“Today those are two separate products that don’t really talk to each other,” Ely Kahn, Okta’s chief product officer, told CyberScoop — a blunt diagnosis that explains why Okta moved to acquire Permiso Security and fold its post-login threat detection into Okta’s identity stack.
Okta announced Thursday that it has signed a deal to buy Permiso Security, a cloud-based company that specializes in identity threat detection and response: spotting risks that appear after a user, machine, or AI-driven agent has already authenticated. The transaction is expected to close in the third quarter of Okta’s 2027 fiscal year, subject to standard regulatory and closing conditions. Financial terms were not disclosed.
Ely Kahn on merging real-time threat detection with posture management
Kahn framed the acquisition as a technical and operational fix. Permiso’s capabilities, he said, let Okta merge two functions that have historically operated separately: real-time threat detection and identity security posture management. Combining them, he argued, produces “sharper alerts for security teams.”
He illustrated the point with a hypothetical: a posture-management tool flags a dormant administrator account, and later that account logs in from an unfamiliar IP address. Kahn said that when those signals are joined, the result is “a very high-confidence, high-fidelity alert that’s more actionable by a security operations team.” In his words, “A security operations team on its own might not care about the dormant account, but when you combine that with some threat signals, then it becomes a higher critical-level alert.”
Permiso’s signal network and SandyClaw
Permiso, according to Okta’s description, draws on more than 2,500 signals from over 70 identity-related partners to identify post-login risks. Those signals are used to flag issues such as excessive access permissions, unused credentials, unusual behavior from AI agents, and violations of internal security policies.
Among the specific capabilities Okta highlighted is a tool called SandyClaw, designed to test AI agent skills and prompts in an isolated environment before the agents are allowed into a customer’s systems. Okta positioned SandyClaw as a way to catch supply-chain attacks that could be embedded in AI tools. Other planned additions referenced by Okta include expanded tracking of AI agent behavior across cloud platforms and SaaS tools, plus automated mechanisms to investigate and isolate AI agents that appear compromised or misconfigured.
Visibility beyond Okta: Microsoft Entra ID and Active Directory
Okta said a crucial part of the deal is visibility beyond its own products. Kahn told CyberScoop that many customers rely on other identity systems — explicitly naming Microsoft Entra ID and Active Directory — that fall outside Okta’s existing view. He framed Permiso as a path to give customers “a full view into their identity threats” rather than an Okta-only perspective.
What this means for security operations teams, enterprises, and AI agent owners
- Security operations teams: The combined signal set aims to reduce false positives and raise the fidelity of alerts, making incident triage more focused when a dormant account, unusual IP login, or agent behavior is detected.
- Enterprises and procurement leaders: Organizations that run heterogeneous identity systems — including Microsoft Entra ID and Active Directory in addition to Okta — may gain unified visibility across those systems through Permiso’s integrations and signal ingestion.
- AI agent owners and operators: Okta emphasized the AI threat vector. Citing figures Okta provided, the company said 58% of executives reported an AI-related security incident or near miss within the past year. Kahn warned, “Agents will be breached,” and recommended narrow, revocable identities for agents to limit blast radius; the acquisition brings tools such as SandyClaw and agent-isolation automation into that strategy.
Deal timing, terms, and open questions
The agreement is slated to close in Okta’s fiscal third quarter of 2027, with the customary regulatory and closing conditions still to be satisfied. Okta did not disclose the purchase price or other economic terms. The announced roadmap highlights specific features Okta plans to add — broader agent tracking, SandyClaw testing, and automated isolation — but the timeline for customer availability of those capabilities was not provided in the statements cited by CyberScoop.
The acquisition centers on a practical premise: identity control doesn’t end at login. Okta and Permiso are betting that linking posture data with live threat signals — and extending visibility across competing identity systems and AI agents — will produce fewer, more actionable alerts. Whether that integration cuts through operational noise for defenders, and how quickly the new tools will ship into customer environments, are the next items to watch as the deal moves toward closing.




