AI agent identity governance: 109 machine identities per human, and what Okta's $200M Permiso deal signals
Summary. On 30 July 2026 Okta signed a definitive agreement to acquire Permiso Security, a platform that detects threats across human, non-human and agentic identities; a source told TechCrunch the price was about $200 million. The number that explains the deal comes from a different vendor: Palo Alto Networks' 2026 Identity Security Landscape report puts the average enterprise at 109 machine identities for every human identity, with respondents expecting AI agent counts to grow 85% over the next 12 months. Check Point's 2026 Cloud Security Report found 64% of organisations already run AI agents in pilot or production and 12% have granted them privileged access to critical systems. Microsoft priced its answer in May: Agent 365 went generally available on 1 May 2026 at $15 per user per month, licensed per human user rather than per agent. For Indian companies there is a second clock: using AI for sizable decision-making or profiling is one of the criteria that can make you a Significant Data Fiduciary under the DPDP framework, which brings a mandatory DPO, an independent audit and a DPIA, with penalties reaching ₹250 crore.
The strategic read is simple. Identity vendors have concluded that authentication is no longer the control that matters, because agents authenticate correctly and then do something unexpected. What they are racing to sell is runtime behaviour: what did this agent actually touch, and can you stop it in the next few seconds.
What Okta actually bought
Permiso is a cloud-native identity security platform covering human, non-human and agentic identities across multi-cloud environments. Okta's announcement describes the detection surface in unusually specific terms: more than 2,500 research-driven signals across over 70 identity partners, used to surface overprivileged access, unused permissions, anomalous agent behaviour and tool usage, policy violations, and high blast-radius behaviour in real time.
Four capabilities are named for after the close. Detection across all identity types by combining authentication signals with behavioural analytics. Continuous identification of risky behaviour across AI agents running locally, on SaaS platforms or in cloud environments. A dynamic sandbox called SandyClaw that detonates AI agent skills and prompts to catch AI supply-chain attacks before they reach customer environments. And automated response that investigates and contains compromised or misconfigured agents in real time.
The third of those is the one worth pausing on. Sandboxing an agent skill treats the skill file the way endpoint security treats an executable: unknown code from a third party, detonated before it runs. That is a different mental model from prompt filtering, and it is a direct response to the supply-chain pattern the industry has been living through, from poisoned packages to poisoned agent instructions.
Permiso's P0 Labs research team joins Okta alongside Okta Threat Intelligence. The transaction is expected to close in the third quarter of Okta's fiscal year 2027 and Okta said it expects no impact on the guidance it issued on 27 May 2026.
Ely Kahn, Chief Product Officer at Okta, framed the purchase around the mixed workforce: "We're thrilled to welcome Permiso to Okta as we help companies secure their agentic enterprises where humans, applications, service accounts, and AI agents work together."
The customer voice in the same announcement is more useful than the vendor one. Sebastian Goodwin, Chief Trust Officer at Autodesk, said: "When you need to secure enterprise AI at scale, visibility and threat detection are non-negotiable. Permiso gives Autodesk the ability to discover and monitor all identities across our environment, making it an important part of our broader cloud security strategy." Discover and monitor. Not authenticate. That is the shift.
The number everyone quotes, and why it is four different numbers
Every vendor deck in this category opens with a machine-to-human identity ratio. They do not agree, and the spread is wide enough to change what you budget.
| Source | Reported ratio | Published | What that tells you |
|---|---|---|---|
| Palo Alto Networks, 2026 Identity Security Landscape | 109 machine identities per human | May 2026 | The figure most cited in 2026 agent-identity marketing |
| GitGuardian, 2026 State of Secrets Sprawl | 80 to 1 | 2026 | Counts through the lens of leaked and sprawling secrets |
| ManageEngine, 2026 Identity Security Outlook | 100 to 1, with some organisations at 500 to 1 | 2026 | Shows how much the tail matters; averages hide the worst case |
| KPMG, 2026 Cybersecurity Considerations | 80 to 1 in the average enterprise | 2026 | Advisory framing aimed at CISOs and boards |
| Composite of four published 2025-2026 ratios | Roughly 79 to 1, median 77 to 1 | 2026 | The averages land well below the headline figure |
The honest reading is that nobody is counting the same thing. Some counts include every TLS certificate and service account; others count only credentialed workload identities. Treat any single ratio as a directional argument for funding, not as an input to a capacity model. Then go count your own, because your number is the only one that determines how big the problem is for you.
What the Palo Alto data adds beyond the headline is the growth split: respondents expect AI agents to grow 85% over the next 12 months, machine identities 77%, and human identities 56%. Every category is growing. Agents are simply growing fastest, off a base that is already ungoverned.
The control gap is not a detection gap, it is a lifecycle gap
Palo Alto's respondents could mostly explain the purpose of their AI agents. Far fewer could define what those agents can access, how that access is limited, when permissions get revoked, or which systems can inherit that access. Environments still lack behavioural monitoring, credential revocation and shutdown mechanisms for agents, and they continue to rely on permanent privileged access rather than just-in-time controls.
The same report describes an executive perception gap worth quoting to your own leadership: C-suite executives believe their companies enforce least privilege because they are looking at human access, while security practitioners disagree because machines and automated systems run a growing share of operations.
Check Point's survey data lines up. Only 5% of respondents said they have full visibility into which AI tools employees use, how those tools are accessed, and where sensitive data goes once it enters an AI system. Only 17% said they have broadly deployed runtime controls that inspect and enforce policy on LLM inputs and outputs. Only 22% said their web application firewall or WAAP is effective against GenAI-specific attacks such as prompt injection, while 71% reported more false positives after adopting generative AI workloads. And 42% said workers bypass AI security controls when those controls slow them down.
Put those next to the adoption figures — 64% with agents in pilot or production, 12% with agents holding privileged access to critical systems — and the shape of the problem is clear. Deployment is ahead of instrumentation by a wide margin. Check Point's own summary of the gap: 77% of organisations have changed their security strategy in response to AI, but only 26% believe their architecture can actually support AI workloads without a major redesign, a 51-point readiness gap.
Fragmentation makes the response slower too. Unit 42 examined more than 750 cyber incidents in 2025 and found that 87% required evidence from two or more distinct sources to establish what happened, with complex incidents needing as many as 10. Practitioners reported that fragmented tooling adds an average of 12 hours to identity-related incidents. Twelve hours is a long time when the actor on the other side is a process, not a person.
What the platforms actually ship
Three approaches are on the table in 2026. This is where they differ.
| Capability | Okta plus Permiso (after close) | Microsoft Agent 365 with Entra Agent ID | Build it yourself |
|---|---|---|---|
| Agent registry and lifecycle | Identity security fabric extended across human, non-human and agentic identities | Register agent identities in Entra; manage lifecycle and access packages through Identity Governance | A table in your own directory, plus whatever your framework exposes |
| Policy at access time | Authentication signals combined with behavioural analytics | Conditional Access applied to agent access attempts; requires an Agent 365 licence | Your own gateway, enforced per call |
| Runtime behaviour detection | Over 2,500 signals across 70+ identity partners, including anomalous agent behaviour and tool usage | Agent sign-in signals feed Identity Protection | Your own telemetry pipeline and detection rules |
| Skill and prompt inspection | SandyClaw dynamic sandbox detonation for agent skills and prompts | Not described as a sandbox in the GA announcement | Static review, if anyone has time |
| Automated containment | Investigate and contain compromised or misconfigured agents in real time | Governance and protection through the Entra stack | Custom kill-switch, usually a manual runbook |
| Commercial model | Capabilities land after the deal closes in Okta's fiscal Q3 2027 | $15 per user per month standalone, also included with Microsoft 365 E7, licensed per human user | Engineering time, ongoing |
Two things stand out. First, Microsoft's per-human-user licensing means your bill tracks headcount rather than agent count, which is generous if you run many agents per person and expensive if you run few. Second, Okta's most differentiated capability, skill sandboxing, is not available to you today: it arrives when the transaction closes, expected in Okta's fiscal Q3 2027. If you have agents in production now, you are building or buying something in the interim regardless.
The pattern in both roadmaps is the same and it is the useful takeaway even if you buy neither. Agent governance is being assembled out of four layers: a registry, a policy point at access time, runtime behavioural telemetry, and a containment action. If you are building, build those four. If you are buying, ask which of the four the product actually covers today rather than on a slide.
A 90-day build order
You do not need a platform decision to start. You need an inventory, because every subsequent control depends on it, and because the vendors' own data says most organisations cannot answer the first question.
| Phase | What to do | Evidence you can show an auditor |
|---|---|---|
| Days 1-15 | Enumerate every credential an agent holds: model provider keys, database roles, SaaS tokens, internal API clients | A list of agent identities with an owner, a purpose and an expiry per credential |
| Days 16-30 | Give every agent its own identity. No shared service accounts, no borrowed human credentials | A one-to-one mapping between running agents and directory principals |
| Days 31-45 | Scope permissions to the narrowest set that keeps the agent working, and remove standing privilege | A before-and-after permission diff per agent |
| Days 46-60 | Log every tool call the agent makes, with the identity, the target and the parameters | Queryable tool-call telemetry with a retention period |
| Days 61-75 | Write the kill switch and test it. Revoking one agent must not take down the fleet | A timed drill record showing revocation and recovery |
| Days 76-90 | Set alert thresholds on blast-radius behaviour: new target systems, permission escalation, unusual call volume | Alert definitions plus at least one tuned true positive |
Two of these are commonly skipped and both are the expensive ones to retrofit. Per-agent identity is skipped because a shared service account is faster on day one, and it destroys attribution permanently: once three agents share a principal you cannot answer which one touched the record. Tool-call logging is skipped because the volume looks frightening, and without it the containment step has nothing to trigger on.
The kill-switch drill deserves a specific note. Most teams discover during the drill that revoking an agent's credential also breaks a batch job, a webhook receiver and a dashboard, because the same credential was quietly reused. Finding that in a drill costs an afternoon. Finding it during an incident costs the incident.
Why authentication stopped being the control
The reason identity vendors are buying detection companies is that the failure mode changed. A compromised human account looks wrong at login: strange geography, strange device, strange hour. A compromised agent looks perfect at login, because it is using the credential it was issued, from the infrastructure it always runs on, at a time it always runs. Everything anomalous happens afterwards.
Palo Alto's report states this plainly: single sign-on and multi-factor authentication help secure logins, but they do not control what users, tokens, connectors or automated systems can reach after authentication. More than half of participants said they cannot consistently enforce least privilege for service accounts across cloud, SaaS and on-premises systems.
This is the same lesson the agent framework CVEs taught from the other direction. When we walked through the LangGraph checkpointer RCE chain, the damage estimate had nothing to do with the CVSS score and everything to do with what credentials sat in the runtime the payload landed in. Blast radius is the unit of analysis. An agent's identity is just the ledger of that blast radius, which is why governing it is the highest-use control available.
That framing also decides build-versus-buy. If your agents hold three read-only API keys, a directory entry and good logging get you most of the way, and a per-user licence is hard to justify. If your agents hold write access to a payments system or a patient record store, you are in the 12% Check Point described, and the runtime detection layer is not optional. We work through the layer model in more depth in enterprise AI agent governance layers and, for fleets, in governing multi-agent systems.
What this does not solve
Identity governance bounds what an agent can reach. It does nothing about what an agent can be persuaded to do inside those bounds. An agent with legitimate access to a customer database, hijacked by an injected instruction, produces perfectly authorised queries that exfiltrate exactly what it was allowed to see. No amount of least privilege catches that, because the access was granted.
The two controls are complements, not substitutes. Identity governance decides the ceiling; input-handling controls decide the behaviour under that ceiling. Teams that buy one and skip the other tend to skip the second, which is why we treat prompt injection guardrails for AI agents as a separate workstream with its own owner.
The other unresolved problem is delegated authority. When an agent acts for a user, whose permissions apply, and how does the downstream system tell? Okta's Cross App Access work, announced with an expanding partner ecosystem on 23 June 2026, is aimed at this, and Microsoft's per-human-user licensing implicitly assumes an agent is always acting on someone's behalf. Neither is a finished answer. Until one exists, write down the delegation model your agents use, because your auditor will ask and the honest answer today is usually "the agent has its own standing rights and we call that delegation".
India-specific considerations
There is a compliance trigger here that Indian teams keep missing, and it does not depend on the size of your agent fleet.
Under the DPDP framework, an organisation can be designated a Significant Data Fiduciary on any of several criteria, and one of them is risk profile: processing sensitive data such as health or finance information, or using AI for sizable decision-making or profiling. The other two common triggers are processing the data of 5 million or more residents and annual turnover of INR 2.5 billion, roughly US$26.24 million. A mid-size Indian company that would never hit the user-count or turnover thresholds can land inside SDF scope purely by putting a decisioning agent into a customer workflow.
The obligations that follow are concrete and dated. By the first quarter of 2027, SDFs are expected to have appointed an India-based Data Protection Officer reporting to the board, engaged an independent data auditor, and completed a Data Protection Impact Assessment for high-risk processing. Full enforcement, with the Data Protection Board of India exercising its adjudicatory powers and penalties up to INR 2.5 billion for major violations, is widely expected on 13-14 May 2027. Soft enforcement is expected to end around November 2026.
Three practical consequences for an Indian engineering team running agents. Your agent inventory is DPIA input, so build it in a form an auditor can read rather than a spreadsheet someone maintains by hand. Your tool-call logs are the evidence that supports "we can demonstrate what accessed this personal data", which is the hardest claim to retrofit. And per-agent identity is what makes a breach report specific instead of speculative, because "one of our agents" is not an answer a regulator accepts. The wider sequencing sits in our DPDP Act engineering playbook.
One more India-specific note on cost. The per-human-user licensing model that Microsoft chose is comparatively favourable for Indian teams, where agent-to-engineer ratios tend to run high in cost-conscious builds. Do the arithmetic on your actual agent count before assuming a per-agent model would have been cheaper. For the broader production readiness picture, see our guide to enterprise AI agents in production.
FAQ
What did Okta announce about Permiso Security?
On 30 July 2026 Okta signed a definitive agreement to acquire Permiso Security, a cloud-native platform that detects and mitigates threats across human, non-human and agentic identities in multi-cloud environments. A source told TechCrunch the price was about $200 million. The transaction is expected to close in the third quarter of Okta's fiscal year 2027.
How many machine identities does a typical enterprise have?
Palo Alto Networks' 2026 Identity Security Landscape report puts the average at 109 machine identities per human identity. Other 2026 reports disagree: GitGuardian and KPMG both publish 80 to 1, and ManageEngine reports 100 to 1 with some organisations reaching 500 to 1. Count your own environment rather than adopting a vendor figure.
What does Microsoft Agent 365 cost?
Agent 365 became generally available on 1 May 2026 at $15 per user per month as a standalone licence, and it is also included with Microsoft 365 E7. It is licensed per human user, meaning the person who manages, sponsors or is served by an agent, rather than per agent. Conditional Access for agents requires that licence.
Why is authentication no longer enough for AI agents?
A compromised agent authenticates correctly, from its usual infrastructure, at its usual time, so nothing looks wrong at login. Palo Alto's report notes that single sign-on and multi-factor authentication do not control what tokens, connectors or automated systems reach after authentication. Detection has to move to runtime behaviour rather than credential presentation.
What is SandyClaw and why does it matter?
SandyClaw is Permiso's dynamic sandbox for AI agent skills, described by Okta as the first platform to bring dynamic sandbox detonation to agent skills. It uses behavioural analysis and a multi-engine detection stack to catch AI supply-chain attacks in agent skills and prompts before they reach customer environments, treating third-party skills like untrusted executables.
Can deploying AI agents make an Indian company an SDF?
Yes, potentially. Significant Data Fiduciary designation criteria include a risk profile based on processing sensitive health or financial data, or using AI for sizable decision-making or profiling. That is independent of the 5 million resident and INR 2.5 billion turnover thresholds, so a mid-size company can enter scope through a decisioning agent alone.
What should we build first if we cannot buy a platform yet?
Start with an inventory of every credential each agent holds, then give every agent its own directory identity rather than a shared service account. Attribution is impossible to retrofit once agents share a principal. After that, scope permissions down, log every tool call, and test a per-agent kill switch under drill conditions.
Does identity governance stop prompt injection?
No. Identity governance bounds what an agent can reach; it does not change what the agent does inside those bounds. A hijacked agent with legitimate database access issues perfectly authorised queries. Input-handling controls and identity controls are complements, and teams that buy only one usually skip the input-handling side.
How eCorpIT can help
eCorpIT's senior engineering teams build and govern production AI agent systems for companies in India and abroad. The work described above is what we do: inventory the credentials your agents actually hold, give each agent its own identity and a scoped permission set, instrument tool-call telemetry an auditor can read, and drill the kill switch before you need it. We are ISO 27001:2022 certified and CMMI Level 5 appraised, and we design applications aligned with DPDP requirements. If you have agents in production and no answer to "what can this one reach", contact us and we will scope an agent identity review.
References
- Okta signs definitive agreement to acquire Permiso Security - Okta newsroom, 30 July 2026
- Okta buys AI security startup Permiso, source says for about $200M - TechCrunch, 30 July 2026
- Okta acquires Permiso for AI identity threat detection - CyberScoop, 2026
- Machine identities outnumber humans 109 to 1 - Help Net Security on the Palo Alto Networks 2026 Identity Security Landscape report, 14 May 2026
- Check Point's 2026 Cloud Security Report: Securing the AI Transformation - Unite.AI summary of the Check Point and Cybersecurity Insiders survey, 26 May 2026
- AI adoption creates critical cloud security gaps for enterprises - Check Point Software press release, 2026
- Microsoft 365 E7 and Agent 365 are now generally available - Microsoft 365 Blog, 1 May 2026
- Governing agent identities: Microsoft Entra ID Governance - Microsoft Learn
- Microsoft Agent 365 overview - Microsoft Learn
- Why non-human identities are your biggest security blind spot in 2026 - CSO Online, 2026
- Machine identity statistics 2026: non-human identity ratios and secrets sprawl - Axis Intelligence composite of published 2025-2026 ratios
- KPMG 2026 cybersecurity report identifies non-human identities as a critical CISO priority - Non-Human Identity news, 2026
- India's DPDP timeline: critical compliance deadlines for 2026-27 - India Briefing, 11 May 2026
- Okta advances the industry standard for secure AI agent connections with expanding Cross App Access ecosystem - Okta newsroom, 23 June 2026
Last updated: 5 August 2026.
Top comments (0)