Security Stack Logo
Permiso Platform logo

Identity & Access ManagementAI Security

Permiso Platform

ISPM and ITDR for human, non-human, and AI identities across cloud, SaaS, and on-prem environments.

Identity Security Posture Management (ISPM)

Permiso Platform Overview

What it does

The Permiso Platform is an identity security platform combining Identity Security Posture Management (ISPM) with Identity Threat Detection and Response (ITDR) for human, non-human, and AI identities across cloud, SaaS, and on-premises environments. Its distinctive mechanism is the Universal Identity Graph, which connects each identity to the credentials it owns, the machines it creates, and the agents it runs, and tracks every action those identities take in real time as they cross authentication boundaries.

How it works

The platform ingests control-plane activity through read-only API integrations with identity providers, cloud service providers, and SaaS applications, then stitches that activity into the Universal Identity Graph, following users across authentication boundaries. A detection engine built by the P0 Labs research team applies 1,500+ detection signals to surface account takeover, credential compromise, and insider threat, while posture modules flag multifactor authentication (MFA) gaps, stale and zombie accounts, and overly permissive policies. The Risk Score Engine scores each identity on behavior, likelihood, and impact, and agent monitoring attributes tool calls and Model Context Protocol (MCP) invocations to the identity behind them.

Credentials and traction

SOC 2 Type I certified. Permiso won the 2026 SC Award for Best Threat Detection Technology, its second consecutive year of SC Awards recognition after winning Most Promising Early-Stage Startup in 2025. Customers include Nutanix, Autodesk, ACV Auctions, Coupa, and Modern Health, and the platform targets enterprise security and identity teams running multi-cloud and SaaS estates.

Key Capabilities

mapped to solution categories
Identity Security Posture Management (ISPM)

Compares granted permissions against observed usage to identify entitlements that exceed what an identity actually needs, candidates for right-sizing or revocation.

Scores each identity by aggregated risk signals (excessive permissions, stale credentials, anomalous access patterns, MFA gaps) to prioritize remediation effort.

Detects indicators of identity compromise and attack activity (anomalous login sequences, MFA fatigue patterns, impossible travel), at the posture layer, enabling detection of active attacks alongside the static risk posture view. Distinct from EDR identity threat detection, which operates as real-time behavioral detection during an active attack.

Discovers service accounts, OAuth apps, API keys, JWT tokens, and Kubernetes service accounts alongside human accounts, mapping the complete identity population.

Flags dormant and zombie accounts, weak access policies, and identity misconfigurations (such as missing MFA or risky discretionary access) so they can be cleaned up before attackers use them.

Compliance

certifications
SOC 2 Type I

Integrations

compatible tools
1PasswordAnthropicApollo.ioAsanaAutomoxAWSBambooHRBitbucketCalendlyCisco MerakiCloudflareConfluenceDatabricksDeelDocuSignDropboxDuo SecurityDynatraceGitHubGitLabGoogle Cloud PlatformGoogle WorkspaceGrafanaHubSpotJFrog ArtifactoryJiraMailchimpMicrosoft 365Microsoft AzureMicrosoft Entra IDMiroMonday.comNotionOktaOpenAIPing IdentityPostmanSalesforceSemgrepSentryServiceNowSlackSmartsheetSnowflakeTableauTerraformTrelloVantaWebexXeroZendeskZohoZoom

Implementation & support

Deployment model
SaaS

Info last updated on July 26, 2026

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.