Four days, two exits, one category

On 30 July Okta signed a definitive agreement to acquire Permiso Security, a Palo Alto company that detects threats across human, non-human and agentic identities in multi-cloud estates. Okta did not disclose terms. A person familiar with the deal told TechCrunch it was just under 200 million dollars and almost entirely cash, with closing expected in Okta's third fiscal quarter of 2027, which runs from August to October this year.

Three days earlier, Keyfactor agreed to buy Cofide, the six-person British firm implementing the SPIFFE and SPIRE workload identity standard, on the same day that standard moved into open source under the Linux Foundation. Two acquisitions in the same narrow category inside four days is not a coincidence and it is not a bidding war either. It is the sound of incumbents deciding what agent identity is going to be.

What just under 200 million dollars actually buys

Permiso emerged from stealth in 2022, founded by Paul Nguyen and Jason Martin, both former FireEye executives. It had raised roughly 29 million dollars, including an 18.5 million dollar Series A in April 2024 led by Altimeter Capital. An exit at just under 200 million returns about seven times the capital that went in. For a four-year-old company in the hottest security category of the year, that is a respectable outcome and a modest one.

The tell is in Okta's own filing language. The company said the transaction is expected to have no impact on the guidance it issued on 27 May. A deal that moves no numbers has almost no revenue attached to it. That is not a criticism of Permiso, whose technology reads more than 2,500 research-driven signals across over 70 identity partners and flags overprivileged access, unused permissions, anomalous agent behaviour and high blast-radius activity in real time. It is a statement about what the buyer thinks it is buying.

Read the price as a classification. Roughly 200 million dollars is what an incumbent pays for a capability it intends to fold into an existing subscription, not for a business it expects to sell separately. Okta has decided agent identity is a feature of the identity platform you already have. If you are three months into evaluating a standalone agent-security product on a three-year term, that decision was just made for you by someone else.

Authentication, and everything that happens after it

Okta is an authentication company. Permiso is post-authentication detection: it watches identity activity after a user, a service or an agent has already been let in. Strip the deal down and Okta has paid a nine-figure sum for the admission that authenticating an agent tells you almost nothing about what the agent then does. Permiso's P0 Labs research team and its SandyClaw sandbox, which looks for supply chain attacks hidden inside agent skills and prompts, both sit on that side of the line.

This is the part to carry into your own procurement. Most agent-identity pitches currently on the market sell the issuing half: give every agent a verifiable identity, rotate its credentials, scope its permissions. That work is necessary and it is the cheap half. The expensive half is knowing that agent number 412 read a customer table at 03:00 that it has never touched in six months of operation, and being able to stop it inside the same minute. When a proposal ends at issuance, you have been quoted for half a control.

The neutrality promise has a shelf life

Permiso's value comes precisely from being multi-vendor. Its signals span more than 70 identity partners, which is why it works in an estate that runs several identity providers at once, as most European groups of any size do after a decade of acquisitions. The founders framed the deal around reaching more organisations through what they called Okta's neutral platform, and Okta's chief product officer, Ely Kahn, positioned it as an extension of Okta's threat detection and response.

Take the neutrality claim seriously and then write it down. The commercial gravity of any acquisition pulls toward making the acquirer's own stack the best-supported one, not out of bad faith but because that is where the engineering budget goes. If you run Entra ID or Ping or a legacy directory alongside Okta, coverage of those systems is now a contractual question rather than a product fact. Ask for it in the renewal, with named systems and a support commitment, while the deal is still pending and the answer is still easy to give.

What to settle before the deal closes in October

Three things belong in your file this quarter. First, freeze your category decision: do not sign a multi-year standalone agent-security contract in the next two quarters unless the vendor is large enough to be a buyer rather than a target. Second, if you are already a Permiso customer, get the roadmap and the pricing path for your renewal in writing now, because the period between signature and close is the window in which those answers are cheapest to obtain. Third, if you are an Okta customer, do not budget for this capability as though it were free; capabilities acquired for nine figures do not stay inside the base tier.

There is a compliance edge to this as well. Under NIS2, supplier security is your obligation, not your supplier's favour, and national authorities from the BSI to ANSSI have been consistent that the duty follows the operator. An acquisition mid-contract changes who processes your identity telemetry and where. That is a supplier change notification in most well-written agreements, and it is worth confirming that yours treats a change of control as a notifiable event rather than an administrative footnote.