Omada Buys EmpowerID Without a Word on EmpowerID's IGA Suite

Omada bought EmpowerID for runtime AI-agent authorization, but the two vendors' IGA suites overlap and the announcement says nothing about EmpowerID's product line or support. Get commitments in writing before renewal.

By Rajesh Beri·September 26, 2026·9 min read
Share:
A server rack in a dim data centre with two nearly identical identity-appliance units mounted one above the other, one unit's status lights on and the other's fading dark, a printed contract lying on top of the rack.

Illustration generated using AI

Omada bought EmpowerID to stop AI agents mid-action, but the announcement says nothing about EmpowerID's other product: a full identity governance suite that overlaps almost entirely with Omada's own. If you run EmpowerID, your platform now belongs to a direct competitor with no published commitment on product line, support or the customisations your deployment depends on. If you run Omada, you have been told agent controls are coming but not when they reach your deployment model. Both groups should get answers in writing before their next renewal.

Omada announced the acquisition on September 24, 2026. Terms were not disclosed. EmpowerID CEO and co-founder Patrick Parker joins Omada as chief innovation officer to oversee the technology integration. Everything else about what happens to an EmpowerID customer on Monday is absent — Omada's own press page contains no transition plan, migration path, support timeline or integration schedule.


What Did Omada Actually Buy?

Omada bought runtime authorization for AI agents — the enforcement layer its own agent product did not have. Three months earlier, Omada launched Omada Agent Governance on June 15, 2026, a product built to tell you who owns every agent, what it can reach, and whether that access is used. As Help Net Security's write-up of the launch lists it, the capabilities are visibility, ownership assignment, dependency mapping and trimming over-privileged identities. That is governance after the fact: it finds the problem at the next review.

Runtime authorization is the other half. It is a policy decision made at the moment an agent tries to act — this agent, on behalf of this person, calling this tool on this resource, right now — with the power to say no. Omada CEO Jakob H. Kraglund put the pitch plainly in the release: the deal means Omada "can also stop those agents the moment they step outside the lines – in real time, not after the fact."

EmpowerID brings the machinery for that:

  • A standards-based policy decision point. EmpowerID says its PDP passed OpenID AuthZEN 1.1 interoperability testing, meaning an enforcement point from another vendor can ask it "can this subject take this action on this resource?" in a standard format. AuthZEN is the OpenID Foundation's API for exactly that question; it is what keeps a policy engine swappable.
  • An MCP gateway. The EmpowerID MCP Gateway "verifies who an agent represents, scopes tool discovery, authorizes each invocation through Governed Authorization, enforces constraints, protects downstream credentials, and records correlated action evidence."
  • Connector tooling. KuppingerCole's analysis credits EmpowerID with 300+ pre-built connectors and AI-assisted connector building it reports at 15 to 30 minutes per connector — a claim worth testing yourself before it shows up in a statement of work.

This is a reasonable buy. Agent authorization at the moment of action is the control that matters most, and we argued in our agent authorization buyer's guide that standing privilege is the whole problem. Omada needed an enforcement layer; it bought one with a standards story instead of building from scratch.


Why Is the IGA Overlap a Problem for EmpowerID Customers?

Because EmpowerID is not an agent-authorization startup — it is a full IGA platform, and Omada already sells one. EmpowerID, founded in 2005 and based in Dublin, Ohio, lists Identity Governance (IGA) alongside agent governance on its own homepage, which now reads "EmpowerID by Omada". Its showcase customer is a global manufacturer governing 569,000 identities with 4.3 million group changes a month. That is not a feature tuck-in. That is a competing core product.

KuppingerCole senior analyst Nitish Deshpande spells out the tension: Omada approaches IGA "from a commercial off-the-shelf (COTS) perspective with standardized user experience and process frameworks," while EmpowerID takes "a developer-centric approach focused on flexible, AI-powered customization." He warns that "combining a standardized platform with a highly configurable one will take a while," and that "if EmpowerID ends up as a separate product line next to Omada Identity, most customers would see little benefit from the deal."

Steel-man Omada's silence first. Acquirers rarely announce a sunset in the press release; doing so on day one would start a competitive poaching campaign against the customer base they just paid for. Keeping Parker in a senior role suggests the EmpowerID architecture is meant to survive, not be stripped for parts.

But the structural pull is obvious. Two IGA engines, one company, one R&D budget. The standardised platform is the one that scales across a SaaS customer base; the heavily customised one is the one that is expensive to support. If you are an EmpowerID customer whose deployment rests on custom workflows, the risk is not that the product dies next quarter. It is that it quietly stops getting investment while the roadmap moves to Omada Identity — and your customisations become the migration cost you pay later, on the vendor's timeline instead of yours.


What Does the Deployment Model Mismatch Mean?

The two companies run different deployment architectures, so "agent controls are coming" means different things depending on how you host. EmpowerID offers SaaS or self-managed deployment across data centres, private, public or sovereign cloud — all single-tenant. Omada's portfolio, per its June 23 Omada Identity Sovereign announcement, covers multi-tenant SaaS, on-premises, and a containerised sovereign edition targeted for early 2027.

That matters to both customer bases:

  • Omada customers on-premises or waiting for Sovereign should expect the agent-runtime pieces to land first wherever integration is easiest, which is rarely the self-hosted estate. KuppingerCole's advice to Omada customers is to ask "when EmpowerID capabilities will be available within your current deployment model."
  • EmpowerID customers on single-tenant or self-managed need to know whether a converged product will preserve that isolation, or whether "convergence" means moving into a multi-tenant cloud your security team did not approve.

EmpowerID's own documentation already hedges the agent features. The MCP Gateway page says feature availability "varies by edition, deployment, and release. Confirm scope with EmpowerID before customer-specific commitments." That sentence was true before the deal. After the deal, "confirm with EmpowerID" means confirming with Omada.


How Does This Compare With Other Agent-Identity Deals?

The other buyers in this wave told customers more on day one. When SailPoint closed its Entro Security acquisition on June 29, 2026, it stated that Entro's products were "available now to SailPoint customers as standalone offerings" while native integration continued. That is a concrete availability statement a buyer can hold a vendor to.

The consolidation is real and fast. KuppingerCole's comparison table lists ServiceNow–Veza at roughly $1bn, SailPoint–Entro at roughly $200m and Cyera–Oasis at roughly $1bn, all announced since December 2025; TechCrunch reported the Cyera deal on July 28 at approximately $1 billion, mostly cash. We covered the same pattern when Okta bought Permiso and when ServiceNow folded Veza into its security stack.

The difference with Omada–EmpowerID is the overlap. SailPoint bought a non-human-identity product it did not have. Cyera bought identity, which it did not have. Omada bought agent enforcement it did not have — and an IGA suite it already had. That second half is where customers get stranded. We saw the version of this with Kiteworks and Bonfy, where the useful question was which customer got a standalone commitment in writing and which did not.

KuppingerCole's summary line is the one to take into procurement: "Agent governance is turning into a standard expectation for IGA platforms." If that is true, every IGA vendor you evaluate should show you runtime enforcement working today, not on a post-merger roadmap. Our comparison of Okta, Entra Agent ID and SailPoint is a starting point; vendors with their own agent-identity pages, such as Okta for AI Agents and Saviynt Zuma, belong on the shortlist.


What to Do Before Your Next Renewal

The leverage you have is the renewal date; use it before the integration plan is written without you.

This Week:

  1. EmpowerID customers: pull your contract and find three clauses — assignment/change of control, support term and end-of-life notice. Write down what notice, if any, the contract requires before the product line you run can be retired — and note if it says nothing.
  2. Inventory your customisations. List every custom workflow, connector and policy in your EmpowerID deployment, with an owner and a rough rebuild estimate. This is your migration exposure, and you want the number before the vendor gives you theirs.
  3. Omada customers: send your account team one question in writing — on what date will runtime agent authorization be available in your deployment model (multi-tenant SaaS, on-prem, or Sovereign)?

This Month:

  1. EmpowerID customers: ask for a written support commitment — a minimum support term for the current product line, a named roadmap for your edition, and a commitment that your customisations will be carried forward or migrated at the vendor's cost. KuppingerCole's own recommendation is to "confirm support commitments and the future of the product line you run today."
  2. Test the AuthZEN claim. If you are buying on standards, have your team point a non-EmpowerID enforcement point at the PDP and run your own authorization requests. A standard you have not tested is a brochure.
  3. Evaluators: make runtime agent enforcement a pass/fail item. Test discovery, ownership, certification and a live block of an out-of-policy agent action during the proof of concept — not a roadmap slide.

Before Renewal:

  1. Tie term length to the roadmap. If Omada cannot put a date on convergence, sign one year, not three. A short term costs you a discount; a long term on an orphaned product costs you a forced migration.
  2. Negotiate a migration credit. If the product line you run is later retired, the cost of moving to Omada Identity should be the vendor's, written into this renewal while you still have the choice to leave.

The Bottom Line

Omada made a sound strategic buy and a thin customer announcement, and the gap between the two is yours to close. Every enterprise software merger that has put two competing products under one roof has produced the same quiet category: the edition that is still supported and no longer improved. Runtime authorization for agents is worth having, and EmpowerID built a credible version of it. But an acquisition that brings two overlapping IGA suites under one roof will eventually pick one, and the press release will not be where you learn which.

Ask now, while the answer is still negotiable.

Continue Reading

Share:

Frequently Asked Questions

Why did Omada acquire EmpowerID?

For runtime authorization of AI agents: the ability to decide in real time what an agent may do and stop it when it exceeds its bounds. Omada's June 2026 Agent Governance product focused on discovery, ownership and access review; EmpowerID adds an AuthZEN-tested policy decision point and an MCP gateway that authorizes each tool call.

What happens to EmpowerID's identity governance product after the Omada acquisition?

Neither Omada's press release nor its press page makes a commitment on EmpowerID's product line, support timeline or migration path. KuppingerCole advises EmpowerID customers to confirm support commitments and ask how heavy customisations will be carried forward as the platforms converge.

What should EmpowerID customers do before renewing?

Check the contract's change-of-control, support-term and end-of-life clauses, inventory every customisation with a rebuild estimate, and ask for a written minimum support term plus a migration commitment at the vendor's cost. If no convergence date is offered, prefer a one-year term over a multi-year one.

When will Omada customers get EmpowerID's agent controls?

No date has been published. Omada sells multi-tenant SaaS, on-premises and a Sovereign edition targeted for early 2027, and EmpowerID's own documentation says agent feature availability varies by edition and deployment. Omada customers should ask for a date specific to their deployment model.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →