The security market names its next problem
Okta agreed to acquire Permiso Security, betting that demand for protecting AI agents and other machine identities will grow as enterprises deploy autonomous software across their operations. Terms were not disclosed, but TechCrunch learned the deal is valued at just under $200 million, structured as an almost all-cash transaction, with an Okta spokesperson declining to dispute the figure. It is expected to close in the third quarter of Okta's fiscal 2027.
What Permiso actually does
Founded by former FireEye executives Paul Nguyen and Jason Martin and out of stealth since 2022, Permiso builds software that helps security teams spot suspicious activity in cloud environments after users or applications have been granted access - specialising in attacks that use stolen or compromised identities to move laterally through cloud infrastructure. More recently it extended the platform to AI agents and machine identities, and in April introduced SandyClaw, a platform that analyses AI agent skills in a sandboxed environment to identify malicious behaviour before deployment. Okta's chief product officer framed the purchase as extending its identity security fabric with proven identity threat detection and response plus a threat-research team. On the returns: Permiso had raised roughly $29 million, including an $18.5 million Series A led by Altimeter in April 2024 at about an $80 million post-money valuation - so this is a solid multiple in a market that rewards being early to the right problem.
The structural shift underneath
The deal reflects identity companies expanding beyond verifying users at login to continuously monitoring what users, applications, and AI agents do once inside a network. That is a fundamentally different product: perimeter authentication assumes a human at a keyboard, while agents authenticate legitimately and then behave unpredictably at machine speed.
What security and IT leaders should take from this
- Inventory your non-human identities now. Most organisations cannot say how many service accounts, API keys, and agent identities they have, what those can reach, or what normal behaviour looks like. That inventory is the prerequisite for every control that follows, and it is what acquirers are paying premiums to solve.
- The sandbox-before-deploy pattern (Permiso's SandyClaw) is worth adopting conceptually even without buying a product: agent skills, plugins, and MCP connectors are executable code from third parties. Review them like dependencies, not like configuration.
- Expect your existing identity vendor to sell you agent security within a year. Budget for it, but negotiate: consolidation means these capabilities are being folded into platforms you already license, so resist paying twice for overlapping detection.
- For founders and investors, this is a clean signal of where enterprise security spend is heading. Agent identity, behavioural monitoring, and pre-deployment analysis are being validated by acquisition, and this week's OpenAI-Hugging Face incident guarantees the budget conversation gets easier.
