Okta has signed a definitive agreement to acquire Permiso Security, a cloud-native identity security platform that detects and mitigates threats across human, non-human, and AI agent identities in multi-cloud environments. The deal, valued at roughly $200 million in an almost all-cash transaction per TechCrunch sources, is one of Okta’s largest acquisitions since the $6.5 billion Auth0 deal in 2021.
The acquisition extends Okta’s identity security fabric into identity threat detection and response (ITDR) — a capability gap that has widened as AI agents, machine identities, and non-human identities proliferate faster than traditional identity governance can track them.
The NHI Explosion Meets a Detection Gap
Permiso brings more than 2,500 research-driven identity risk signals across 70-plus identity partners, behavioral analytics for detecting anomalous access patterns, and two capabilities specifically designed for the AI agent era: automated AI identity response to investigate and contain compromised or misconfigured agents, and SandyClaw — the first dynamic sandbox for detecting AI supply chain attacks in agent skills and prompts.
The deal lands against a structural backdrop. The CSA reported in July that the non-human identity-to-human ratio has reached 144:1, with only 21% of organizations having NHI governance programs. AI agent identities are the fastest-growing segment within that gap — and the least governed.
“Permiso will extend Okta’s identity security fabric with proven identity threat detection and response capabilities, and an incredible threat research and security team that will advance Okta’s threat detection and prevention capabilities,” said Ely Kahn, Okta’s Chief Product Officer, who will lead the integration.
From FireEye to AI Agent Security
Permiso was co-founded by Paul Nguyen and Jason Martin, both former executives at FireEye (now Trellix). The company’s P0 Labs research team has published work on identity-based attack techniques, and its SandyClaw sandbox represents the first dedicated tool for detecting malicious payloads inside AI agent capabilities before they execute.
SandyClaw addresses the same class of supply chain attack that Forkast has tracked across the AI agent ecosystem — from HalluSquatting’s 85% hit rate on hallucinated package names, to AgentBaiting’s 800-plus fake AI Skills delivering StealC malware, to Unit 42’s documentation of malicious skills surviving VirusTotal scans in agent marketplaces. The attack surface is the AI agent’s tool chain: the skills, prompts, MCP servers, and plugins that agents load and trust at runtime.
“Joining the leading, neutral identity provider means that work now reaches far more organizations than we could have on our own,” said Jason Martin, Permiso’s co-founder.
“Combining our technology and expertise with Okta’s platform is what makes comprehensive identity threat protection possible at this scale,” said Paul Nguyen, the other co-founder.
The Platform Play
The acquisition positions Okta as the first major identity provider to offer unified ITDR across human, machine, and AI agent identities within a single platform. Okta’s existing strength — managing authentication and authorization at scale — pairs with Permiso’s detection and response layer, creating coverage from identity posture management through active threat containment.
Ely Kahn will lead the integration. The deal is expected to close in the third quarter of Okta’s fiscal year 2027 (August through October 2026), subject to customary closing conditions.
For the T/I/S beat, the signal is structural: the identity security market is consolidating around the recognition that AI agent identities are not a future problem. They are a present attack surface that existing IAM tools were not designed to see, let alone defend. Permiso’s SandyClaw sandbox — purpose-built to analyze agent skills and prompts for malicious payloads — is the clearest vendor acknowledgment yet that AI agent supply chains are already compromised at the semantic layer.
The 144:1 NHI-to-human ratio means most identity activity in enterprise environments is already non-human. The question is no longer whether AI agents need dedicated identity threat detection. It is how fast the market can close the gap before the attack surface outpaces the defenses.
