permiso raised approximately $29 million in total funding, including an $18.5 million Series A in April 2024 led by Altimeter Capital, which valued the company at roughly $80 million post-money. TechCrunch

In April 2026, Permiso introduced a platform called SandyClaw that analyzes AI agent skills in a sandboxed environment, essentially a safe testing ground, to detect malicious behavior before those agents are deployed in live systems. The product targets an emerging threat surface: as enterprises increasingly deploy autonomous AI agents with access to systems and data, those agents' capabilities themselves become an attack vector if an agent is compromised or deliberately crafted to act maliciously. TechCrunch

Okta's chief product officer Ely Kahn stated that Permiso will extend Okta's identity security fabric with identity threat detection and response capabilities. Okta Permiso confirmed the acquisition on its own website, directing readers to Okta's announcement for further information. Permiso

The strategic logic is straightforward. Okta's core business is identity authentication and access management, meaning determining who a user is and what they can access. Permiso's technology operates one layer deeper: detecting when authenticated identities behave abnormally in cloud infrastructure, which is the signature of a compromised credential or an insider threat. Folding that capability into Okta's platform moves the company from identity provisioning into continuous identity threat detection, a category sometimes labeled ITDR, or identity threat detection and response.

The SandyClaw component is the more forward-looking part of the deal. Securing AI agents before deployment is a problem most enterprises have not yet fully grappled with, because most have not yet deployed AI agents at scale in production environments with sensitive access. Okta is buying capability ahead of broad adoption, which carries both opportunity and risk. The risk is that the market for pre-deployment agent security matures more slowly than expected, or that larger cloud providers build equivalent controls into their own platforms.

For Permiso's investors, the exit is a solid one. A roughly $200 million acquisition against $29 million in total funding is a strong return multiple, particularly for a company that had been operating for roughly four years. The deal also reflects ongoing consolidation in the identity security space, where standalone point products are increasingly absorbed into broader platform vendors rather than remaining independent.

Permiso won a 2026 SC Award, noted on its homepage alongside the acquisition notice. Permiso

The broader context is that this acquisition fits a pattern that has repeated across multiple technology cycles: a platform vendor absorbing a specialized security capability to deepen its moat and expand its surface area. What is newer here is the AI agent security dimension. Whether that capability matures into a must-have category or remains a niche offering will depend on how quickly autonomous agents become a standard part of enterprise infrastructure, a question that, as of mid-2026, does not yet have a settled answer.