Skip to content
Rush Commerce
AI & Automation3 min read

Okta buys Permiso: your IdP is the AI agent control plane

Okta is acquiring Permiso Security for about $200M to watch AI agents and machine identities. The lesson isn't buy a tool — it's use the identity provider you already pay for.

Okta signed a definitive agreement to acquire Permiso Security, a startup that detects threats across human, machine, and AI agent identities. TechCrunch puts the price at just under $200 million, near-all-cash. The deal matters less as an M&A datapoint than as a signal about where agent governance is landing: not in a new category of tool you have to evaluate, but inside the identity provider you already pay for every month.

What actually happened

Per Okta's announcement, Permiso brings identity threat detection and response across human, non-human, and agentic identities, plus behavioral analytics and automated response. The piece built specifically for agents is SandyClaw, a dynamic sandbox that runs AI agent skills and prompts to catch supply chain attacks before the agent gets deployed. Okta cites 2,500+ research-driven signals across 70+ identity partners, and Chief Product Officer Ely Kahn framed the goal as securing enterprises "where humans, applications, service accounts, and AI agents work together."

The valuation math tells you how hot this category is. TechCrunch reports Permiso raised roughly $29 million total, including an $18.5 million Series A in April 2024 at about $80 million post-money. That's a Palo Alto company exiting at roughly 2.5x its last round valuation in a little over two years. The transaction is expected to close in Q3 of Okta's fiscal 2027.

Why AI agent identity matters for your business

If you run Okta, Entra ID, or Google Workspace, the honest read is that you don't need to go shopping. The controls are arriving in the platform you already have. What you need is to stop treating agents as an exception to the access rules you enforce on people.

Here's the pattern we keep finding in small-business stacks: someone wired an AI assistant into the CRM and the shared drive using a personal admin token, because that was the account that already had access. That token doesn't expire, doesn't show up in any review, and doesn't distinguish the agent's actions from the human's in the audit log. When something goes wrong, you can't answer the only question that matters — what did it touch?

Four things to fix this week, no procurement required. Give every agent its own service identity, never a human's credentials. Scope it to the minimum — one system, read-only until read-write is proven necessary. Set an expiration on the credential so abandoned integrations die on their own. Review unused permissions quarterly, because the grant you made for a pilot in March is still live in October.

Okta says 58% of executives reported an AI-related security incident or near miss in the past year — their number, from their own research, and directionally consistent with what other vendor surveys are finding. Treat it as a floor. The agent you deployed last quarter has the permissions you gave it, plus every permission the account you borrowed already had.

Key takeaways

  • Okta is acquiring Permiso Security for just under $200M per TechCrunch; the deal closes in Q3 of Okta's fiscal 2027
  • Permiso adds identity threat detection across human, non-human, and agentic identities, plus SandyClaw, a sandbox for agent skills and prompts
  • Agent identity governance is consolidating into mainstream identity providers — you likely don't need a new vendor, you need to use the one you have
  • Give each agent its own scoped, expiring service identity and review unused permissions on a schedule

Every agent we deploy gets its own identity, its own scope, and its own audit trail — before it touches a customer record. If you've got an AI integration running on somebody's admin login, let's take a look at it. Or see how we build automations you can actually govern.

Sources: Okta Newsroom, TechCrunch.

  • #ai-agents
  • #identity
  • #security
  • #okta
  • #access-control
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.