The problem isn't securing humans anymore — it's securing the bots they're building to do their jobs.
The Summary
- Okta acquired AI security startup Permiso for approximately $200M, bringing identity threat detection capabilities in-house as enterprises scramble to secure AI agents
- The deal signals a market shift: non-human identities now outnumber human ones in cloud environments, creating security gaps traditional identity management wasn't built to handle
- Permiso's tech focuses on detecting threats specific to autonomous agents operating across cloud infrastructure — the exact problem every company deploying AI agents will face in the next 18 months
The Signal
Okta just paid $200M for something most enterprises don't realize they need yet. But they will. Permiso specializes in identity threat detection for non-human identities. That's security industry speak for AI agents, service accounts, API keys, and all the autonomous software entities you're about to deploy at scale. The problem is simple: your agents need credentials to do their work, and those credentials are attack vectors.
Traditional identity management was built for people. Humans log in. Humans log out. Humans get phished and call IT. Agents don't behave like humans. They spin up, execute tasks, make API calls, move data, and terminate. Often within minutes. Sometimes hundreds at once. Your legacy security stack can't track that, and attackers know it.
"Non-human identities now outnumber human ones in cloud environments."
Here's what Okta is betting on: every company building with AI agents will need to answer three questions. Who is this agent? What can it access? Is it doing what it's supposed to? Right now, most companies can't answer any of them with confidence. Permiso built detection systems specifically for this problem. Okta just bought those answers.
The timing matters. We're six months into the agent economy going from theory to production. Companies are deploying customer service agents, data analysis agents, coding agents. Each one needs permissions. Each one is a potential entry point. The first major breach caused by a compromised AI agent hasn't happened yet, but it's coming. Okta is positioning to own the infrastructure layer that prevents it.
The Implication
If you're building agents, you need an answer for how they authenticate and what happens if they're compromised. The market just told you that answer is worth $200M to get right. The companies that figure out non-human identity management first will have a moat. The ones that don't will have a breach.
Watch for more acquisitions in this space. Identity threat detection for agents isn't a feature anymore. It's infrastructure. And infrastructure commands infrastructure prices.