Sept. 24, 2026

How Jason Martin Built Permiso, Sold It to Okta, and Saw the Next Identity Security Challenge Coming

Tech leadership often means recognizing a problem before the market has a name for it. That is a central theme of my conversation with Jason Martin, co-founder of Permiso Security, on The Tech Leader’s Playbook. Jason helped build a company around a growing gap in cloud security: organizations could verify an identity when it logged in, but struggled to see what that identity did afterward.

That gap matters even more as companies deploy AI agents that can access data, call tools, and act across systems. It also helps explain why Okta acquired Permiso in August 2026. Jason’s story brings together two questions every technology leader should be asking: How do you build a company before buyers fully understand the problem? And how do you secure an enterprise when some of its most active “workers” are software?

Start With the Problem, Not the Product

Before building Permiso, Jason and his team spoke with roughly 100 enterprise security leaders. That customer discovery shaped their view of the market. They saw a recurring problem around cloud identities, permissions, and activity after authentication.

Consider what happens when a legitimate account is compromised. The initial login may appear normal. The danger emerges in what follows: unusual access, unexpected actions across cloud services, or use of privileges that the account never needed in the first place. A security team needs to connect those actions to the identity behind them quickly enough to respond.

Permiso built for that problem. Its platform helps security teams discover identities, understand their access, and detect suspicious behavior across cloud environments. The company’s focus was broader than employee accounts. Service accounts, applications, and other non-human identities could also carry significant permissions and create risk.

For founders, the lesson from Jason’s approach is practical: enthusiastic feedback does not prove that a market exists. The stronger signal is whether customers recognize the problem in their own environment, devote attention to it, and change their behavior to solve it.

Building Before the Market Catches Up

In our conversation, Jason discusses the difficulty of creating a category while also trying to sell a product. A founder can understand an emerging risk clearly and still face a hard go-to-market problem: buyers may lack a budget, an agreed name for the issue, or a clear owner for the decision.

Permiso had to make identity threats visible and urgent to customers who were already juggling competing security priorities. That meant translating a technical problem into an operational one: Who has access? What are they doing with it? How would we know if that activity became dangerous?

Jason also talks about the pressure that comes with fundraising and leading a growing company. Those parts of the episode matter because the path from insight to acquisition was not automatic. Finding an important problem is only the beginning. A team still has to build a useful product, earn customer trust, and sustain the company while the market develops.

He and fellow co-founder Paul Nguyen also shared the co-CEO role. In the episode, Jason discusses what that leadership arrangement required as Permiso grew. It is a useful reminder that a startup’s operating decisions are part of the story, alongside its technology.

Why AI Agents Make Identity Security More Urgent

Permiso’s original insight has become more consequential with the rise of AI agents. Traditional identity systems can tell an organization that a user or application authenticated. That does not necessarily give a security team a clear view of the actions that follow.

An AI agent may call tools, interact with other applications, access sensitive data, or carry out a sequence of tasks with limited human intervention. Some agents may use credentials associated with the person who deployed them. If the organization cannot trace an action back through that chain, investigating a problem becomes much harder.

Jason has described this as a visibility gap after authentication. In a May 2026 article, he explained why knowing an agent’s permissions at one moment is insufficient: security teams also need to understand what it actually does while running. Permiso extended its platform to connect agent activity, tool calls, and data access back to an identity, with detection and response built around that activity.

For CISOs, this leads to a more useful set of questions than simply asking how many agents the company has:

  • Which agents can access sensitive systems and data?

  • Who owns each agent and the credentials it uses?

  • Can we trace its actions across tools and systems?

  • What behavior would trigger an investigation?

  • Can we contain the agent quickly if something goes wrong?

Inventory and least-privilege access are essential starting points. Runtime visibility and the ability to respond matter too, especially when an agent’s actions may unfold faster than a person can review them.

The Okta Acquisition

Okta announced its agreement to acquire Permiso on July 30, 2026, and confirmed that the acquisition closed on August 26. The deal brought Permiso’s identity threat detection capabilities into Okta’s broader identity platform.

The strategic fit is clear. Okta helps organizations manage identity and access. Permiso adds insight into risky behavior across human, machine, and AI agent identities, including activity that takes place after access has been granted. Okta has said the acquisition will strengthen its ability to detect and respond to identity threats and expand its reach into security operations.

For Jason and the Permiso team, the sale marks a significant outcome after years spent developing a market and building for it. It also gives their work a route to reach more organizations through Okta. The acquisition is one chapter of the episode, but it connects directly to the security discussion: the problem Permiso set out to solve has become harder for enterprises to ignore.

What Leaders Can Take From Jason’s Story

Jason’s journey offers lessons for both founders and enterprise technology leaders.

For founders, customer discovery comes first. Talk to the people who live with the problem before committing to a product or assuming that investor interest equals customer demand. If the market is early, be prepared to explain the problem repeatedly and show why it deserves action now.

For technology and security leaders, identity can no longer be treated as a question answered at login. You need to understand the access granted to people, applications, and agents, then see how they use it. As AI agents take on more work, that visibility becomes part of deploying them responsibly.

My conversation with Jason covers the full arc: the early customer interviews, the challenge of building and selling Permiso, the realities of co-CEO leadership and fundraising, the Okta acquisition, and the identity risks created by AI agents. Watch the full episode, “How AI Agents Are Forcing a Rethink of Enterprise Identity Security.”

Related Episode

146
Aug. 20, 2026

How AI Agents Are Forcing a Rethink of Enterprise Identity Security

In this episode of The Tech Leader’s Playbook, Jason Martin shares the founder decisions behind building Permiso, from interviewing 100 enterprise security leaders before writing code to creating a new cybersecurity market before most buyers understood the problem. He breaks down product-market fit, go-to-market challenges, fundraising pressure, co-CEO leadership, startup resilience, and the realities of selling a company. The conversation also explores AI agents, non-human identities, identity ...