Permiso Security - Experts & Thought Leaders
Latest Permiso Security news & announcements
Permiso Security, the unified identity security platform, announces the Permiso Risk Score Engine, a proprietary model that assigns continuous, multi-dimensional risk scores to every identity in an organization's environment. The Risk Score Engine is powered by Permiso's Universal Identity Graph and produces three distinct scoring outputs: Identity Risk Scores that prioritise which identities carry the most risk, Session Scores that highlight which activity needs immediate investigation, and Organization Risk Scores that roll up identity risk into a single tenant-level, quantifiable metric with peer benchmarking. Biggest contributing factors "Before Permiso, we had no way to quantify identity risk across our environment in a single view. The Risk Score Engine changed that. We can now see exactly which identities carry the most risk, why, and how that risk is trending over time. It has fundamentally improved how we prioritise," Said Brian Salomon, Security Engineer, YAGEO Group. Enterprise security teams today are unable to answer a straightforward question: across every environment, what is my overall identity risk, and what specifically are the biggest contributing factors? Answering it requires comprehensive visibility of every identity type and runtime behavioural data showing what each identity is doing at any given minute. Most organizations have neither. They assign identities a fixed risk tier based on privilege level and leave it there, or rely on noisy alert-driven approaches that only flag an identity when a detection fires. Neither scales. Distinct response recommendations The Permiso Risk Score Engine addresses these issues through a blend of static posture, graphed relationships between identities, and runtime data to score every identity on a 0-to-100 scale across three dimensions: Behavior (is this identity doing something unusual), Likelihood (is this identity likely compromised), and Impact (how much damage can this identity cause). The three-dimensional approach ensures that two identities with the same composite score, but different risk profiles, receive distinct response recommendations, giving security teams actionable intelligence rather than a single number. "The identity security market has lacked a consistent, quantifiable way to measure risk across all identity types. Continuous scoring that combines posture, behavior, and context into a single model is where the industry needs to go, and it is a meaningful step beyond what legacy ITDR and ISPM tools offer today," said Chris Kissel, Research Vice President, Security Products at IDC. Historical risk profile Key Capabilities: Three-dimensional scoring (Behavior, Likelihood, Impact) that explains why an identity is risky and prescribes specific responses based on the risk profile. Dual-layer risk computation combining static posture analysis (privilege levels, credential hygiene, entitlement scope) with runtime behavioral signals (active anomalies, threat intelligence matches, authentication context). Session-level scoring on dual axes (Suspicion and Impact) that enables SOC teams to triage active sessions based on what is happening now, independent of the identity's historical risk profile. Score velocity detection that identifies when the rate of score change is itself the signal, catching identity compromise sequences that unfold over minutes rather than days. Organization-level risk posture with peer benchmarking that gives CISOs a trackable, reportable metric for board-level communication on identity risk. Coverage across every identity type, from human users to service accounts, API keys, OAuth tokens, and IAM roles, including AI agents, the fastest-growing and least-governed identity class, scored with the same model as every other identity. "Static labels and one-alert-at-a-time triage do not scale when you are managing a global employee base, sprawling NHIs, and a growing agentic workforce. The Risk Score Engine gives every identity a continuous, evidence-backed score that tells you not just that something is risky, but why, and what to do about it," said Paul Nguyen, Co-Founder and CEO, Permiso Security. Another alerting system The Permiso Risk Score Engine is available now as part of the Permiso platform. "We built the Risk Score Engine on top of the Universal Identity Graph because risk scoring without unified identity context is just another alerting system. When you can see every identity, trace how they connect across environments, and layer behavioural baselines with threat intelligence, you can compute a score that actually means something. That is what separates a risk score from a risk guess," said Sanjeev Williams, SVP of Product, Permiso Security.
Permiso Security, the unified identity security platform, announces AI agent runtime security capabilities that give security teams the ability to discover every agent in their environment, managed or shadow, and maintain continuous visibility into agent runs, events, tool calls, and data access across agents, sub-agents, MCP servers, and the underlying infrastructure those agents operate on. Autodesk, a Fortune 500 design and engineering software company, is deploying the capabilities to secure AI agents operating across its products, global workforce, and cloud infrastructure. Making autonomous decisions "Autodesk is investing significantly in AI across our workforce, infrastructure, and products. Permiso Security was already our security platform for Identities, so the natural next step was to partner with them for Agentic AI Identities. Permiso gave us the ability to discover agents across our environment, maintain a full registry, attribute actions to an initiating identity, and monitor all events, runs, and tool calls touching our systems. This is non-negotiable when you’re securing enterprise AI at scale. In the agentic era, visibility and threat detection are what allows us to move fast," said Sebastian Goodwin, Chief Trust Officer, Autodesk. Agents are making autonomous decisions, calling external tools and MCP servers, spawning sub-agents, and interacting with downstream data stores and systems at machine speed, often without human oversight. Most security teams cannot answer fundamental questions about their agent environment: how many agents are running, what identities they are using, what tools they are calling, or what data they are accessing. NHI security vendors Most of the market is solving for posture: where agents are, how they authenticate, what permissions they hold. Posture matters. But posture is a snapshot. Agents operate in real time, making context-dependent decisions across tools, data stores, and downstream systems in milliseconds. The security question that actually keeps security professionals up at night is not what an agent is allowed to do, but what it is doing right now and whether users can stop it. Traditional identity providers lose visibility the moment an agent authenticates, and NHI security vendors are treating agents like static machine identities when agents actually behave more like humans in their credential usage, logging in as the users who deployed them and making context-dependent decisions in real time. Traditional security tools "The market is full of vendors claiming they can prevent AI agent security incidents. As someone who has spent decades in the security industry, I can tell you that’s not possible. You are putting a deterministic capability on a non-deterministic brain. Agents will do things they were not supposed to do. The question is whether you have visibility into every run, every tool call, and every piece of data an agent touches to detect when it happens, and the controls to contain it. That is what we built," said Jason Martin, Co-Founder and Co-CEO, Permiso Security. Purpose-built for the specific challenges agents create: non-deterministic behavior, dynamic tool usage, inherited credential chains, and runtime activity that traditional security tools were never designed to monitor. Behavioral anomaly detection The platform delivers agent runtime identity attribution and agent behavioral anomaly detection across the full agent lifecycle, from the moment an agent is born in a code repository through deployment, runtime operation, and containment. The six core capabilities include: Agent and session discovery that inventories every AI agent, sub-agent, builder, model, and user across cloud, SaaS, IdPs, and code environments, including agents running in Lambdas, containers, and VMs that traditional identity tools cannot see. Identity attribution at runtime that ties every run, event, tool call, and MCP invocation to a specific human, non-human, or AI identity, visualised through Permiso's agent graph and preserved as a complete audit trail. Tool, data, and infrastructure observability captures what tools an agent called, what MCP servers it connected to, what data it accessed, and what downstream systems it reached. Runtime detection of over-privileged access, unused permissions, anomalous tool usage, policy violations, and high blast radius behavior surfaced in the same alert module security teams already use for human and non-human identity threats. Behavioral skill sandboxing of new and existing agent skills. Identity-first controls including least privilege recommendations based on actual agent behavior, approval gates for high-risk actions, and kill switches that operate at machine speed. Enterprise AI copilots These capabilities are informed by years of AI-specific threat research from Permiso's P0 Labs team, including the discovery of LLMjacking attack techniques, cross-prompt injection vulnerabilities in enterprise AI copilots, and analysis of malicious AI agent skills across public marketplaces. "Every enterprise we talk to is deploying AI agents. Almost none of them can tell us how many agents are running, what identities those agents are using, or what MCP servers they are calling. We are not asking customers to buy a new product. We are extending the platform they already trust to cover the fastest-growing and least-governed identity class in the enterprise," said Paul Nguyen, Co-Founder and Co-CEO, Permiso Security. Permiso’s AI agent runtime security capabilities are available today for existing and new customers.
Permiso Security, the unified identity security platform, announces SandyClaw, the first dynamic analysis platform for AI agent skills. SandyClaw executes skills in a sandboxed environment, records every action at the LLM and operating system level, and delivers a verdict backed by multiple detection engines. Permiso platform customers receive unrestricted access. AI agents require skills to perform useful work: downloadable capabilities that teach them how to interact with tools, APIs, and services. Skill marketplaces have become the software supply chain for AI agents, and attackers have already begun publishing malicious skills on these platforms. The current approach to skill security relies on static code analysis or LLM-based evaluation. Neither executes the skill, which means neither can detect behavior that only manifests at runtime. Publishing malicious skills Permiso's threat research team was among the earliest to publicly identify and document malicious skills in the wild. That research led directly to SandyClaw. SandyClaw applies sandbox detonation, a methodology the cybersecurity industry has relied on for evaluating suspicious executables, to the agent skill ecosystem. It records every LLM action, network call, domain resolution, file write, and environment variable access attempt. SSL traffic is intercepted and decrypted. Analysis runs against Sigma, Yara, Nova, and Snort engines augmented with custom Permiso detection rules. SandyClaw works across all major agent frameworks including OpenClaw, Cursor, and Codex. Multi-engine detection "Agents are only as trustworthy as the skills they run. As skill marketplaces become the primary distribution channel for agent capabilities, the ability to validate what a skill actually does before it reaches your environment becomes a security requirement, not a nice-to-have. That is what SandyClaw delivers," said Paul Nguyen, Co-Founder and Co-CEO, Permiso Security Key capabilities: Dynamic detonation with full behavioral recording that captures every action at the LLM and OS level, including network calls, file writes, environment variable access, and domain resolution. Multi-engine detection using Sigma, Yara, Nova, and Snort alongside custom Permiso detection rules, delivering evidence-backed verdicts rather than confidence scores. Full traffic visibility with SSL intercept that decrypts encrypted outbound traffic inside the sandbox, exposing exfiltration attempts that would be invisible to tools without decryption capabilities. Full verdict transparency that provides the complete behavioral record behind every determination, including every file written, domain resolved, and network call made, so security teams can verify the finding themselves rather than trusting an opaque score. Cross-framework support and platform integration covering OpenClaw, Cursor, Codex, and other agent frameworks, with the ability to automatically analyze skills when the Permiso platform detects a download or installation. Sensitive environment variables "Most skill scanners inspect code or ask an LLM for an opinion. But real risk shows up at runtime: network activity, file writes, and access to sensitive environment variables. SandyClaw was built on the belief that behavior is more revealing than source code alone. We detonate the skill, capture everything it does, and let the evidence speak for itself," said Ian Ahl, CTO, Permiso Security SandyClaw is available now. Permiso platform customers receive unrestricted access. Security teams can sign up at sandyclaw.permiso.io to get started.