VYPR
advisoryPublished Jul 30, 2026· 1 source

Okta Acquires Permiso Security to Bolster Identity Threat Detection with AI

Okta is acquiring Permiso Security to enhance its identity threat detection and response capabilities, integrating AI-driven analysis of post-login activities and broader identity ecosystems.

Okta announced Thursday it has signed a deal to buy Permiso Security, a cloud-based firm that tracks threats tied to human, machine, and AI-driven digital identities. Permiso specializes in spotting risks after a user or system has already logged in, an area the industry refers to as identity threat detection and response (ITDR).

The company draws on more than 2,500 signals gathered from over 70 identity-related partners to flag issues such as excessive access permissions, unused credentials, unusual behavior from AI agents, and violations of internal security policies. Ely Kahn, Okta’s chief product officer, told CyberScoop that Permiso will allow Okta to merge two functions that have operated separately: real-time threat detection and identity security posture management.

"Today those are two separate products that don't really talk to each other," he said. Combining them, Kahn said, produces sharper alerts for security teams. As an example, he described a hypothetical scenario where a dormant administrator account is flagged by posture-management tools that later shows a login from an unfamiliar IP address. "By combining those things, you now have a very high-confidence, high-fidelity alert that's more actionable by a security operations team," Kahn said.

"A security operations team on its own might not care about the dormant account, but when you combine that with some threat signals, then it becomes a higher critical-level alert," he added. A crucial part of the deal, according to Kahn, is that Permiso will bring visibility beyond Okta’s current threat detection products, telling CyberScoop that customers also rely on other identity systems, such as Microsoft Entra ID or Active Directory, that fall outside that view.

"For us to be a real player in the identity security space, we have to look beyond the Okta perspective and give folks a full view into their identity threats," he stated. The acquisition also fits into a security landscape reshaped by artificial intelligence. According to figures cited by Okta, 58% of executives say their organizations experienced an AI-related security incident or a near miss within the past year.

That trend has pushed identity companies like Okta to expand beyond authentication and into continuous monitoring of what accounts, including AI agents, actually do once inside a system. "Agents will be breached," Kahn warned. "The most important thing you can do is ensure that if an agent is compromised, the blast radius is small," through a narrowly defined, revocable identity tied to each agent.

Among the capabilities Okta says it will gain is a tool called SandyClaw, which tests AI agent skills and prompts in an isolated environment before they are allowed into a customer's systems, aiming to catch supply-chain attacks embedded in AI tools. Other planned additions include expanded tracking of AI agent behavior across cloud platforms and software-as-a-service tools, and automated systems to investigate and isolate AI agents that appear compromised or misconfigured.

The transaction is expected to close in the third quarter of Okta's 2027 fiscal year, pending standard regulatory and closing conditions. Terms of the acquisition, including its purchase price, were not disclosed. This move positions Okta to offer a more comprehensive and integrated approach to identity security in an era increasingly defined by AI-driven threats and complex hybrid environments.

Synthesized by Vypr AI