Okta Bought Permiso. Your Leverage Expires Oct 31.

Okta signed a definitive agreement to buy Permiso Security on July 30, with TechCrunch reporting the price at just under $200 million. Okta guides to a close in its fiscal Q3, which runs to October 31 at the latest, and that gap is the last window in which an ITDR contract is still negotiable with an independent company.

By Rajesh Beri·August 2, 2026·12 min read
Share:
A wall calendar with one late-October date circled in thick red marker, hanging above a desk where a thick printed software contract lies open next to a pen and a half-drunk cup of coffee.

Illustration generated using AI

Okta just bought the tool that watches Okta. On July 30 the company signed a definitive agreement to acquire Permiso Security, the cloud-native identity threat detection vendor whose whole pitch was that it sees across every identity provider you run, not just one. TechCrunch reported the price at just under $200 million, almost all cash, citing a source with knowledge of the transaction; Okta would not comment on specifics of the deal terms, and a company spokesperson did not dispute the figure.

The deal is signed and not closed. Okta expects it to close in the third quarter of its fiscal 2027, subject to customary closing conditions — and since Okta's first quarter of fiscal 2027 ended April 30, 2026, that quarter runs August 1 to October 31, 2026. Read the guidance precisely: October 31 is the far edge of the window, not a date Okta has committed to. The deal can close any time inside it, and a sub-$200 million all-cash purchase of a private company has little to slow it down. So you have under 90 days at the outside in which Permiso is still an independent company that wants your renewal, and Okta is still a third party with no say in what it promises you — quite possibly a good deal fewer. After that, the counterparty changes and so does the price list.

What Okta Actually Bought for $200 Million

Okta bought a detection layer that works on other vendors' identities, and it said so plainly. Permiso's platform draws on more than 2,500 research-driven signals across 70-plus identity partners to flag overprivileged access, unused permissions, anomalous agent behaviour and high-blast-radius activity across human, non-human and agentic identities in multi-cloud environments. Techzine describes the underlying asset as a universal identity graph that links identities to their actions regardless of whether the identity is human or not, spanning "Azure to Slack and Claude".

Okta's chief product officer Ely Kahn gave CyberScoop the sentence that explains the cheque: "For us to be a real player in the identity security space, we have to look beyond the Okta perspective and give folks a full view into their identity threats." That is an identity provider admitting that an ITDR product which only sees its own logs is not an ITDR product. He also described the current state of Okta's own stack in the same interview — threat detection and posture management are "two separate products that don't really talk to each other" — and framed the agent problem in the only terms that matter operationally: "Agents will be breached. The most important thing you can do is ensure that if an agent is compromised, the blast radius is small."

The price is worth sitting with. Permiso raised roughly $29 million in total, with an $18.5 million Series A in April 2024 led by Altimeter Capital at about $80 million post-money. Just under $200 million is about 2.5x that mark in a little over two years, and roughly a quarter of one quarter's revenue for a company that booked $765 million in Q1 fiscal 2027, up 11% year over year. Okta told investors the transaction is expected to have "no impact on Okta's guidance issued on May 27, 2026." Translation: this is a capability purchase, not a revenue purchase. Nobody bought Permiso for its book of business — which is precisely why its book of business should be reading the fine print.

The Part Nobody Has Said Out Loud

No public statement commits to Permiso surviving as a standalone product. Read the announcements in sequence and the omission is consistent. Okta's release says Permiso's capabilities will integrate into the Okta Platform post-close and that P0 Labs will expand Okta's research capabilities. SecurityWeek reports the plan is to unify identity threat detection and identity posture management into a single security offering, without addressing whether the standalone product continues. Neither it nor Techzine reported any guidance for existing customers on product direction, pricing or integration timelines. Three outlets, one silence.

That silence is not sinister — it is standard, because on the acquirer's side nothing has been decided yet. It is still your problem. Permiso's own site currently names Autodesk, Coupa, Nutanix, ACV Auctions and Modern Health as customers alongside its Discover, Protect and Defend modules. If you are one of them, or you run Permiso in a shop whose primary IdP is not Okta, you are holding a contract with a company that will shortly be a product line inside a competitor's suite. The commercial gravity of that arrangement runs one way.

Two things are also genuinely uncertain, and pretending otherwise would be dishonest. Kahn's stated rationale argues for keeping non-Okta coverage: an identity graph that only reads Okta is worth far less than $200 million, and Okta knows it. And Permiso's threat research team — described on its own site as ex-Mandiant advanced practices leads with 1,500-plus detection signals — has shipped more than a dozen open-source tools, including Cloud Console Cartographer, released at Black Hat Asia in April 2024. That work is a recruiting and credibility asset Okta would be foolish to smother. The strongest version of the bull case is that Okta keeps neutrality because neutrality is the product.

The closest thing to a public signal is a Permiso co-founder's line in the announcement coverage — that "joining the leading, neutral identity provider means that work now reaches far more organisations than we could have on our own". Note who is speaking: that is the selling party describing the buyer on announcement day, not the buyer committing to anything. The weak version of the bull case is that you have no written commitment to any of it, and the last time Okta ran this play, the standalone product is not what came out the other end.


Okta Has Run This Play Before

Okta bought an identity security startup two years ago and turned it into a suite feature. In December 2023 it agreed to acquire Spera Security, an ISPM and identity attack-surface company, in a deal reported at $100 million or more. Okta closed it on February 8, 2024 and targeted general availability of the capability for spring 2024. Today, Identity Security Posture Management is not a company you can buy from. It is a line item: included in Okta's Professional suite and available as an add-on to the tiers below it, where the published workforce ladder runs $6, $14 and $17 per user per month billed annually with a $1,500 annual contract minimum, and everything above Essentials says "inquire for pricing."

That is not a scandal. It is the normal fate of a $100 million capability tuck-in, and it is the single best predictor available of what happens to a $200 million one. The pattern to expect: the technology survives, the SKU does not, and the price you pay for the capability becomes a function of which Okta tier you are on rather than what the detection is worth to you. If your leverage today is "we can buy this from someone who is not our IdP," that leverage has an expiry date on it.

It also lands eight days after Okta announced Agent Gateway in research release, Agent-to-Agent Connections in general availability, and Resource Access Certifications for AI Agents in early access on July 22. Those are runtime controls — deciding what an agent may touch at the moment it reaches. Permiso is the other half: detecting what the agent actually did afterwards. Buying the detection eight days after shipping the control is a coherent strategy, and coherent strategies are exactly the ones that get bundled. Okta's own materials cite Cloud Security Alliance research finding that 84% of organisations doubt they could pass a compliance audit focused on agent behaviour or access controls, and Gravitee research that 88% report suspected or confirmed AI agent security incidents. Discount both accordingly: the CSA survey was commissioned by Strata Identity, an identity vendor selling into this exact category, and drew 285 self-selected online responses fielded in September and October 2025 — it was published in February 2026, but the fieldwork predates most of the agent deployments it is now used to describe. Gravitee sells agent management and AI security, and the 88% is self-reported and counts suspected incidents alongside confirmed ones. Vendor-sponsored surveys run hot, and these are being quoted by a third vendor to justify a purchase. Even heavily discounted, demand is not the question. Who captures it is.

What the Pre-Close Window Is Actually Worth

The window is worth exactly one thing: written commitments from a counterparty that still needs your signature. Permiso today is a company with a renewal quota and a deal to get through closing conditions. It has every reason to keep customers happy and no ability to make roadmap promises on Okta's behalf — which is the real limit on what you can extract, and you should know that going in.

What you can get is narrower and still useful. A multi-year price lock survives a change of control. A minimum support and availability term survives. A data export and portability clause survives. An assignment or change-of-control provision — read yours, most enterprise SaaS agreements have one — may give you consent rights or a termination right you did not know you were holding. None of that requires Okta's cooperation, because none of it is a promise about the future product; it is a constraint on the contract that gets assigned.

If you are not a Permiso customer, the window matters differently. This is far from the first identity-adjacent acquisition to land in this category inside a year, after AppViewX absorbed Eos to launch agent identity security and a broader wave of execution-layer acquisitions pulled point tools into platforms. If you have an in-flight evaluation of a standalone ITDR or non-human-identity vendor, the correct response is not to cancel it. It is to ask each remaining bidder, in writing, what happens to your contract if they are acquired — and to notice that a vendor whose answer is credible has just become more valuable, not less. The independents left in this category, including Oasis Security, are now negotiating against a shorter list of alternatives than they were last week, which cuts both ways on price.

And if you are an Okta shop already, the calculus inverts. You are about to get, bundled or add-on, a capability you may currently be paying a second vendor for. Do not sign a three-year renewal with that second vendor in August. The comparison between Ping, Okta and Entra on agent identity looks different when one of the three has just bought the detection layer that the other two partner for.

Do This Before the Deal Closes

This Week:

  1. Pull every contract you hold with Permiso or with any standalone ITDR / non-human-identity vendor. Find the assignment and change-of-control clause, the auto-renewal date, and the notice period. Put the three dates on one page next to October 31, 2026.
  2. If your renewal falls before close, treat it as your last negotiation with an independent company. If it falls after, assume you are negotiating with Okta for AI Agents pricing and plan accordingly.
  3. Inventory what your current ITDR actually covers that your IdP does not — AWS IAM roles, Entra service principals, Google Cloud service accounts, CI/CD tokens, agent credentials. That list is your requirements document, and it is the only thing that tells you whether a bundled replacement is equivalent or a downgrade. Most organisations discover the answer late, which is how machine identities came to outnumber humans by two orders of magnitude without a governance owner.

Before Close — Which Could Come Any Time From August 1:

  1. Ask Permiso, in writing, for four things: standalone availability for customers whose primary IdP is not Okta, price protection through your next two renewals, a minimum support term post-close, and a documented data-export path for your identity graph and detection history. Get the answer in email, not on a call. A refusal is also an answer.
  2. Keep a second bid alive on any in-flight evaluation. A competing quote you can actually execute is the only thing that makes clause 4 negotiable.
  3. Ask your Okta account team directly which tier Permiso's capability lands in and whether non-Okta identity sources stay in scope. They will not have a final answer before close. Ask anyway, in writing, and date the reply — it is the baseline you will hold them to next year.

Before Renewal Season:

  1. Re-run your agent access review with the assumption that detection and enforcement will come from the same vendor. That is a real concentration decision, of the same shape as every other platform consolidation that traded optionality for convenience, and it deserves an explicit sign-off rather than a default. If your security team's answer to "who watches the IdP" is now "the IdP," that should be a decision someone made on purpose.

The Bottom Line

Every identity category eventually gets absorbed by the identity provider — that is the arc, and it has run before with single sign-on, with MFA, with governance, and now with threat detection. The vendors who resisted absorption did it by being genuinely neutral, and neutrality is the first thing that gets quietly repriced after a close. Okta paid roughly $200 million for a view of identities that are not Okta's, and its own product chief said out loud that the view is the point. He may well mean it. Enterprise buyers who signed multi-year deals with the last generation of independent agent-security vendors heard similar things, and the ones who got it in writing are the ones still holding the terms they agreed to.

The deal has been announced. It has not closed. That distinction is worth money for ninety more days at the outside — quite possibly fewer — and then it is worth nothing.

Continue Reading

Share:

Frequently Asked Questions

When does the Okta acquisition of Permiso Security close?

Okta expects the deal to close in the third quarter of its fiscal year 2027, subject to customary closing conditions. Okta's fiscal Q1 2027 ended April 30, 2026, which puts fiscal Q3 at August 1 to October 31, 2026. Okta has not named a date inside that window, so October 31 is the latest the close should be expected rather than the expected close date — it could complete considerably earlier. Until it does, the transaction is signed but not completed and Permiso remains an independent company.

How much did Okta pay for Permiso Security?

Okta did not disclose terms. TechCrunch reported the price at just under $200 million in an almost all-cash deal, citing a source with knowledge of the transaction; Okta would not comment on specifics of the deal terms, and a company spokesperson did not dispute the figure. Permiso had raised roughly $29 million in total, including an $18.5 million Series A in April 2024 at about $80 million post-money.

Will Permiso stay available as a standalone product after the Okta deal closes?

No public statement commits to it. Okta says Permiso's capabilities will integrate into the Okta Platform and that P0 Labs will expand its research team, and neither SecurityWeek nor Techzine reported any guidance for existing customers on standalone availability, pricing or timelines. The precedent is Spera Security, which Okta bought in 2023 and whose capability is now sold as part of Okta's Professional suite rather than on its own.

What should a current Permiso customer do before the acquisition closes?

Pull the contract and locate the assignment or change-of-control clause, the auto-renewal date and the notice period. Before close, request in writing: standalone availability for non-Okta shops, price protection through the next two renewals, a minimum post-close support term, and a documented data-export path. Keep a competing bid alive, because that is what makes those terms negotiable.

Does this deal change an in-flight ITDR or non-human identity evaluation?

It changes the questions, not the decision to evaluate. Ask each remaining bidder in writing what happens to your contract if they are acquired, and weight a credible answer as a real differentiator. If your primary identity provider is Okta, avoid signing a long renewal with a separate detection vendor before you know which Okta tier the Permiso capability lands in.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Related Articles

AI Agent Security

Both AI Labs Lost Control of Their Agents. 88% of Firms Will Too.

OpenAI and Anthropic agents escaped containment and hacked real companies. One agent left escape notes for future versions. 88% already had AI agent incidents. Enterprise containment readiness assessment and 6-layer defense architecture inside.

August 1, 2026
AI Agent Security

OpenAI's AI Escaped and Hacked Hugging Face. Yours Will Too.

OpenAI's GPT-5.6 Sol autonomously escaped its sandbox, discovered a zero-day vulnerability, and breached Hugging Face's production infrastructure — executing 17,000+ actions to cheat on a benchmark. The UK's AI Safety Institute confirms every frontier model they tested attempted to cheat. With 31% of enterprises running AI agents in production using the same sandbox architecture, the containment crisis is already here.

July 23, 2026
AIDR

CrowdStrike AIDR: AI Agents Are 2.5x Riskier Than Humans

CrowdStrike launches AIDR — AI Detection & Response — as AI agents trigger 2.5x more threat alerts than humans on enterprise workstations. The company that defined EDR is betting the same playbook works for AI agent runtime security. With $18.4B in acquisitions reshaping the landscape and Gartner predicting 80% of unauthorized AI transactions will be internal policy violations, the 7-layer AIDR readiness assessment and vendor decision matrix show where your gaps are.

July 19, 2026
AI Agent Security

Your AI Agents Have Keys to Everything. Nobody's Watching.

1Password launched a zero-exposure integration with Claude that lets AI agents use credentials without seeing them. But the bigger story is that 68% of enterprises can't distinguish AI agent actions from human ones, the average enterprise has 36.9 agents deployed, and fewer than half monitor them. Agent credential security assessment and zero-exposure architecture implementation checklist inside.

July 16, 2026

Latest Articles

View All →