Omada bought EmpowerID to stop AI agents mid-action, but the announcement says nothing about EmpowerID's other product: a full identity governance suite that overlaps almost entirely with Omada's own. If you run EmpowerID, your platform now belongs to a direct competitor with no published commitment on product line, support or the customisations your deployment depends on. If you run Omada, you have been told agent controls are coming but not when they reach your deployment model. Both groups should get answers in writing before their next renewal.
Omada announced the acquisition on September 24, 2026. Terms were not disclosed. EmpowerID CEO and co-founder Patrick Parker joins Omada as chief innovation officer to oversee the technology integration. Everything else about what happens to an EmpowerID customer on Monday is absent — Omada's own press page contains no transition plan, migration path, support timeline or integration schedule.
What Did Omada Actually Buy?
Omada bought runtime authorization for AI agents — the enforcement layer its own agent product did not have. Three months earlier, Omada launched Omada Agent Governance on June 15, 2026, a product built to tell you who owns every agent, what it can reach, and whether that access is used. As Help Net Security's write-up of the launch lists it, the capabilities are visibility, ownership assignment, dependency mapping and trimming over-privileged identities. That is governance after the fact: it finds the problem at the next review.
Runtime authorization is the other half. It is a policy decision made at the moment an agent tries to act — this agent, on behalf of this person, calling this tool on this resource, right now — with the power to say no. Omada CEO Jakob H. Kraglund put the pitch plainly in the release: the deal means Omada "can also stop those agents the moment they step outside the lines – in real time, not after the fact."
EmpowerID brings the machinery for that:
- A standards-based policy decision point. EmpowerID says its PDP passed OpenID AuthZEN 1.1 interoperability testing, meaning an enforcement point from another vendor can ask it "can this subject take this action on this resource?" in a standard format. AuthZEN is the OpenID Foundation's API for exactly that question; it is what keeps a policy engine swappable.
- An MCP gateway. The EmpowerID MCP Gateway "verifies who an agent represents, scopes tool discovery, authorizes each invocation through Governed Authorization, enforces constraints, protects downstream credentials, and records correlated action evidence."
- Connector tooling. KuppingerCole's analysis credits EmpowerID with 300+ pre-built connectors and AI-assisted connector building it reports at 15 to 30 minutes per connector — a claim worth testing yourself before it shows up in a statement of work.
This is a reasonable buy. Agent authorization at the moment of action is the control that matters most, and we argued in our agent authorization buyer's guide that standing privilege is the whole problem. Omada needed an enforcement layer; it bought one with a standards story instead of building from scratch.
Why Is the IGA Overlap a Problem for EmpowerID Customers?
Because EmpowerID is not an agent-authorization startup — it is a full IGA platform, and Omada already sells one. EmpowerID, founded in 2005 and based in Dublin, Ohio, lists Identity Governance (IGA) alongside agent governance on its own homepage, which now reads "EmpowerID by Omada". Its showcase customer is a global manufacturer governing 569,000 identities with 4.3 million group changes a month. That is not a feature tuck-in. That is a competing core product.
KuppingerCole senior analyst Nitish Deshpande spells out the tension: Omada approaches IGA "from a commercial off-the-shelf (COTS) perspective with standardized user experience and process frameworks," while EmpowerID takes "a developer-centric approach focused on flexible, AI-powered customization." He warns that "combining a standardized platform with a highly configurable one will take a while," and that "if EmpowerID ends up as a separate product line next to Omada Identity, most customers would see little benefit from the deal."
Steel-man Omada's silence first. Acquirers rarely announce a sunset in the press release; doing so on day one would start a competitive poaching campaign against the customer base they just paid for. Keeping Parker in a senior role suggests the EmpowerID architecture is meant to survive, not be stripped for parts.
But the structural pull is obvious. Two IGA engines, one company, one R&D budget. The standardised platform is the one that scales across a SaaS customer base; the heavily customised one is the one that is expensive to support. If you are an EmpowerID customer whose deployment rests on custom workflows, the risk is not that the product dies next quarter. It is that it quietly stops getting investment while the roadmap moves to Omada Identity — and your customisations become the migration cost you pay later, on the vendor's timeline instead of yours.
What Does the Deployment Model Mismatch Mean?
The two companies run different deployment architectures, so "agent controls are coming" means different things depending on how you host. EmpowerID offers SaaS or self-managed deployment across data centres, private, public or sovereign cloud — all single-tenant. Omada's portfolio, per its June 23 Omada Identity Sovereign announcement, covers multi-tenant SaaS, on-premises, and a containerised sovereign edition targeted for early 2027.
That matters to both customer bases:
- Omada customers on-premises or waiting for Sovereign should expect the agent-runtime pieces to land first wherever integration is easiest, which is rarely the self-hosted estate. KuppingerCole's advice to Omada customers is to ask "when EmpowerID capabilities will be available within your current deployment model."
- EmpowerID customers on single-tenant or self-managed need to know whether a converged product will preserve that isolation, or whether "convergence" means moving into a multi-tenant cloud your security team did not approve.
EmpowerID's own documentation already hedges the agent features. The MCP Gateway page says feature availability "varies by edition, deployment, and release. Confirm scope with EmpowerID before customer-specific commitments." That sentence was true before the deal. After the deal, "confirm with EmpowerID" means confirming with Omada.
How Does This Compare With Other Agent-Identity Deals?
The other buyers in this wave told customers more on day one. When SailPoint closed its Entro Security acquisition on June 29, 2026, it stated that Entro's products were "available now to SailPoint customers as standalone offerings" while native integration continued. That is a concrete availability statement a buyer can hold a vendor to.
The consolidation is real and fast. KuppingerCole's comparison table lists ServiceNow–Veza at roughly $1bn, SailPoint–Entro at roughly $200m and Cyera–Oasis at roughly $1bn, all announced since December 2025; TechCrunch reported the Cyera deal on July 28 at approximately $1 billion, mostly cash. We covered the same pattern when Okta bought Permiso and when ServiceNow folded Veza into its security stack.
The difference with Omada–EmpowerID is the overlap. SailPoint bought a non-human-identity product it did not have. Cyera bought identity, which it did not have. Omada bought agent enforcement it did not have — and an IGA suite it already had. That second half is where customers get stranded. We saw the version of this with Kiteworks and Bonfy, where the useful question was which customer got a standalone commitment in writing and which did not.
KuppingerCole's summary line is the one to take into procurement: "Agent governance is turning into a standard expectation for IGA platforms." If that is true, every IGA vendor you evaluate should show you runtime enforcement working today, not on a post-merger roadmap. Our comparison of Okta, Entra Agent ID and SailPoint is a starting point; vendors with their own agent-identity pages, such as Okta for AI Agents and Saviynt Zuma, belong on the shortlist.
What to Do Before Your Next Renewal
The leverage you have is the renewal date; use it before the integration plan is written without you.
This Week:
- EmpowerID customers: pull your contract and find three clauses — assignment/change of control, support term and end-of-life notice. Write down what notice, if any, the contract requires before the product line you run can be retired — and note if it says nothing.
- Inventory your customisations. List every custom workflow, connector and policy in your EmpowerID deployment, with an owner and a rough rebuild estimate. This is your migration exposure, and you want the number before the vendor gives you theirs.
- Omada customers: send your account team one question in writing — on what date will runtime agent authorization be available in your deployment model (multi-tenant SaaS, on-prem, or Sovereign)?
This Month:
- EmpowerID customers: ask for a written support commitment — a minimum support term for the current product line, a named roadmap for your edition, and a commitment that your customisations will be carried forward or migrated at the vendor's cost. KuppingerCole's own recommendation is to "confirm support commitments and the future of the product line you run today."
- Test the AuthZEN claim. If you are buying on standards, have your team point a non-EmpowerID enforcement point at the PDP and run your own authorization requests. A standard you have not tested is a brochure.
- Evaluators: make runtime agent enforcement a pass/fail item. Test discovery, ownership, certification and a live block of an out-of-policy agent action during the proof of concept — not a roadmap slide.
Before Renewal:
- Tie term length to the roadmap. If Omada cannot put a date on convergence, sign one year, not three. A short term costs you a discount; a long term on an orphaned product costs you a forced migration.
- Negotiate a migration credit. If the product line you run is later retired, the cost of moving to Omada Identity should be the vendor's, written into this renewal while you still have the choice to leave.
The Bottom Line
Omada made a sound strategic buy and a thin customer announcement, and the gap between the two is yours to close. Every enterprise software merger that has put two competing products under one roof has produced the same quiet category: the edition that is still supported and no longer improved. Runtime authorization for agents is worth having, and EmpowerID built a credible version of it. But an acquisition that brings two overlapping IGA suites under one roof will eventually pick one, and the press release will not be where you learn which.
Ask now, while the answer is still negotiable.
Continue Reading
- Agent Authorization: Standing Privilege Is the Whole Problem
- Okta vs Entra Agent ID vs SailPoint: Two Issue, One Governs
- Okta Bought Permiso. Your Leverage Expires Oct 31.
- MCP Server Governance: Enforce at the Client, Not the Registry
- Kiteworks Bought Bonfy. Ask for the Terms WAMNET Got.
- 9 in 10 Enterprises Breached Through Identity No One Manages
