Summary

  • Okta’s service-specific terms say that, as between the parties, customers are fully responsible for the acts, controls, configurations, omissions and errors of their AI agents. Identity enforcement can improve attribution without transferring the underlying business decision to Okta.
  • Okta for AI Agents is generally available, but the July control additions occupy three different states: Agent-to-Agent Connections is in General Availability, Resource Access Certifications is in Early Access and Agent Gateway is a requestable research release.
  • Fiscal-Q2 2027 subscription revenue rose 12% to US$793 million, RPO rose 17% to US$4.858 billion and cRPO rose 14% to US$2.585 billion. Okta does not disclose AI-agent revenue, customers, licensed Users per Month, agent identities or governed connections.
  • The commercial proof is therefore a bridge, not a headline: paid entitlement must become active identity, governed connection, attributable authorisation, useful action, renewal or expansion and recognised revenue.

The most revealing sentence in Okta’s AI-agent strategy does not appear in its earnings release. It appears in the service-specific terms.

The document defines an AI agent as software that takes autonomous action on the customer’s behalf with little or no human supervision, connects to the service and is managed or governed through it. It then assigns the operational consequence. As between Okta and the customer, the customer is responsible for the agent’s acts, controls, configuration, omissions and errors. Activity by or for the agent counts as customer activity under the agreement and order form.

That allocation matters because Okta describes identity as the control plane for an agentic enterprise. The phrase can sound as though control and responsibility arrive in one package. They do not. Okta may authenticate the principal, enforce a permitted scope, broker a credential, record the event and stop future access. The customer still chooses the agent, connects it, sets policy, assigns an owner and puts its output into a business process. The model maker, application provider and downstream system retain other pieces of the chain.

The clause should not be stretched beyond its language. It is not a court ruling, and it does not cancel Okta’s own contractual, security, privacy or statutory obligations. It does identify the commercial perimeter: the product sells governance over access; it does not guarantee the truth, legality or economic merit of every autonomous act.

One product name, three release states

Okta announced general availability of Okta for AI Agents on 29 April 2026. The available package brought agents into Universal Directory as first-class identities, allowed human owners to be assigned, supported imports from named platforms, governed connections to resources, used scoped credentials and offered access requests, certification, deactivation and telemetry.

The April page also named future capabilities. Agent-to-agent delegation, Agent Gateway, threat detection and human-in-the-loop controls were described as coming in the months ahead. A product can be GA while parts of its roadmap are not. Treating the whole list as one finished surface would turn an announcement into operating evidence.

The 22 July product update makes the ladder explicit. Agent-to-Agent Connections had reached General Availability. Resource Access Certifications for AI Agents was in Early Access. Customers could request access to a research release of Agent Gateway.

These labels do different work. GA indicates a commercially released capability, subject to its documentation and terms. Early Access exposes a feature to a narrower pre-general-release population. A research release is a still earlier operating state. None proves production use at scale, paid attachment or renewal. Equally, the existence of a research component does not make the GA product imaginary.

The functions are strategically coherent. Agent Gateway is meant to stand between agents and tools, validate the agent and initiating user, apply policy and issue a short-lived credential. Agent-to-Agent Connections is meant to preserve the authorised handoff and delegation chain. Resource Access Certifications reviews whether connections should remain after projects or scopes change. Together they cover moment-of-access control and continuing entitlement review.

But the same coherence creates a dependency. A decision at the gateway is only as good as the identity record, owner, policy, requested scope, resource map and revocation state supplied to it. A complete log of the wrong policy is still evidence of the wrong policy. A short-lived credential limits time; it does not decide whether the instructed purchase, code change, payment or customer response was wise.

US$4.858 billion of RPO cannot name the agent contribution

Okta’s Q2 results give the strategy a strong aggregate financial setting. Revenue rose 11% to US$805 million. Subscription revenue rose 12% to US$793 million and accounted for 98% of the total. GAAP operating income increased from US$41 million to US$107 million. Company-defined free cash flow reached US$227 million.

Contracted value also accelerated. Total remaining performance obligations rose 17% to US$4.858 billion. Current RPO, the portion expected to become revenue over the next 12 months, rose 14% to US$2.585 billion. Customers with annual contract value above US$100,000 increased from 4,945 to 5,255, while dollar-based net retention moved from 106% to 107%.

Those numbers support a business with improving expansion and near-term contract visibility. They do not identify an AI-agent business. The Form 10-Q reports subscription revenue across Okta’s platforms and defines RPO as future non-cancelable contracted revenue, including deferred amounts already invoiced and amounts to be invoiced later. It does not break out Okta for AI Agents.

Management is more specific about the drivers it can see. It attributes ACV acceleration to steady momentum in core workforce and customer identity and says new products helped, led by Okta Identity Governance. That statement leaves room for agent products to contribute. It does not quantify them.

The evidence boundary is therefore simple. It is wrong to say AI agents produced none of the US$793 million subscription revenue or US$4.858 billion RPO. It is equally wrong to assign any disclosed portion to them. Okta publishes no AI-agent customer count, revenue, licensed Users per Month, registered-agent count, governed-connection count, tool-call volume, certification rate or renewal cohort.

RPO is particularly easy to overread. It is a contract-accounting state, not cash, usage or a completed deployment. A customer may sign before rollout, invoice before revenue recognition and expand a contract before the new control is fully used. The path from order form to economic value remains: entitlement, implementation, identity registration, resource connection, policy decision, useful operation, renewal and recognised revenue.

Q3 guidance adds a useful check. Okta forecasts revenue of US$813–817 million and cRPO of US$2.590–2.600 billion, implying 11–12% cRPO growth. That is below Q2’s reported 14% rate. The forecast does not isolate agent demand either, but it prevents one quarter’s acceleration from becoming an unbounded adoption curve.

The licence counts users, not the story told about agents

The service terms say Okta for AI Agents is licensed according to the number of Users per Month in the order form. The purchased quantity cannot be reduced during the term; added users are priced consistently for the remainder and co-terminate with it. Okta can monitor use, and usage that materially increases cost or threatens platform stability may produce additional fees, throttling or suspension.

This makes the commercial object more concrete while leaving its public size unknown. The headline subject is the autonomous agent. The contractual meter is a defined monthly-user quantity. The source set does not show a public unit price, a customer order form, current licensed volume or how much realised activity sits behind purchased capacity.

That difference can create healthy recurring economics. A non-reducible in-term commitment gives Okta revenue visibility, while additions create expansion. It can also create shelfware if the purchased base runs ahead of registered agents and governed connections. The next useful disclosure is not merely more logos; it is a relationship between entitlement and active use.

The implementation perimeter is moving as well. Professional-services-and-other revenue fell from US$17 million to US$12 million. The filed table reports a negative 70% gross margin for that line. Okta says it is accelerating the transfer of services work to global systems integrators and expects the change to reduce full-year total-revenue growth by about one percentage point.

Moving a loss-making service line outward can improve Okta’s reported mix and let partners scale deployment. It also puts more of the installation, data mapping, policy design and organisational change in another company’s hands. That is not evidence that partner delivery is worse. It is a change in where delivery quality, labour economics and accountability must be observed.

For agent identity, implementation is not trivial configuration. Someone must discover agents, decide which are sanctioned, bind owners, map resources, convert static secrets, choose scopes, define review intervals and connect logs to response. If a systems integrator performs that work, the economic chain becomes vendor–partner–customer–agent–resource. The subscription belongs to Okta; part of successful control belongs to the partner’s execution and the customer’s policy.

An authorisation receipt is not an outcome receipt

Okta’s proposed runtime record can answer valuable questions. Which registered agent asked? On whose behalf? For which resource and scope? Under which policy? Was access granted? Which credential was issued? What was the result? When was access revoked?

That is a substantial improvement over a shared API key or an unowned service account. It can narrow investigation, support certification and reduce standing privilege. It can also preserve a delegation chain when one agent invokes another.

The record stops short of the business decision. An accounts-payable agent may be correctly authenticated and authorised to send a payment while acting on a fraudulent invoice. A coding agent may have a valid token and still introduce a defect. A customer-service agent may access the right record and generate an impermissible answer. Identity proves who or what crossed a boundary under a rule. It does not prove that everything after the boundary was correct.

That is why the responsibility clause and the control-plane pitch fit together. The more faithfully Okta records identity and authorisation, the more precisely the customer can own the policy and the act. The product’s value is not absorbing all liability. It is replacing an ambiguous failure with a traceable one that can be stopped, reviewed and corrected.

The market opportunity is real if customers will pay for that precision. The current financial report shows stronger aggregate demand, margin and cash. The dated product records show a widening capability set. What remains missing is the joining key between them.

Sources