
Identity & Access ManagementAI Security
Permiso Platform
ISPM and ITDR for human, non-human, and AI identities across cloud, SaaS, and on-prem environments.
Permiso Platform Overview
What it does
The Permiso Platform is an identity security platform combining Identity Security Posture Management (ISPM) with Identity Threat Detection and Response (ITDR) for human, non-human, and AI identities across cloud, SaaS, and on-premises environments. Its distinctive mechanism is the Universal Identity Graph, which connects each identity to the credentials it owns, the machines it creates, and the agents it runs, and tracks every action those identities take in real time as they cross authentication boundaries.
How it works
The platform ingests control-plane activity through read-only API integrations with identity providers, cloud service providers, and SaaS applications, then stitches that activity into the Universal Identity Graph, following users across authentication boundaries. A detection engine built by the P0 Labs research team applies 1,500+ detection signals to surface account takeover, credential compromise, and insider threat, while posture modules flag multifactor authentication (MFA) gaps, stale and zombie accounts, and overly permissive policies. The Risk Score Engine scores each identity on behavior, likelihood, and impact, and agent monitoring attributes tool calls and Model Context Protocol (MCP) invocations to the identity behind them.
Credentials and traction
SOC 2 Type I certified. Permiso won the 2026 SC Award for Best Threat Detection Technology, its second consecutive year of SC Awards recognition after winning Most Promising Early-Stage Startup in 2025. Customers include Nutanix, Autodesk, ACV Auctions, Coupa, and Modern Health, and the platform targets enterprise security and identity teams running multi-cloud and SaaS estates.
Key Capabilities
mapped to solution categoriesCompares granted permissions against observed usage to identify entitlements that exceed what an identity actually needs, candidates for right-sizing or revocation.
Scores each identity by aggregated risk signals (excessive permissions, stale credentials, anomalous access patterns, MFA gaps) to prioritize remediation effort.
Detects indicators of identity compromise and attack activity (anomalous login sequences, MFA fatigue patterns, impossible travel), at the posture layer, enabling detection of active attacks alongside the static risk posture view. Distinct from EDR identity threat detection, which operates as real-time behavioral detection during an active attack.
Discovers service accounts, OAuth apps, API keys, JWT tokens, and Kubernetes service accounts alongside human accounts, mapping the complete identity population.
Flags dormant and zombie accounts, weak access policies, and identity misconfigurations (such as missing MFA or risky discretionary access) so they can be cleaned up before attackers use them.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on July 26, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.