Agents & Margins · Note 03 Türkçe →

Note 03

Okta–Permiso: The Authority Layer Is Bought Before It Has a Price

Okta's agreement to buy Permiso — press-reported at just under $200m and published by neither party — takes the absorption side of this series' two-sided test from six transactions to seven, while the independence side has still never disclosed a revenue figure.

·Independent signal & macro-trend analysis·Published 19 August 2026·Evidence window: 8 January 2026 – 19 August 2026·16 min read



01

Seven absorptions on one side of the test, no revenue figure on the other

On 30 July 2026 Okta signed a definitive agreement to acquire Permiso Security, which it describes as detecting threats "across human, non-human, and agentic identities in multi-cloud environments" [1]. Neither party published a price: the release states no terms, and SecurityWeek confirmed the same day that they were not disclosed [1][2]. TechCrunch put the deal at just under $200 million on a single source with knowledge of it; an Okta spokesperson declined to comment and did not dispute it [2]. It is the weakest price class this series records. Nor has the deal closed: Okta expects completion in fiscal Q3 2027, which on a 31 January year end runs 1 August to 31 October 2026 [1][3]. Announced is not absorbed. It matters because Thesis 01 published a two-sided test — whether independent authority and assurance vendors reach $100m ARR alone, or are bought and bundled into incumbents.

  • ~$200M Reported price for Permiso, against ~$29m of venture funding raised in total and a Series A post-money near $80m [2] TechCrunch, 30 Jul 2026 · single unnamed source, not disputed by Okta, published by neither party · definitive agreement, pending close PRESS-REPORTED
  • $637.1M Total consideration CrowdStrike transferred for SGNL, of which $561.1m — 88% — was booked as goodwill [4] Form 10-Q for the quarter ended 30 Apr 2026, filed 4 Jun 2026 · completed 20 Feb 2026 · not the $740m press headline MEASURED filed
  • $370M Raised by four independent agent-security vendors in seventeen days, none of which published a revenue figure of any size [5] 20 Jul – 5 Aug 2026 · amounts supplied by the companies and their investors COMPANY CLAIM

This note updates one tracked signal and opens none. R01.5's absorption count moves from six to seven on the Permiso agreement. Three rows in the agent M&A registry carry the argument here: Permiso itself, pending close; CrowdStrike–SGNL, completed 20 February 2026, the only transaction in this layer whose price was ever filed; and Cisco–WideField Security, completed 31 July 2026, the only one whose buyer came back for a second. The score holds at −1: unchanged in direction, better evidenced in fact. Two further transactions are recorded and deliberately excluded; both are argued below. The full reading sits in the signal ledger.

Verdict

“With these new innovations within Okta for AI Agents, every agent connection can be evaluated and authorized in real time, then continuously validated as projects evolve.”

Ely Kahn, chief product officer, Okta — Okta newsroom, July 2026 product innovations, 22 July 2026 [6]

Refine — continuous validation of a connection is not observation of a behaviour, and Okta's next move said so eight days later.

On 22 July 2026 Okta brought Agent-to-Agent Connections to general availability and released an Agent Gateway that enforces policy at runtime [6]. Eight days later it agreed to buy the company whose product is the record of what agents did after they were authorized: Permiso surfaces "overprivileged access, unused permissions, anomalous agent behavior and tool usage, policy violations, and high blast radius behavior, in real time" [1]. Were the connection already continuously validated, that purchase would be redundant. Refined: a connection can be authorized continuously, and the authorization still says nothing about what the agent did with it. Okta priced that gap at a press-reported ~$200m [2] PRESS-REPORTED — unconfirmed by either party, pending close.

02

Three incumbents got the gate, then went back for the camera

  1. 8 Jan 2026

    CrowdStrike announces it will acquire SGNL, "the runtime access enforcement layer" between identity providers and the resources people, non-human identities and AI agents reach [7]. The release carries no figure; a spokesperson tells SecurityWeek $740m, predominantly cash [8].

    Announced · price from a spokesperson, not the releaseEnforcementCOMPANY CLAIM

  2. 20 Feb 2026

    The acquisition closes. CrowdStrike's Form 10-Q, filed 4 June 2026, records total consideration transferred of $637.1m and states the deal "did not have a material impact" on its financial statements [4]. Forty-three days from announcement to close.

    Completed · filed purchase-price allocationAbsorbedMEASURED

  3. 15 Jun 2026

    Falcon ships Continuous Identity for AI Agents, credited to SGNL's technology and positioned as "the identity security control plane for the agentic enterprise". No list price, no general-availability date [9].

    Shipped · vendor product claim, unpricedFolded inCOMPANY CLAIM

  4. 18 Jun – 31 Jul 2026

    Cisco announces it will acquire WideField Security and records the completion on the same page six weeks later, with no price disclosed by any party. The technology goes into Splunk's Agentic SOC and the Cisco Data Fabric, and Cisco places the deal in a run of its own: “Building on the recent additions of Astrix Security and Galileo” [10]. Its second authority purchase of 2026, and the plainest statement anywhere here of what is being bought: identity is “not just focused on who logged in but who, or what, took action and under which authority, which session, and with what blast radius” [10].

    Announced 18 Jun · completed 31 Jul · no price disclosed by any partyCamera boughtCOMPANY CLAIM

  5. 22 Jul 2026

    Okta brings Agent-to-Agent Connections to general availability and releases Agent Gateway as a research release, with Resource Access Certifications for AI Agents in early access [6].

    Mixed · GA and research release, vendor claimGate builtCOMPANY CLAIM

  6. 30 Jul 2026

    Okta signs for Permiso: no terms in the release, a press-reported ~$200m from a single source, and no impact on the guidance issued 27 May 2026 [1][2].

    Definitive agreement · pending close · press-reported priceCamera boughtPRESS-REPORTED

  7. 4–5 Aug 2026

    Three independent vendors announce $270m in two calendar days: Zenity's $125m Series C, Obsidian Security's $85m at a $1.1bn valuation, Oligo Security's $60m [5]. None publishes revenue.

    Announced · amounts supplied by companies and investorsIndependenceCOMPANY CLAIM

Read as one sequence, these seven headlines are a single manoeuvre performed three times. CrowdStrike shipped the layer it bought as a platform capability 115 days after the close — my arithmetic from the filed dates INFERENCE. Cisco did not even change the wording: having taken the authorization half in June, it spent July buying the half that records what the authorization was used for.

Authorization is a decision. Assurance is a record. Both incumbents built the decision and bought the record.

A fourth platform did neither. Across 5 August 2026 Cloudflare shipped the same capability as product rather than acquisition: an identity-aware AI Gateway in open beta that puts “a verified identity on every request”, and User Insights — the analytics half, the record — generally available “to every AI Gateway customer at no additional cost” [11]. Alongside it, WriteGuard entered private beta as “a shared policy, attribution, and auditing layer” that can enrich an agent’s tool call with attribution or block it before its handler runs [12]. Nine days later the same gateway began classifying MCP traffic outright, off the protocol-version header [13]. None of it carries a price, because it is not sold; it is the reason to be on the platform.

CrowdStrike paid $637.1m, Okta a press-reported ~$200m and Cisco a sum it has never named, all to own the record; a fourth incumbent is giving the same record away to defend a different franchise. My reading is that this is worse for the independence side than either acquisition, because an absorbed vendor at least establishes a transfer price, and a bundled one establishes that the capability is worth nothing on its own. Cloudflare is on neither side of R01.5’s two-sided test. The layer can also simply stop being a product.

03

Eighty-eight cents of every dollar CrowdStrike paid was goodwill

SGNL is the only transaction in this window carrying a filed number. CrowdStrike's Form 10-Q for the quarter ended 30 April 2026 records total consideration transferred of $637.1m, allocated to goodwill of $561.1m and developed technology of $87.9m [4].

CrowdStrike bought technology worth $87.9m and paid $637.1m

Preliminary purchase-price allocation for SGNL, as filed MEASURED

Unit: US dollars, millions · acquisition date 20 February 2026 · from CrowdStrike's Form 10-Q for the quarter ended 30 April 2026, filed 4 June 2026 · the filer states the allocation is preliminary

SGNL purchase-price allocation: goodwill against developed technology Two horizontal bars. Goodwill: five hundred sixty-one point one million dollars. Developed technology: eighty-seven point nine million dollars, a bar roughly one sixth as long. Goodwill $561.1M · 88% Developed tech. $87.9M
The two bars plus net tangible liabilities of −$11.9m reconcile to the $637.1m transferred; the 88% share is calculated here from the filed figures. The $740m headline is a different quantity in a different class — a CrowdStrike spokesperson's statement to SecurityWeek on 8 January 2026, present in no release and no filing [8].

The same filing calls the acquisition immaterial, against a quarter in which CrowdStrike booked $1,385.6m of revenue, up 26% [4]. CrowdStrike did not buy a business. It bought a position in the authorization path for roughly fifteen times the ~$42m SGNL had ever raised — my calculation from the filed consideration and the reported funding total INFERENCE. Okta's deal has the same shape an order down: a press-reported ~$200m against ~$29m raised [1][2], about 6% of one year's revenue for a company guiding to $3.185–3.205bn in fiscal 2027 [3]. Hence the second meaning in this note's title: a vendor absorbed while its revenue is still immaterial to its buyer never reaches the size at which anyone publishes an ARR figure, and the capability then ships unpriced inside the platform, as Falcon's did [9].

04

The independence side has capital, and no number the test can read

Between 20 July and 5 August 2026 four independent vendors in this layer announced $370m, Neo's $100m launch among them [5]. Zenity's $125m Series C drew SoftBank Vision Fund 2, Intel Capital and Hitachi Ventures, which is not how a dying category gets funded. Every figure comes from the companies and their investors, and not one published revenue of any kind: Oligo gave +300% growth with no absolute base, and Obsidian Security's $1.1bn valuation is a private mark. This signal scores absorption in transactions and independence in disclosed ARR — different units, and only one of them is something companies routinely publish. Part of that −1 measures the ruler, not the world.

The sharpest problem is not on the funding side. On 11 February 2026 Palo Alto Networks completed its acquisition of CyberArk for roughly $25bn on acquirer-announced terms, from an announcement of 30 July 2025 that predates this window [14]. It is not counted here — one public incumbent buying another is not an agent-layer startup absorbed — but it breaks the threshold anyway. R01.5 confirms when an independent authority vendor publicly passes $100m ARR without being acquired. CyberArk cleared that bar a decade ago by an order of magnitude and was absorbed regardless. My reading is that the threshold tests whether a vendor can get big, when the question is whether the layer survives as a category; the correction is a clause requiring independence at the resolution date, minted at the next Scorecard rather than smuggled into a note. Thesis 01 gave Absorption the smallest weight of its scenarios, 15%, the path venture prices least; this window is going the null path's way, and I wrote the weighting down.

A second consolidation runs alongside the first. On 28 July 2026 Cyera announced on its own blog that it was acquiring Oasis Security, stating neither price nor deal form; TechCrunch reported a letter of intent at approximately $1bn the same day, and twenty-two days on nothing public had converted it [15]. Cyera is a private challenger, not an incumbent, so this sits in the M&A registry and outside the count — though Oasis stops being independent either way.

It is tempting to say the incumbents are routing around standards; they are not. Okta's Cross App Access is the product name for the Identity Assertion JWT Authorization Grant, an adopted IETF working-group draft at revision 04 as of 21 May 2026 whose lead author is an Okta employee [16]; CrowdStrike's agent identity is built on the open SPIFFE standard, and its acquisition release names the Continuous Access Evaluation Protocol [7][9]. Falcon decides on Falcon's risk signals, Okta enforces through Okta's own policy engine. The token format is standardised; the decision is not. R01.4 weakens only when drafts stall and vendors ship proprietary schemes, and the first half is false — while no normative profile has shipped either, the relevant US work still at concept-paper stage since 5 February 2026 [16]. Cloudflare’s Agent Access Model of 5 August 2026 carries no status word anywhere: it proposes task-scoped credentials, enforcement in the harness and the network rather than the prompt, and an append-only activity log whose records name the initiating principal, the current actor and the resolved scope — on OCSF and two IETF grants, not a schema of its own [17]. The company sells the gateway such a model would run on. That signal stays at 0 and this note does not move it.

05

What would change my reading

Three dated tests, each scoreable from a named public surface. One — the headline deal closes. Graded on 31 October 2026. If it has not closed by 31 January 2027, or Okta discloses a termination, this was an announcement rather than an absorption and the count reverts to six; a purchase-price allocation in the Q3 FY2027 results, due early December 2026, would also grade the ~$200m against a filed figure. Two — the other side produces a number. By 31 December 2027, if Zenity, Obsidian Security, Oligo Security or Neo discloses ARR at or above $100m while still unacquired, R01.5 confirms and the score moves off −1. The candidate set is fixed here; none had published any figure as of 19 August 2026. Three — the layer gets a price. By 30 June 2027, if CrowdStrike publishes a standalone list price or SKU for Continuous Identity for AI Agents, or Okta does the same for Permiso-derived detection, the layer survived as a priced category and section 03's argument fails.

Method, evidence classes and disclosure. Evidence window: 8 January 2026 to 19 August 2026. The start is anchored to the earliest load-bearing evidence here, CrowdStrike's SGNL announcement of 8 January 2026; the end is the re-check cutoff. Every figure was re-checked against the linked source on 19 August 2026, including a direct read of Okta's newsroom that day, which carries no completion release for Permiso and no price. One event predates the window: Palo Alto Networks–CyberArk, announced 30 July 2025, completed 11 February 2026. Evidence classes: MEASURED a filed or observed record; COMPANY CLAIM a figure a company publishes or states about itself, unaudited; PRESS-REPORTED a figure known only from journalism, published by no party and measured by nobody; FORECAST a named forecaster's projection; INFERENCE my own arithmetic or judgement, inputs shown. Every press-reported figure carries its outlet, its sourcing and the deal's status beside it. Incentives, named: Okta, CrowdStrike, Cyera, Cloudflare and Palo Alto Networks sell products into the trend their releases describe; funding figures come from companies and their investors; the IETF draft cited here is led by an employee of an acquirer. Disclosure: written in a personal capacity from public sources only. The author works within the Türkiye venture ecosystem; to avoid conflicts of interest, no Türkiye-based fund or startup is named or evaluated. The author holds no positions in, and no client relationship with, any company named.

06

This is a note, not a thesis

Notes are conjunctural: the same discipline, a shorter spine, no scorecard of their own. The standing argument this one sits under — and updates — is Thesis 01. Both new transactions, their price qualifiers and statuses, and the two scope amendments queued for the next Scorecard are in the signal ledger.

Sources

  1. 1.OktaOkta signs definitive agreement to acquire Permiso Security, 30 July 2026. Definitive agreement, expected to close in Okta's fiscal third quarter of 2027, subject to customary conditions; no purchase price appears anywhere in the release, and it states no impact on the guidance issued 27 May 2026. All Permiso product descriptions and the Ely Kahn quotation were read verbatim from this page on 19 August 2026.
  2. 2.TechCrunchOkta buys AI security startup Permiso, source says for about $200M, 30 July 2026: the valuation is attributed to a single source with knowledge of the deal; an Okta spokesperson declined to comment on specifics and did not dispute it. Also the source for ~$29m raised in total and an $18.5m Series A led by Altimeter Capital at roughly $80m post-money. securityweek.com — "financial terms of the acquisition were not disclosed"
  3. 3.Okta — first quarter fiscal 2027 results, released 28 May 2026: revenue $765m, up 11% year over year; fiscal 2027 guidance $3.185–3.205bn. With the second-quarter release scheduled for 26 August 2026, Okta's fiscal third quarter of 2027 runs 1 August to 31 October 2026 on its 31 January year end. businesswire.com — Q2 FY2027 results date, 1 August 2026
  4. 4.CrowdStrike Holdings — Form 10-Q for the quarter ended 30 April 2026, filed 4 June 2026, Note 11 "Acquisitions" and Item 2. Acquisition date 20 February 2026; total consideration transferred $637.1m; preliminary allocation to goodwill $561.1m, developed technology $87.9m over 96 months, net tangible liabilities $11.9m; ~$82.2m of Class A shares issued subject to service-based vesting outside the purchase price; the acquisition "did not have a material impact" on the financial statements. Quarterly revenue $1,385.6m, up 26%.
  5. 5.SecurityWeek — Zenity's $125m Series C, 4 August 2026, with SoftBank Vision Fund 2, Norwest, Intel Capital, Hitachi Ventures and LG Technology Ventures named. The independent-capital cluster in this note is this round plus the three below; all amounts are supplied by the companies and their investors, and none is accompanied by a revenue figure. securityweek.com — Obsidian Security, $85m at $1.1bn, 4 Aug 2026 fintech.global — Oligo Security, $60m and +300% growth with no stated base, 5 Aug 2026 globenewswire.com — Neo launches with $100m, 20 Jul 2026
  6. 6.Okta — July 2026 product innovations, 22 July 2026: Agent-to-Agent Connections in general availability, Agent Gateway as a research release, Resource Access Certifications for AI Agents in early access. Source of the adjudicated Ely Kahn claim. okta.com — Agent Gateway runtime governance, 23 July 2026
  7. 7.CrowdStrikeCrowdStrike to acquire SGNL, 8 January 2026. No dollar figure appears in the release; consideration is described as predominantly cash with a portion in stock subject to vesting. Names the Continuous Access Evaluation Protocol as the open standard the enforcement layer is built against.
  8. 8.SecurityWeekCrowdStrike to buy identity security firm SGNL for $740 million in cash, 8 January 2026: the figure is attributed on the record to a CrowdStrike spokesperson and appears in no release and no filing. Also the source for SGNL's ~$42m raised in total, including a $30m Series A in February 2025.
  9. 9.CrowdStrikeCrowdStrike unveils Continuous Identity for AI Agents, 15 June 2026: powered by technology from the SGNL acquisition, agent identity based on the SPIFFE open standard, positioned as the identity security control plane for the agentic enterprise. No list price and no general-availability date is published.
  10. 10.CiscoAI Agents Need New Security: Cisco Announces Intent to Acquire WideField Security, 18 June 2026, with the completion recorded on the same page on 31 July 2026. No price appears anywhere in the post and none has been reported. Both deal dates are the acquirer's own statements about itself. Source of the authority, session and blast-radius formulation and of the Splunk Agentic SOC destination. Read directly on 19 August 2026.
  11. 11.CloudflareCatching rogue AI behavior with identity-aware analytics, 5 August 2026. Identity-aware AI Gateway with Cloudflare Access announced in open beta; User Insights stated as generally available to every AI Gateway customer at no additional cost. Product status is quoted from the post itself; read directly on 19 August 2026.
  12. 12.CloudflareWriteGuard: fine-grained controls for MCP Servers, 5 August 2026: private beta, described as a shared policy, attribution and auditing layer for write actions on MCP servers, built internally before being offered to customers. Read directly on 19 August 2026.
  13. 13.CloudflareHow Cloudflare detects MCP traffic and helps secure it, 14 August 2026: classification of MCP negotiation from the MCP-Protocol-Version header on TLS-inspected requests. No traffic volume is published. Read directly on 19 August 2026.
  14. 14.Palo Alto Networks — completion of the CyberArk acquisition, 11 February 2026, at $45.00 in cash plus 2.2005 PANW shares per CyberArk ordinary share; announced 30 July 2025, outside this note's evidence window, and read on 19 August 2026 for the completion date and the consideration.
  15. 15.CyeraOne platform to secure the agentic enterprise, 28 July 2026: the company announces the acquisition of Oasis Security and states neither a price nor a deal form. techcrunch.com — letter of intent at approximately $1bn, plus Cyera's >$150m ARR and $12bn valuation, 28 July 2026
  16. 16.IETF Datatrackerdraft-ietf-oauth-identity-assertion-authz-grant-04, revision dated 21 May 2026, an adopted OAuth working-group draft whose authors include an Okta employee. Cited alongside the US standards position: csrc.nist.gov — concept paper on software and AI agent identity and authorization, initial public draft 5 February 2026, comments closed 2 April 2026; no normative profile has followed as of 19 August 2026
  17. 17.CloudflareThe Agent Access Model, 5 August 2026: a reference model, not a product — no general availability, beta, preview or waitlist wording appears anywhere in it. Sets out an Agent Identity Broker, a task-scoped access engine, a mediation layer, a trust ratchet and an append-only Agent Activity Log whose records identify the task execution graph, task template, initiating principal, current actor, enforcing component, operation and requested and resolved scope, against the Open Cybersecurity Schema Framework, RFC 8693 and RFC 9449. Cloudflare sells the gateway and access products such a model would run on. The privacy-violation rates the post quotes from third-party CI-Work simulations are not used here; they are simulation results reported by a vendor, and this series does not carry a benchmark it has not read at the primary. Read directly on 19 August 2026.