Identity is a difficult concept to grasp within IT systems. Okta has been talking for quite some time about what it calls an identity fabric, which requires a comprehensive overview. Thanks to the proposed acquisition of Permiso Security, a Universal Identity Graph will be added to the mix. What does this entail, and how can the combination of these two technologies create a stronger solution?
Permiso Security is about six years old and based in Palo Alto. The platform was clearly built for and designed to support multicloud environments, as well as being multiplatform. Attack surfaces ranging from Azure to Slack and Claude are all connected via a so-called Universal Identity Graph. This links identities to all the actions and connections they manage, regardless of whether that identity is human or not.
Okta’s fabric and Permiso’s graph
In a sense, the solution is reminiscent of Wiz’s approach to cloud security, but specifically applied to identity. This approach acknowledges that identities not only pose a major cyber threat and are highly sought after by attackers, but that tracking these identities and their interactions with IT environments is the real challenge. Not every identity is worth stealing, but defenders often don’t know what the potential blast radius is. This is precisely where Permiso promises to provide clarity.
For Okta, the proposed acquisition of Permiso is more than just the incorporation of a potential rival. Customers, incidentally, aren’t really eager for multiple identity solutions, regardless of whether those tools actually overlap. Okta already had functionality similar to what Permiso does, but will be able to leverage Permiso’s capabilities to enhance its existing offerings. Consider, for example, an integration within Identity Security Posture Management, which immediately highlights the danger of “identity sprawl.”
Reducing friction
Permiso uses 2,500 research-based indicators sourced from 70 different parties. Depending on the context, these indicators may be quite common or may point to potential problems. Examples include overprivileged access, unused permissions, anomalous agent behavior, and policy violations. Permiso measures these in real time.
Okta highlights the rapid growth of identities and cites figures from its own research. Fifty-eight percent of executives surveyed reported an AI-related security incident or “near-miss” in the past year. Attackers are increasingly using post-authentication techniques to bypass defense lines. This makes it logical to add a deeper layer of investigation, such as the solution offered by Permiso.
The sum of acquisitions
In 2025, Permiso launched a platform that linked risk management to threat detection, with a Universal Identity Graph at its core. Okta itself has previously been working on ITDR through its acquisitions of Spera and Axiom Security, and in March introduced Okta for AI Agents. Within this platform, AI agents are full-fledged, non-human identities that, thanks to their autonomy, can behave like human users.
There is already a sign of Permiso’s integration within Okta. According to Okta, Permiso’s SandyClaw is the first to bring dynamic sandbox detonation to AI agent skills. It detects supply chain attacks in skills and prompts before they reach customer environments.
What customers get
Once the integration is complete, Okta customers will be able to deploy advanced detection by combining authentication signals with behavioral analytics. They will also gain visibility into risky behavior by AI agents, machine identities, and privileged accounts. Compromised or misconfigured agents can be investigated and isolated in real time.
“We are delighted to welcome Permiso to Okta,” said Ely Kahn, Chief Product Officer at Okta. The acquisition also brings Okta further into the Security Operations Center. Permiso’s research team, P0 Labs, will join Okta Threat Intelligence. The transaction is expected to close in the third quarter of Okta’s fiscal year 2027, well within this calendar year, subject to customary conditions. That third quarter ends in late October.