Identity Security
What identity security is
Identity security is the discipline of governing who (and increasingly what) can access which resources, under what conditions, and for how long. It is not one product but a stack of adjacent control points that grew up separately and are now colliding:
- Access management (IAM / SSO / MFA): the front door — authenticating a human or service and issuing a session. Revenue model: per-user-per-month SaaS, priced on monthly active identities.
- Privileged access management (PAM): vaulting, rotating, and brokering the powerful credentials (admins, root, service accounts) that attackers most want. Higher ACV, stickier, compliance-mandated.
- Identity governance & administration (IGA): the system of record for entitlements — who should have access, certified on a cadence, joiner-mover-leaver automation. Slow-moving, deeply embedded, audit-driven.
- Machine / non-human identity (NHI): the fastest-growing frontier — securing the secrets, tokens, API keys, and workload identities that now outnumber humans 40-to-1 in a modern cloud estate.
- Identity threat detection & response (ITDR) / CIEM: the detection layer that watches identity in use and flags compromise or over-permissioned entitlements.
These were five separate buying centers a decade ago and are converging into a single identity fabric; whoever assembles the most complete fabric, with distribution, captures the pool.
Economics and differentiation across layers
| Layer | Leaders | Challengers | Economics & moat | M&A posture |
|---|---|---|---|---|
| Access (IAM/SSO/MFA) | Microsoft Entra, Okta | Ping (Thoma Bravo), Cloudflare, Beyond Identity | Per-MAU SaaS; moat = directory lock-in + app integrations (Okta's ~7,000+ pre-built connectors) | Okta independent buyer; Ping a TB roll-up |
| PAM | CyberArk (now Palo Alto), Delinea (TPG), BeyondTrust | Teleport, StrongDM, HashiCorp Vault (IBM) | Highest ACV in identity; vaulting is compliance-mandated and highly retentive | CyberArk absorbed; Delinea/BeyondTrust are sponsor-owned consolidators |
| IGA | SailPoint (re-IPO'd 2025), Saviynt | Omada, Zilla (CyberArk), Lumos | Deep ERP/HR integration; switching cost is enormous; slow sales cycles | SailPoint public again; Saviynt a likely strategic target |
| Machine / NHI | Astrix, Aembit, Token Security, Oasis, Silverfort, Clutch | Entro, Britive, Corsha | Land-grab pricing; moat still forming; secrets sprawl is the wedge | VC-backed, strategic-scarce; primarily sell-side candidates |
| ITDR / CIEM | Silverfort, Microsoft, CrowdStrike | Permiso (Okta, closed Aug 26 2026), Sonrai, Ermetic (Tenable) | Detection layer; rides the platform's data | Tuck-in fuel for platforms (Tenable–Ermetic, Microsoft, Okta–Permiso) |
The key differentiation: PAM and IGA are "system-of-record" businesses (high switching cost, durable, compliance-anchored — which is why TB and PANW pay up for them), whereas access management is a distribution business (whoever owns the directory — Microsoft — has structural advantage), and NHI is a greenfield land-grab (no incumbent has won yet, which is why it draws the most sell-side interest).
Consolidation map
The two public pure-plays, first quarter fiscal 2027
Two identity-security companies still report as standalone public pure-plays: Okta in access management and SailPoint in identity governance. Both run a fiscal year ending January 31, so their reporting periods align — the figures below cover the quarter ended April 30, 2026, fiscal Q1 2027 for each (Okta Q1 FY27 results · SailPoint fiscal Q1 2027 results). CyberArk's results are consolidated inside Palo Alto Networks and no longer disclosed separately; Ping, Delinea, BeyondTrust and Saviynt are privately held. The public record of identity economics is therefore these two companies.
| Okta | SailPoint | |
|---|---|---|
| Primary layer | Access management (IAM/SSO/MFA), extending into governance and ITDR | Identity governance (IGA), extending into machine and agent identity |
| Revenue | $765M, +11% | $280.1M, +21.6% |
| Subscription revenue | $750M, +11% | $265.8M, +23.5% |
| Recurring-revenue disclosure | RPO $4.719B, +16%; cRPO $2.499B, +12% | ARR $1,163M, +26%; SaaS ARR $781M, +36% |
| GAAP operating margin | 7.3% (income of $56M) | (28.5)% (loss of $79.8M) |
| Non-GAAP / adjusted operating margin | 25.0% ($191M) | 13.5% ($37.8M) |
| Free cash flow | $271M, 35.4% of revenue | $32.5M, 11.6% of revenue |
| Full-year guide | Revenue $3.185–3.205B (+9–10%); non-GAAP operating margin 25–26%; free cash flow $855–885M | Revenue $1.265–1.275B (+18–19%); ARR $1.364–1.374B (+21–22%); adjusted operating margin 18.7–19.3% |
Three findings follow from the panel.
The two companies score almost identically on growth-plus-margin and arrive there from opposite directions. Rule-of-40 scores are 36 for Okta and 35 for SailPoint, a difference inside the rounding. The composition is not close: SailPoint grows revenue at roughly twice Okta's rate, and Okta runs an operating margin roughly 1.85 times SailPoint's. A single composite score therefore says almost nothing about which business a buyer is looking at, and the layer explains the split — access management is a scaled, penetrated, distribution-led business, while governance is still converting an installed base to subscription.
Cash conversion diverges far more than operating margin does. The non-GAAP operating-margin gap is 11.5 points; the free-cash-flow-margin gap is 35.4% against 11.6%, a ratio of roughly three to one. SailPoint's GAAP operating loss of $79.8M sits $117.7M below its adjusted operating income. That bridge reconciles as $69.1M of equity-based compensation plus $50.8M of amortization of acquired intangibles plus $1.7M of RSU payroll taxes, less a $3.9M credit for amortization of acquired contract-acquisition costs. The two amortization items are direct consequences of purchase accounting from the 2022 take-private; the equity-based compensation is ordinary but elevated following the relisting. The balance sheet carries the same history — goodwill of $5.15B and intangibles of $1.33B together are about 86% of total assets of $7.53B. A leveraged buyout followed by a relisting leaves a company whose GAAP results are shaped by purchase accounting for years afterward, which is why the adjusted and GAAP pictures separate so widely here and barely at all at Okta.
The two do not disclose on the same basis. Okta's quarterly release reports RPO and cRPO and no ARR figure; SailPoint's reports ARR and SaaS ARR and no RPO. The metrics are not interchangeable — cRPO is contracted backlog scheduled to be recognized within twelve months, while ARR annualizes the value of active contracts at a point in time, including contracts in renewal negotiation. Okta's cRPO of $2.499B and SailPoint's ARR of $1,163M cannot be read as a like-for-like scale comparison.
Underneath SailPoint's headline growth, the subscription mix is still shifting: SaaS ARR is 67% of total ARR, SaaS revenue grew 35% while maintenance and support revenue declined 8% and term subscriptions grew 10%. The transition from a perpetual-and-maintenance base to SaaS is the mechanical source of a large share of the growth differential against Okta, and it has a finite runway.
Relevance to M&A. A single "identity comp set" spanning both names produces a misleading benchmark, because the two are priced on different lines: Okta on cash generation and durability at low growth, SailPoint on ARR growth and the trajectory toward its guided ~19% adjusted operating margin. When a private identity target is benchmarked, the comparison has to be made against the layer, not the sector — a governance or PAM asset with a system-of-record install base belongs against SailPoint's growth-and-conversion frame, while a scaled access-management asset belongs against Okta's margin-and-cash frame. The panel also sets the reference point for the sub-scale privates: at $1.16B of ARR, SailPoint is roughly the size at which the layer's economics become visible, and every independent NHI and agent-identity vendor named below is at least an order of magnitude smaller.
Signature deals
- Palo Alto → CyberArk, $25B, closed Feb 11 2026 — the largest pure-play identity deal ever; puts PAM at the center of a network/cloud/SOC platform and reframes identity as the platform battleground.
- Thoma Bravo → SailPoint (2022, $6.9B) → re-IPO 2025 (~$12B+) — the take-private-improve-relist loop, executed on the IGA leader; SailPoint's NHI line is now its fastest-growing segment (see 06a).
- Thoma Bravo → Ping Identity ($2.8B) + ForgeRock ($2.3B), merged — built an access-management challenger by combining two assets it owned.
- Tenable → Ermetic; CrowdStrike, Microsoft into ITDR — detection-layer tuck-ins that pull identity telemetry into the platform.
- Okta → Permiso, agreed Jul 30 2026, closed Aug 26 2026 (~$200M reported; terms undisclosed by Okta) — the access-management leader extends beyond identity issuance into identity threat detection and response, adding runtime detection across human, non-human and AI-agent identities and pulling Okta into the security operations center. Part of the same 2026 wave of identity and data-security platforms absorbing agentic-identity capability (cf. Cyera–Oasis; see 20b). The close was confirmed alongside Okta's Q2 FY27 results, in which the company attributed demand to securing AI agents and other non-human identities and raised full-year guidance; Permiso's P0 Labs threat-research team joins Okta's research operation (23).
- 1Password → Apono, ~$250–300M (reported ~$275M), announced Jun 15 2026 — extends 1Password (AgileBits) from credential security into access governance: just-in-time, policy-scoped, auto-revoked access for every human, machine, and AI-agent identity, paired with its new Credential Broker. The clearest sign that the password-manager incumbents now see NHI/agent access as core, not adjacent. See 11.
- Machine-identity rounds (2025–26): Persona's ~$200M Series D and continued raises across Astrix, Aembit, Token Security, and Oasis confirm NHI as the venture frontier — and the next strategic shopping list. NewCore extended this in Jun 2026 with a $66M seed at a $300M valuation (Cyberstarts-led; founder Zohar Alon of Dome9/Check Point), launching a "security-first identity" platform that treats AI agents as first-class identities — the largest pure AI-agent-identity seed to date.
- Oak — $60M seed, announced Jul 15 2026 (emerged from stealth) — co-led by Accel, CRV, and Greylock Partners, with Hetz Ventures and AlphaDrive Ventures. Founded December 2025 by Shai Morag (CEO; prior exits include Secdo→Palo Alto Networks 2018 and Ermetic→Tenable 2023) and Tal Marom, Oak is an AI-native identity platform — a single control plane intended to replace the fragmented identity-governance/security stack — governing every identity, whether human, machine, or AI agent, generally available and deployed at enterprise customers at launch. Alongside NewCore's $66M and Ent's $100M seed rounds, it is the third identity mega-seed of the 2026 cycle, a signal that agent-era identity now attracts repeat founders at unprecedented entry prices (PR Newswire, Jul 15 2026 · TechCrunch); see 11.
- Keyfactor → Cofide, announced Jul 27 2026 (terms undisclosed) — the first strategic acquisition off that growth capital. Keyfactor acquires UK-based Cofide (founder and CEO Matthew Bates), an open-standards platform built on SPIFFE, OAuth and OIDC that issues each software workload and AI agent a unique, short-lived verified identity in place of static secrets, extending the Trust Control Plane from PKI and certificates into cloud-native workload and agentic identity. The machine-identity incumbent moving into agentic identity by issuance — the counterpart to Okta–Permiso's move into agentic-identity detection — with team and technology joining immediately. See 11, 20b.
AI-agent access governance
The fastest-moving thread inside NHI is no longer just secrets sprawl but governing what an autonomous AI agent is allowed to do — provisioning an agent identity, scoping its access to a task, and revoking it when the work is done. Agentic workflows broke the old assumption that identity = a human with a standing account: agents are non-deterministic, numerous, and short-lived, so the control model shifts from vaulting a credential to brokering just-in-time, policy-bound access in real time. This is the wedge under the 2026 identity buying wave — CrowdStrike–SGNL (real-time grant/revoke), Cisco–Astrix and Cisco–WideField (agent/NHI discovery + telemetry into Splunk's Agentic SOC), SailPoint–Entro (secrets + machine-identity into its Agentic Fabric), 1Password–Apono (JIT access governance), and Keyfactor–Cofide (SPIFFE-based workload/agent identity issuance). Finro's Q2 2026 dataset confirms the pull at the deal level: IAM led every cyber niche with 15 M&A transactions at a ~20x average EV/Revenue, explicitly attributing the demand to "AI-agent proliferation making identity infrastructure non-negotiable for platform buyers" (see 12). The independents still in play — Aembit, Token Security, Oasis, Britive, Corsha, plus newly-funded NewCore — sit directly in the path of that demand.
The incumbent response is now shipping rather than announced. SailPoint moved Agentic Fabric to general availability in August 2026 and packaged it with Human Fabric — the renamed Identity Security Cloud — as a single Identity Security solution, available both standalone and inside its Agentic Business suites. The disclosed capability set reaches past governance into agent runtime control: endpoint and browser sensors that discover AI agents, credentials and Model Context Protocol servers; inline prompt inspection that redacts personally identifiable information before it reaches a model; a centralized control to disable a rogue agent; and automated ownership rules assigning a human owner to every machine account. The company's own research, cited in the launch, puts 97% of AI agents as having access to sensitive data and 21% of organizations as highly confident in managing AI-agent security risk — vendor-sponsored figures, and directionally consistent with the deal record above (SailPoint, Aug 4 2026).
What that build-out cost is now public, and it is smaller than the market assumed. SailPoint's periodic filings price three acquisitions that were never publicly priced or were priced wrongly: Entro Security at $122.6M cash for 100% of the equity on Jun 29 2026, against roughly $200M reported at announcement; Security Savvy Ltd (Savvy) at $18.4M on Sep 15 2025, structured as an asset acquisition rather than a business combination; and, earlier, Imprivata's acquired assets at $16.4M and Double Zero at $5.4M. Four transactions assembling the agent-identity and application-visibility layers total roughly $163M of consideration. Against the $122.6M Entro price, the ARR that Agentic Fabric is now expected to carry is the relevant comparison: SailPoint reports AI-driven ARR above $70M and targets at least $800M by FY29 (23). The capability was bought for materially less than one year of the revenue it is being asked to produce, which is the argument for buying this layer rather than building it, and it sets a lower reference price for the remaining NHI independents than the reported figures did (11).
Two consequences for the sub-segment. First, the boundary between identity governance and AI security is moving: prompt inspection and agent kill-switches are not governance functions, and an IGA incumbent shipping them inside an existing enterprise contract narrows what a standalone agent-security product can claim as distinct (20b, AI Security). Second, it sharpens what the independents have to sell: the incumbent bundles discovery, governance and runtime enforcement together, while most of the venture-funded cohort sells one of the three. Vendors positioned on visibility alone are the most exposed to that packaging.
The bear case
If Microsoft's directory advantage compounds — Entra bundled into E5, free Security Copilot capacity, ITDR built in — then standalone access vendors (even Okta) face structural multiple compression, and the independent identity premium narrows to PAM, IGA, and NHI only. The falsifiable test is Okta's net revenue retention and whether NHI startups can reach durable seven-figure ACVs before the platforms ship "good-enough" native NHI. If NHI economics stay thin and platforms ship native, the land-grab collapses into tuck-ins rather than standalone exits.
→ Cross-references: Vendors, Thoma Bravo, Deals & Comps, AI Security, Buy-Side Prospect Framework.
Adjacent market: the fraud-prevention and identity-verification industry converging with cyber identity is mapped on Fraud & Identity Verification.
Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.