UpTrajectory Review
The core idea here is worth sitting with: businesses have spent two decades building identity and access management around humans — employees, contractors, customers — and AI agents are quietly breaking that model. An AI agent with system access isn't an employee; it doesn't have a badge, it doesn't get offboarded, and it can act at machine speed. Okta is betting that 'who are you?' is about to become 'what are you, and what are you allowed to touch?' That's a real and underappreciated shift, and TheStreet's piece captures the moment Okta tried to claim that territory at its Oktane 2026 conference.
For small-business operators, this isn't an abstract enterprise problem. If you're using AI tools that connect to your CRM, your accounting software, or your email, you already have agents operating inside your systems — often without a clear inventory of what they can access or do. The 'Shadow AI Agent Discovery' product Okta announced exists precisely because companies don't know what's already running. If you're not asking vendors hard questions about agent permissions and audit trails, you're likely exposed in ways your current security setup wasn't designed to catch.
What TheStreet's piece does well is surface the tension in BofA's analysis: the analyst raised the price target to $220 but kept a Neutral rating, explicitly noting that Okta's AI story is more compelling than its near-term financial reality. That's a useful signal. It suggests the 'Agentic Identity' market is real but early — Okta is positioning for a wave that hasn't fully arrived. We agree with BofA's skepticism that narrative alone doesn't justify aggressive positioning, but the conference announcements (free Agent SSO, Agent Gateway, Agent-to-Agent Connections) are concrete enough to take seriously.
The second-order effect worth watching is competitive. Okta isn't the only player chasing agent governance — Microsoft, Palo Alto Networks, and a wave of startups are all circling the same problem. If Okta's 'control layer' thesis holds, it could expand its total addressable market meaningfully, as BofA suggests. But if the market consolidates around platform players like Microsoft, Okta's window narrows. For operators, the practical implication is that your identity stack vendor is about to become a much more strategic decision than it used to be.
What to do now: audit which AI tools in your stack have API access to sensitive systems, ask your identity vendor what their agent-governance roadmap looks like, and pay attention to whether Okta's free Agent SSO offering gains traction — free entry points often signal a land-grab strategy that smaller vendors can't match. The agent identity problem is real, and it's arriving faster than most small businesses are prepared for.
“Companies increasingly need to govern not only who can access their systems, but also which AI agents may access them and what those agents can do once they're inside.” — TheStreet
Takeaway: Audit which AI tools have system access now — agent governance is becoming a core security requirement, and your current identity setup likely wasn't built for it.
Excerpt from the original — TheStreet
Artificial intelligence is generating a new cybersecurity dilemma. Companies increasingly need to govern not only who can access their systems, but also which AI agents may access them and what those agents can do once they’re inside.
That might be a big opportunity for Okta (OKTA), according to Bank of America Securities.
Okta’s Oktane 2026 conference led BofA analyst Tal Liani to lift his price target on the stock to $220 from $200, according to a Sept. 24 research note emailed to TheStreet.
The analyst kept the Neutral rating but pointed out the disconnect between the promise of Okta’s AI approach and how little it’s really doing for the firm now.
Okta used its annual conference to cast itself as an identity-security control layer for AI bots. Among the developments BofA called out were free Agent SSO, Shadow AI Agent Discovery, Agent Gateway, and …