Okta

Type: company (enterprise identity & access management incumbent) Sector: IAM / non-human & AI-agent identity governance First seen: 2026-08-21 (as a Sources-list entry on AI Governance Platforms) Last updated: 2026-08-28

Created 2026-08-28 from S-2026-08-24-okta-agent-sso-ga (daily AI-governance vendor-intelligence scan; primary press release fetched in full). The vault’s 2026-08-21 decision not to create an Okta page (recorded on AI Governance Platforms: “a large existing IAM vendor outside this page’s watchlist scope”) is superseded, not contradicted: the schema’s 2+-source trigger is now met (S-2026-07-30-okta-permiso-acquisition + this GA release), and Agent SSO is a shipped product move squarely inside the agent-identity governance locus the vault tracks, not merely an M&A event. The earlier decision and its reasoning are preserved on the topic page.

Snapshot

Okta is a large, publicly listed enterprise IAM vendor (NASDAQ: OKTA; 20,000+ customers on core SSO per its own release) that in mid-2026 moved decisively into AI-agent identity governance: agreeing to acquire NHI-behavioural-monitoring startup Permiso (~$200M, 30 Jul 2026) [S-2026-07-30-okta-permiso-acquisition] and making Agent SSO generally available inside core SSO at no extra cost (24 Aug 2026), registering Cross-App-Access-capable AI agents as first-class identities in Universal Directory with short-lived, identity-governed tokens [S-2026-08-24-okta-agent-sso-ga]. It matters to this wiki because it makes agent identity a default-on feature of incumbent IAM rather than a specialist purchase — directly bearing on the agent-inventory-of-record and machine-identity questions tracked on AI Governance Platforms.

Positions / Claims they advance

  • Agents today “operate as anonymous traffic with no owner, no policy, and no audit trail”, reaching data via static API keys and one-off OAuth grants; only 34% of organisations apply the same security controls to agents as to human workers (Okta’s own commissioned survey ⚠️) [S-2026-08-24-okta-agent-sso-ga].
  • Agent authorization should move “from individual applications to the enterprise identity provider” — the SSO centralisation argument re-run for agents [S-2026-08-24-okta-agent-sso-ga].
  • Enterprises must govern three agent populations at once: self-built, embedded-in-purchased-software, and shadow-deployed [S-2026-08-24-okta-agent-sso-ga].
  • The paid Okta for AI Agents tier (GA May 2026) claims shadow-agent discovery (browser/endpoint/network), named human owners per agent, access certifications, approval workflows and a deactivation kill switch — all vendor-asserted, mechanisms undisclosed [S-2026-08-24-okta-agent-sso-ga].
  • Post-access behavioural monitoring of agent credentials/activity is the Permiso capability being absorbed — detecting anomalous agent behaviour after access is granted [S-2026-07-30-okta-permiso-acquisition].

Relationships

  • relates-to → AI Governance Platforms — incumbent-IAM claimant on the agent-identity and agent-inventory loci tracked there [S-2026-08-24-okta-agent-sso-ga].
  • relates-to → DORA — agent identity/access lifecycle controls map to ICT access-management expectations [inference].

Tracked changes

  • 2026-07-30 — Agreed to acquire Permiso Security (~$200M, almost-all-cash; expected close Okta FY Q3 2027) for AI/non-human-identity threat detection and post-access behavioural monitoring [S-2026-07-30-okta-permiso-acquisition].
  • 2026-08-24Agent SSO GA: Cross App Access built into core Okta SSO at no additional cost; agents registered as first-class identities in Universal Directory; short-lived identity-governed tokens replace stored credentials; Cross App Access formally incorporated as the Enterprise-Managed Authorization extension for MCP; integration network includes Anthropic (Claude), Atlassian, Slack, Notion, Datadog [S-2026-08-24-okta-agent-sso-ga].

Open Questions

  • What audit evidence does Agent SSO retain per agent (issuance, access, policy changes), with what retention/immutability — Art. 12 / SS1/23-grade or operational-log-grade? Unstated [S-2026-08-24-okta-agent-sso-ga].
  • Agent SSO covers only Cross-App-Access-capable agents; independent commentary surfaced in search (not fetched) reportedly flags material coverage gaps — how large is the uncovered population in a typical estate? [S-2026-08-24-okta-agent-sso-ga]
  • Does default-on agent identity in incumbent IAM commoditise the venture-funded agent-identity cohort (Hush Security, Neo, Onyx) tracked on AI Governance Platforms? [inference]
  • No named customer for Agent SSO, no regulatory standard named in either source, and no EU/UK regulated-FS reference — the category-wide pattern holds.

Sources

  • S-2026-07-30-okta-permiso-acquisition — secondary AIGI/TechCrunch relay of the Permiso acquisition (medium authority; no primary Okta release fetched).
  • S-2026-08-24-okta-agent-sso-ga — Agent SSO GA press release, fetched in full from the vendor newsroom (medium authority; primary, self-interested; 34% figure vendor-commissioned; release partly an upsell for the paid tier).