Okta Permiso acquisition brings cloud identity detection into Okta
Okta agreed to buy Permiso Security, with TechCrunch reporting a nearly $200 million mostly cash deal for cloud identity threat detection.
By Dominic Okoye · Staff Writer
· 3 min read
Okta said July 30 it signed a definitive agreement to buy Permiso Security, a Palo Alto startup that detects identity-based attacks across cloud accounts, SaaS tools and AI agents. The Okta Permiso acquisition gives Okta a broader runtime detection layer outside its own identity control plane, where many cloud keys, service accounts and agent actions now sit.
Okta did not announce a purchase price. TechCrunch reported, citing a person familiar with the transaction, that the deal is valued at just under $200 million and is almost entirely cash; an Okta spokesperson did not dispute that figure, according to the report. Okta said the transaction is expected to close by the end of October, during its fiscal third quarter, and that guidance issued May 27 is unchanged.
What does Permiso Security do?
Permiso was founded in 2020 by Jason Martin and Paul Nguyen, both former FireEye employees, and began selling publicly two years later. Its software watches how identities behave across identity providers, cloud environments, SaaS applications and infrastructure-as-code systems, then flags activity that does not fit the normal use of an account, key or agent.
Okta said Permiso’s detection system uses more than 2,500 research-driven signals across more than 70 identity partners. The companies did not disclose Permiso’s revenue or headcount in the deal announcement. Permiso had raised $28.5 million, including an $18.5 million Series A in April 2024 led by Altimeter Capital Management with participation from Point72 Ventures.
Customers named for Permiso include Autodesk, Nutanix, Coupa Software and ACV Auctions. Autodesk deployed Permiso’s AI-agent monitoring capabilities in May across its products, workforce and cloud infrastructure, according to the earlier company disclosure cited in the announcement coverage.
Why is Okta buying Permiso?
Okta already sells Identity Threat Protection and posture management products, but Permiso addresses a gap in environments that extend beyond Okta-managed sessions. Its detections run across cloud accounts, access keys and agents that may operate outside Okta’s direct control, which is a practical problem for security teams trying to connect identity posture with live activity.
Ely Kahn, Okta’s chief product officer, said Permiso will add identity threat detection and response capabilities to what Okta calls its identity security fabric, particularly for companies where humans, applications, service accounts and AI agents operate together. Nguyen said combining Permiso’s technology with Okta’s platform would make broader identity threat protection possible at Okta’s scale.
How the AI-agent angle fits
Permiso expanded its platform in September to cover what it calls AI users, AI builders and AI agents. This year it added agent and session discovery, runtime attribution that ties activity back to a specific identity, detection for over-privileged agents, kill switches and SandyClaw, a sandbox for testing agent skills and prompts before production use.
The company also built recognition through P0 Labs, its research arm. In 2024 it released CloudGrappler, an open-source tool for finding known threat actor activity in AWS and Azure accounts, and later added three more open-source tools that brought P0 Labs’ total to 10. Last October it introduced P0LR Espresso, which normalizes cloud logs from different providers into a common format for analysts.
The purchase is Okta’s second security acquisition in less than a year, after its August deal for privileged access management startup Axiom Security. For Okta, Permiso adds cloud and agent identity telemetry to a security portfolio that has been moving from access control into threat detection and response.
This story draws on original reporting from SiliconANGLE.