AI Agents Need Security Too: Why Okta Is Paying Nearly $200 Million for Permiso
Artificial intelligence is no longer limited to answering questions or generating content.
Businesses are increasingly deploying AI agents that can access company systems, analyze information, communicate with software tools, and complete tasks with limited human supervision.
That creates a new cybersecurity challenge: How do you control an AI system that has its own digital identity, permissions, and access to sensitive business data?
Okta believes this problem could become a major part of the cybersecurity industry.
The identity management company has signed a definitive agreement to acquire Permiso Security, a startup that specializes in detecting suspicious activity involving employees, applications, service accounts, and AI agents. Okta did not publicly disclose the purchase price, but TechCrunch reported that the transaction is valued at just under $200 million and is structured primarily as a cash deal.
The acquisition is expected to close during the third quarter of Okta’s fiscal 2027, subject to the usual regulatory and closing requirements.
What Does Permiso Security Do?
Permiso Security helps companies understand what happens after someone or something successfully logs into a system.
Traditional identity security tools often focus on the login stage:
- Is the username correct?
- Was the password accepted?
- Did the user complete multifactor authentication?
- Should this account be allowed into the system?
But a successful login does not guarantee that everything happening afterward is safe.
An attacker may steal legitimate credentials, sign in as an authorized user, and then quietly move through cloud applications, databases, and business systems.
Permiso’s technology continuously tracks the activities of human users, software services, machines, and AI agents across cloud, software-as-a-service, and on-premises environments. Its platform connects identities with their credentials, permissions, machines, agents, and real-time actions.
This helps security teams detect behaviors such as:
- A compromised account accessing unusual systems
- An AI agent using permissions it should not need
- A service account moving sensitive information
- Stolen credentials being used to move between cloud environments
- An authorized identity behaving in an unauthorized way
In simple terms, Permiso does not only ask, “Who logged in?”
It also asks, “What did that identity do after it got inside?”
Why Okta Wants Permiso
Okta is best known for identity and access management tools that help organizations control how employees and customers sign into applications.
However, the identity landscape is changing.
Companies now have to manage far more than employee accounts. Their networks may include:
- AI agents
- Automated applications
- Cloud workloads
- Service accounts
- Software bots
- Application programming interfaces
- Machine-to-machine connections
These are often described as non-human identities because they can access systems and perform actions without being traditional human users.
Okta already promotes products designed to secure AI agents and non-human identities. Acquiring Permiso gives the company additional identity threat detection and response capabilities, allowing it to monitor what these identities do after authentication.
That could help Okta evolve from being primarily a company that controls access into one that also detects dangerous activity throughout the entire identity lifecycle.
AI Agents Are Becoming Digital Employees
An AI agent can be given a goal and allowed to take multiple actions to complete it.
For example, a company might deploy an AI agent that can:
- Read incoming customer emails
- Access customer records
- Review previous transactions
- Generate a response
- Issue a refund
- Update the customer relationship management system
To perform those tasks, the agent needs access to several company systems.
That access creates risk.
If the agent is poorly configured, compromised, manipulated through malicious instructions, or granted excessive permissions, it may expose confidential information or take damaging actions at machine speed.
Permiso warns that AI agents can inherit permissions, cross between environments, and become invisible to traditional tools that cannot follow the complete authentication chain.
This is why AI agents must increasingly be treated like digital employees.
They need:
- Unique identities
- Clearly defined permissions
- Limited access
- Continuous monitoring
- Activity logs
- Automatic access removal
- Security policies controlling what they can do
Giving an AI agent unlimited access simply because it needs to complete a task could become the cybersecurity equivalent of giving every employee the master key to the building.
Permiso’s SandyClaw Adds Another Layer of Protection
Permiso has also been developing technology designed specifically for AI agent security.
Its SandyClaw platform analyzes AI agent skills in an isolated sandbox before those skills are deployed inside a company’s environment.
An AI agent “skill” is a capability, integration, or instruction set that allows the agent to perform a particular task. A malicious or compromised skill could secretly steal credentials, access restricted information, or execute unauthorized commands.
Sandbox testing allows security teams to observe how the skill behaves in a controlled environment before trusting it with real company systems.
This could become increasingly important as businesses download AI agent tools, connectors, prompts, and skills from third-party marketplaces.
The same way companies scan software before installing it, they may eventually need to test every AI agent skill before allowing it into the workplace.
Why the Reported $200 Million Price Matters
Permiso reportedly raised approximately $29 million before the acquisition, including an $18.5 million Series A funding round in 2024. TechCrunch reported that the round valued the startup at roughly $80 million after the investment.
A reported acquisition price approaching $200 million would therefore represent a significant increase over that previous valuation.
More importantly, the deal suggests that established cybersecurity companies believe AI identity protection could become a valuable market.
The biggest opportunity in enterprise AI may not only be building intelligent agents.
It may also be securing, monitoring, governing, and auditing them.
What Businesses Should Learn From the Acquisition
1. AI agents should not share employee accounts
Every AI agent should have its own identity. Allowing an agent to operate through a shared employee account makes it difficult to determine whether an action was performed by the employee, the agent, or an attacker.
2. Authentication is only the beginning
Multifactor authentication and strong passwords remain important, but companies must also monitor what authorized identities do after gaining access.
A legitimate login can still lead to a serious breach.
3. AI agents should receive minimum permissions
An agent should only have access to the systems and information required for its assigned task.
This is known as the principle of least privilege.
A customer-support agent, for example, may need to review customer records but should not automatically receive access to payroll information, source code, or financial accounts.
4. Machine identities need regular audits
Organizations should maintain an inventory of their service accounts, cloud workloads, bots, applications, and AI agents.
Unused identities should be disabled, expired credentials should be removed, and excessive permissions should be reduced.
5. Third-party AI tools must be tested
AI plugins, agent skills, integrations, and automation tools should be reviewed before they are connected to sensitive business systems.
A useful AI tool can still introduce security vulnerabilities or create an unexpected path into the company’s network.
6. Companies need an emergency shutdown process
Businesses should be able to quickly disable an AI agent, revoke its credentials, and stop its active sessions when suspicious behavior is detected.
Without that capability, a compromised agent may continue operating even after the security team discovers the problem.
What This Means for Cybersecurity Startups
The Okta-Permiso deal sends a strong signal to startup founders.
As AI adoption grows, companies will need products that help them:
- Discover AI agents operating inside the business
- Assign and manage agent identities
- Monitor agent behavior
- Detect abnormal tool usage
- Review inherited permissions
- Secure machine-to-machine communication
- Test third-party agent skills
- Investigate AI-related security incidents
- Maintain audit trails for regulators
- Automatically stop compromised agents
Startups that solve these problems may become attractive acquisition targets for identity, cloud, endpoint, and cybersecurity companies.
However, founders should avoid building tools that only place an “AI security” label on traditional products.
The strongest opportunities will likely involve threats created specifically by autonomous systems, such as unpredictable agent behavior, excessive permissions, insecure agent-to-agent communication, and malicious tool integrations.
The Aqyreon Take
Okta’s proposed acquisition of Permiso is not simply another cybersecurity company buying a smaller startup.
It reflects a larger shift in how businesses must think about identity.
For years, identity security focused primarily on employees, customers, and contractors. Now companies must also manage AI agents, bots, applications, cloud workloads, and other digital actors that can access information and make decisions.
As these non-human identities multiply, knowing who logged in will no longer be enough.
Businesses must also understand what each identity accessed, what actions it performed, whether those actions were normal, and how quickly its permissions can be revoked.
The next major cybersecurity battle may not be about preventing AI from entering the workplace.
It may be about making sure every AI agent can be identified, monitored, limited, and stopped.
Disclosure: Okta officially confirmed the agreement to acquire Permiso Security but did not disclose the transaction price. The figure of approximately $200 million was reported by TechCrunch based on an unnamed source familiar with the deal.






