ProBackend
agentic ai security risks
just now5 min read

Okta Drops $200M on Permiso to Watch What AI Agents Do After Login

Okta is acquiring Permiso Security for roughly $200 million in cash, signaling a shift from traditional user authentication toward post-login threat detection for non-human identities and AI agents.

Beyond the Gatekeeper: Why Login Is No Longer Enough

Single sign-on was never going to be the end state for enterprise security. Verifying a username and password at the front door worked when human employees sat behind office desktops, but that model broke the moment software began operating on behalf of other software. Okta's decision on July 30, 2026, to acquire AI security startup Permiso Security for roughly $200 million makes one thing obvious: checking credentials at login is dead end security if you can't monitor what identities do after they get inside.

The deal, structured almost entirely as cash, is slated to close in the third quarter of Okta’s fiscal 2027, subject to customary closing conditions. Okta didn't disclose exact transaction terms in its official announcement, but sources familiar with the transaction confirmed the near-$200 million price tag in TechCrunch's reporting. When asked about the figure, an Okta spokesperson declined to dispute the $200 million valuation.

For years, identity management vendors built lucrative businesses around identity verification. You prove who you are, receive a session token, and step into the cloud ecosystem. But modern enterprise environments are flooded with API keys, service accounts, and autonomous software agents that execute complex tasks without human intervention. Once an attacker gets hold of a valid credential, traditional identity systems treat every subsequent API request as legitimate. That fundamental blind spot is why identity threat detection and response (ITDR) has become the primary defense line in cloud security.

By bringing Permiso into its portfolio, Okta is acknowledging that its identity fabric must extend far past authentication into live threat monitoring. Checking access once at the gate offers zero protection when an authorized AI agent gets tricked into running malicious commands across your infrastructure.

Permiso’s Playbook: Spotting Compromised Cloud Access

Permiso isn't a newcomer to tracking post-authentication activity. Founded by former FireEye executives Paul Nguyen and Jason Martin, the Palo Alto startup emerged from stealth in 2022 with a clear objective: detecting suspicious identity activity inside cloud environments after access has already been granted.

Security teams have long struggled with identity-based attacks because compromised credentials look identical to normal operational traffic. When an attacker steals an enterprise token or API secret, they don't break code—they simply log in. Permiso built its runtime platform to baseline identity behavior across multi-cloud infrastructure, analyzing telemetry to catch unauthorized privilege escalation, abnormal access patterns, and lateral movement across cloud workloads.

Before Okta agreed to acquire the company, Permiso had raised about $29 million from venture investors. Its last major funding event, an $18.5 million Series A round led by Altimeter Capital in April 2024, valued the startup at roughly $80 million on a post-money basis. Selling for nearly $200 million just over two years later demonstrates how quickly non-human identity security has shifted from a niche add-on to essential defense.

FireEye veterans understand how threat actors maneuver through compromised networks. Nguyen and Martin built Permiso on the premise that identity is the primary attack vector for cloud breaches. When enterprise environments shift from human-driven applications to automated agentic pipelines, tracking behavioral anomalies becomes the only reliable way to catch compromised accounts before data exfiltration occurs.

Sandboxing Autonomous Skills: The SandyClaw Breakthrough

As enterprise engineering teams began wiring large language models into production systems, Permiso realized that monitoring static machine credentials wasn't enough. AI agents present an entirely new operational risk because they don't just query databases—they execute code, call external tools, and make runtime decisions based on unpredictable prompt inputs.

In April 2026, Permiso introduced SandyClaw, a platform built specifically to inspect AI agent capabilities in a sandboxed environment before deployment. SandyClaw isolates agent tools and skills, running them through execution testing to identify hidden vulnerabilities, unauthorized system commands, or malicious prompt behavior before the agent receives permission to run in live corporate networks.

This sandbox approach hits directly at a growing weakness in enterprise AI integration. Software developers frequently grant broad API permissions to AI agents to keep setup simple. When an agent has read-and-write permissions across enterprise datastores, a single prompt injection attack can turn a helpful assistant into a rogue actor.

By pairing SandyClaw’s sandboxing with runtime monitoring, Permiso gave security teams visibility into both what an AI agent is designed to do and what it actually does when executing tasks. Okta picking up this technology gives the identity giant a direct mechanism to audit autonomous software tools before they interact with enterprise identity systems.

Integrating Threat Detection into Okta’s Identity Fabric

Okta’s chief product officer Ely Kahn outlined the strategic core of the transaction, stating that Permiso will extend Okta’s identity security fabric with proven identity threat detection and response capabilities while adding Permiso's specialized threat research team to Okta’s engineering organization.

This acquisition marks a major operational shift for Okta. After experiencing high-profile social engineering and credential-based attacks over recent years, Okta has faced steady pressure to strengthen its defensive capabilities. Buying a startup with specialized threat research capabilities helps Okta transform from an access broker into an active monitoring engine.

The expansion reflects an urgent reality across enterprise infrastructure: non-human identities now outnumber human employees by orders of magnitude. Every automated script, microservice, container, and AI agent requires authorization to function. Managing those identities with static access policies is impossible at scale.

Securing enterprise operations now demands real-time inspection of token usage, continuous validation of service account activity, and automated response capabilities when machine identities drift from expected behavior patterns. Okta’s acquisition of Permiso follows a broader trend of tech leaders securing non-human identity stacks, signaling that the future of identity management isn't just deciding who gets in—it is constantly watching what every user, script, and AI agent does once they step inside.

Beyond the Gatekeeper: Why Login Is No Longer Enough

Beyond the Gatekeeper: Why Login Is No Longer Enough

More blogs