Okta is expanding its push into AI and cloud security with a definitive agreement to acquire Permiso Security, adding identity threat detection and response (ITDR) capabilities designed to protect human users, machine identities, and AI agents across enterprise environments.
The acquisition reflects a broader shift in enterprise cybersecurity as organizations deploy increasing numbers of AI-powered applications and autonomous agents. While identity has long been the foundation of enterprise security, the rise of agentic AI has introduced new attack surfaces that traditional authentication tools alone cannot address.
Permiso’s technology will become part of the Okta Platform, adding behavioral analytics, runtime threat detection, and identity risk signals that help organizations identify suspicious activity after authentication has already occurred.
Expanding Identity Security Beyond Login
According to Okta, enterprises are managing a rapidly growing mix of employees, service accounts, APIs, cloud workloads, and AI agents. This expanding identity landscape is making it more difficult for security teams to monitor privileged access and detect malicious behavior.
Permiso brings capabilities that analyze more than 2,500 threat signals across over 70 identity and cloud platforms. Those signals include excessive permissions, unused credentials, unusual AI agent behavior, policy violations, and other indicators that could signal compromised identities.
Once integrated into Okta, the technology is expected to provide organizations with continuous monitoring across the entire identity lifecycle rather than focusing solely on authentication.
AI Agents Create New Security Challenges
The announcement highlights the growing importance of securing AI agents as enterprises automate workflows across cloud environments.
Okta said the combined platform will allow organizations to:
- Detect sophisticated identity attacks using behavioral analytics alongside authentication signals.
- Monitor AI agents, machine identities, and privileged accounts for risky activity.
- Investigate and contain compromised AI agents in real time.
- Extend visibility across SaaS applications and multi-cloud environments.
One of the more notable additions is SandyClaw, Permiso’s dynamic sandbox designed to analyze AI agent skills and prompts before they are deployed into production environments. The platform aims to detect AI supply chain attacks by evaluating agent behavior in an isolated environment before those skills interact with enterprise systems.
Strengthening Security Operations
The acquisition also expands Okta’s role inside enterprise security operations centers.
Permiso’s research organization, P0 Labs, will join Okta to strengthen threat intelligence and behavioral detection capabilities. Together with Okta Threat Intelligence, the combined teams are expected to improve detection of identity-based attacks that occur after users or AI systems have successfully authenticated.
The move positions Okta beyond traditional identity and access management by adding continuous monitoring and response capabilities that security teams increasingly require as AI adoption accelerates.
Customer Demand Growing
The announcement comes as enterprises face increasing pressure to secure AI deployments.
Okta cited research showing that 58% of executives experienced an AI-related security incident or near miss during the past year, underscoring the need for greater visibility into both human and non-human identities.
Autodesk, an existing Permiso customer, said the platform has helped improve visibility across identities throughout its cloud environment as part of its broader cloud security strategy.
The Bottom Line
As AI agents become active participants inside enterprise applications, identity security is evolving from managing user logins to continuously monitoring the behavior of humans, machines, and autonomous software. Okta’s planned acquisition of Permiso signals that identity threat detection is becoming a core requirement for enterprise AI security, giving organizations greater visibility into emerging risks while extending protection beyond authentication alone.

