Okta just bought the tool that watches Okta. On July 30 the company signed a definitive agreement to acquire Permiso Security, the cloud-native identity threat detection vendor whose whole pitch was that it sees across every identity provider you run, not just one. TechCrunch reported the price at just under $200 million, almost all cash, citing a source with knowledge of the transaction; Okta would not comment on specifics of the deal terms, and a company spokesperson did not dispute the figure.
The deal is signed and not closed. Okta expects it to close in the third quarter of its fiscal 2027, subject to customary closing conditions — and since Okta's first quarter of fiscal 2027 ended April 30, 2026, that quarter runs August 1 to October 31, 2026. Read the guidance precisely: October 31 is the far edge of the window, not a date Okta has committed to. The deal can close any time inside it, and a sub-$200 million all-cash purchase of a private company has little to slow it down. So you have under 90 days at the outside in which Permiso is still an independent company that wants your renewal, and Okta is still a third party with no say in what it promises you — quite possibly a good deal fewer. After that, the counterparty changes and so does the price list.
What Okta Actually Bought for $200 Million
Okta bought a detection layer that works on other vendors' identities, and it said so plainly. Permiso's platform draws on more than 2,500 research-driven signals across 70-plus identity partners to flag overprivileged access, unused permissions, anomalous agent behaviour and high-blast-radius activity across human, non-human and agentic identities in multi-cloud environments. Techzine describes the underlying asset as a universal identity graph that links identities to their actions regardless of whether the identity is human or not, spanning "Azure to Slack and Claude".
Okta's chief product officer Ely Kahn gave CyberScoop the sentence that explains the cheque: "For us to be a real player in the identity security space, we have to look beyond the Okta perspective and give folks a full view into their identity threats." That is an identity provider admitting that an ITDR product which only sees its own logs is not an ITDR product. He also described the current state of Okta's own stack in the same interview — threat detection and posture management are "two separate products that don't really talk to each other" — and framed the agent problem in the only terms that matter operationally: "Agents will be breached. The most important thing you can do is ensure that if an agent is compromised, the blast radius is small."
The price is worth sitting with. Permiso raised roughly $29 million in total, with an $18.5 million Series A in April 2024 led by Altimeter Capital at about $80 million post-money. Just under $200 million is about 2.5x that mark in a little over two years, and roughly a quarter of one quarter's revenue for a company that booked $765 million in Q1 fiscal 2027, up 11% year over year. Okta told investors the transaction is expected to have "no impact on Okta's guidance issued on May 27, 2026." Translation: this is a capability purchase, not a revenue purchase. Nobody bought Permiso for its book of business — which is precisely why its book of business should be reading the fine print.
The Part Nobody Has Said Out Loud
No public statement commits to Permiso surviving as a standalone product. Read the announcements in sequence and the omission is consistent. Okta's release says Permiso's capabilities will integrate into the Okta Platform post-close and that P0 Labs will expand Okta's research capabilities. SecurityWeek reports the plan is to unify identity threat detection and identity posture management into a single security offering, without addressing whether the standalone product continues. Neither it nor Techzine reported any guidance for existing customers on product direction, pricing or integration timelines. Three outlets, one silence.
That silence is not sinister — it is standard, because on the acquirer's side nothing has been decided yet. It is still your problem. Permiso's own site currently names Autodesk, Coupa, Nutanix, ACV Auctions and Modern Health as customers alongside its Discover, Protect and Defend modules. If you are one of them, or you run Permiso in a shop whose primary IdP is not Okta, you are holding a contract with a company that will shortly be a product line inside a competitor's suite. The commercial gravity of that arrangement runs one way.
Two things are also genuinely uncertain, and pretending otherwise would be dishonest. Kahn's stated rationale argues for keeping non-Okta coverage: an identity graph that only reads Okta is worth far less than $200 million, and Okta knows it. And Permiso's threat research team — described on its own site as ex-Mandiant advanced practices leads with 1,500-plus detection signals — has shipped more than a dozen open-source tools, including Cloud Console Cartographer, released at Black Hat Asia in April 2024. That work is a recruiting and credibility asset Okta would be foolish to smother. The strongest version of the bull case is that Okta keeps neutrality because neutrality is the product.
The closest thing to a public signal is a Permiso co-founder's line in the announcement coverage — that "joining the leading, neutral identity provider means that work now reaches far more organisations than we could have on our own". Note who is speaking: that is the selling party describing the buyer on announcement day, not the buyer committing to anything. The weak version of the bull case is that you have no written commitment to any of it, and the last time Okta ran this play, the standalone product is not what came out the other end.
Okta Has Run This Play Before
Okta bought an identity security startup two years ago and turned it into a suite feature. In December 2023 it agreed to acquire Spera Security, an ISPM and identity attack-surface company, in a deal reported at $100 million or more. Okta closed it on February 8, 2024 and targeted general availability of the capability for spring 2024. Today, Identity Security Posture Management is not a company you can buy from. It is a line item: included in Okta's Professional suite and available as an add-on to the tiers below it, where the published workforce ladder runs $6, $14 and $17 per user per month billed annually with a $1,500 annual contract minimum, and everything above Essentials says "inquire for pricing."
That is not a scandal. It is the normal fate of a $100 million capability tuck-in, and it is the single best predictor available of what happens to a $200 million one. The pattern to expect: the technology survives, the SKU does not, and the price you pay for the capability becomes a function of which Okta tier you are on rather than what the detection is worth to you. If your leverage today is "we can buy this from someone who is not our IdP," that leverage has an expiry date on it.
It also lands eight days after Okta announced Agent Gateway in research release, Agent-to-Agent Connections in general availability, and Resource Access Certifications for AI Agents in early access on July 22. Those are runtime controls — deciding what an agent may touch at the moment it reaches. Permiso is the other half: detecting what the agent actually did afterwards. Buying the detection eight days after shipping the control is a coherent strategy, and coherent strategies are exactly the ones that get bundled. Okta's own materials cite Cloud Security Alliance research finding that 84% of organisations doubt they could pass a compliance audit focused on agent behaviour or access controls, and Gravitee research that 88% report suspected or confirmed AI agent security incidents. Discount both accordingly: the CSA survey was commissioned by Strata Identity, an identity vendor selling into this exact category, and drew 285 self-selected online responses fielded in September and October 2025 — it was published in February 2026, but the fieldwork predates most of the agent deployments it is now used to describe. Gravitee sells agent management and AI security, and the 88% is self-reported and counts suspected incidents alongside confirmed ones. Vendor-sponsored surveys run hot, and these are being quoted by a third vendor to justify a purchase. Even heavily discounted, demand is not the question. Who captures it is.
What the Pre-Close Window Is Actually Worth
The window is worth exactly one thing: written commitments from a counterparty that still needs your signature. Permiso today is a company with a renewal quota and a deal to get through closing conditions. It has every reason to keep customers happy and no ability to make roadmap promises on Okta's behalf — which is the real limit on what you can extract, and you should know that going in.
What you can get is narrower and still useful. A multi-year price lock survives a change of control. A minimum support and availability term survives. A data export and portability clause survives. An assignment or change-of-control provision — read yours, most enterprise SaaS agreements have one — may give you consent rights or a termination right you did not know you were holding. None of that requires Okta's cooperation, because none of it is a promise about the future product; it is a constraint on the contract that gets assigned.
If you are not a Permiso customer, the window matters differently. This is far from the first identity-adjacent acquisition to land in this category inside a year, after AppViewX absorbed Eos to launch agent identity security and a broader wave of execution-layer acquisitions pulled point tools into platforms. If you have an in-flight evaluation of a standalone ITDR or non-human-identity vendor, the correct response is not to cancel it. It is to ask each remaining bidder, in writing, what happens to your contract if they are acquired — and to notice that a vendor whose answer is credible has just become more valuable, not less. The independents left in this category, including Oasis Security, are now negotiating against a shorter list of alternatives than they were last week, which cuts both ways on price.
And if you are an Okta shop already, the calculus inverts. You are about to get, bundled or add-on, a capability you may currently be paying a second vendor for. Do not sign a three-year renewal with that second vendor in August. The comparison between Ping, Okta and Entra on agent identity looks different when one of the three has just bought the detection layer that the other two partner for.
Do This Before the Deal Closes
This Week:
- Pull every contract you hold with Permiso or with any standalone ITDR / non-human-identity vendor. Find the assignment and change-of-control clause, the auto-renewal date, and the notice period. Put the three dates on one page next to October 31, 2026.
- If your renewal falls before close, treat it as your last negotiation with an independent company. If it falls after, assume you are negotiating with Okta for AI Agents pricing and plan accordingly.
- Inventory what your current ITDR actually covers that your IdP does not — AWS IAM roles, Entra service principals, Google Cloud service accounts, CI/CD tokens, agent credentials. That list is your requirements document, and it is the only thing that tells you whether a bundled replacement is equivalent or a downgrade. Most organisations discover the answer late, which is how machine identities came to outnumber humans by two orders of magnitude without a governance owner.
Before Close — Which Could Come Any Time From August 1:
- Ask Permiso, in writing, for four things: standalone availability for customers whose primary IdP is not Okta, price protection through your next two renewals, a minimum support term post-close, and a documented data-export path for your identity graph and detection history. Get the answer in email, not on a call. A refusal is also an answer.
- Keep a second bid alive on any in-flight evaluation. A competing quote you can actually execute is the only thing that makes clause 4 negotiable.
- Ask your Okta account team directly which tier Permiso's capability lands in and whether non-Okta identity sources stay in scope. They will not have a final answer before close. Ask anyway, in writing, and date the reply — it is the baseline you will hold them to next year.
Before Renewal Season:
- Re-run your agent access review with the assumption that detection and enforcement will come from the same vendor. That is a real concentration decision, of the same shape as every other platform consolidation that traded optionality for convenience, and it deserves an explicit sign-off rather than a default. If your security team's answer to "who watches the IdP" is now "the IdP," that should be a decision someone made on purpose.
The Bottom Line
Every identity category eventually gets absorbed by the identity provider — that is the arc, and it has run before with single sign-on, with MFA, with governance, and now with threat detection. The vendors who resisted absorption did it by being genuinely neutral, and neutrality is the first thing that gets quietly repriced after a close. Okta paid roughly $200 million for a view of identities that are not Okta's, and its own product chief said out loud that the view is the point. He may well mean it. Enterprise buyers who signed multi-year deals with the last generation of independent agent-security vendors heard similar things, and the ones who got it in writing are the ones still holding the terms they agreed to.
The deal has been announced. It has not closed. That distinction is worth money for ninety more days at the outside — quite possibly fewer — and then it is worth nothing.
Continue Reading
- Ping vs Okta vs Entra: Best AI Agent Identity in 2026?
- 9 in 10 Enterprises Breached Through Identity No One Manages
- AppViewX Launches AI Agent Security After Eos Acquisition
- 3 Giants Declare War on Unsecured AI Agents: IBM, OpenAI, Okta
- Oasis Security Raises $120M for AI Agent Access
- AI Agent Identity Crisis: 92% of CISOs Are Flying Blind
- 5 Acquisitions in 14 Days. The AI Agent Stack Is Being Bought.
- $60B Bought Cursor. Your Dev Team Is the Product Now.
