Okta Is Buying Security Firm Permiso to Catch Identity-Based Attacks
The deal would push Okta beyond managing who can log in and into spotting when a legitimate login is being used to do something it shouldn't.

Key points
- Okta, a company that controls who is allowed to sign in to corporate software, has agreed to acquire Permiso, a firm that watches for suspicious behaviour inside those same accounts.
- The deal moves Okta into a category known as identity threat detection and response, meaning tools that raise an alarm when a valid account starts acting oddly.
- No purchase price or regulatory approval timeline has been disclosed publicly.
- The acquisition positions Okta to compete with security vendors that already bundle login control and suspicious-activity monitoring in one product.
Okta manages identity, which in plain terms means it is the gatekeeper that decides whether you are who you say you are when you log in to your company's software. Permiso does something different: it watches what happens after you get in.
Why does that distinction matter?
Most security breaches today don't start with someone kicking down a digital door. They start with a stolen password or a hijacked session token, a small piece of data your browser holds to prove you already logged in, that lets a criminal walk straight through the front gate.
Once inside, the criminal looks just like a normal employee. Standard login controls won't catch them. That is exactly the gap Permiso was built to close, by watching for behaviour that a real employee would be unlikely to do: downloading thousands of files at 3 a.m., accessing systems the account never touched before, or exporting a customer list minutes after logging in from an unfamiliar country.
As SecurityWeek first reported, the deal extends Okta's reach directly into that detection space.
What changes for organisations that use Okta?
Nothing changes immediately. Acquisitions of this kind move through regulatory review and integration planning before any product changes reach customers. For Okta's existing customers, the longer-term promise is a single platform that both controls access and watches for misuse of that access.
For organisations that don't yet use either product, the deal is a signal that the identity security market is consolidating. Buying two separate tools to cover login control and post-login monitoring may become less common as vendors bundle both.
Common questions
Does this affect ordinary employees who use Okta to log in to work?
Not directly and not soon. The acquisition is a business and product decision that will take time to work through integration. Day-to-day login screens are unlikely to change in the near term.
Should companies worry that their login data is being shared with a new entity?
Permiso analyses behaviour patterns rather than storing raw passwords, but any organisation with a data-handling agreement with Okta should review what that agreement says about data use when Okta acquires a new subsidiary. Standard contract review is reasonable; alarm is not warranted at this stage.



