On Wednesday evening, Okta and CrowdStrike reported earnings within about an hour of each other, and if you read only the headlines you'd think they were describing two different industries. Okta: revenue up 11%, a beat, a raise, the stock up 20% after hours, and a CEO calling the agentic AI opportunity "very early" with revenue contribution still immaterial. CrowdStrike: revenue up 26%, net new ARR up 51%, and George Kurtz declaring that securing AI is "the largest market opportunity in our history." Same market. Same night. One company is banking the identity business it already has; the other is telling you the identity business hasn't started yet.
Both can be right, which is the genuinely useful thing here — and this week you get to watch the argument resolve in real time, because Fal.Con opens today in Las Vegas. So: the week's movers with both earnings calls, then a special segment making a specific, falsifiable prediction about what CrowdStrike announces this week — built not on vibes but on job postings, because hiring is the one roadmap a company can't spin. Then a vendor assessment of Idira, the platform formerly known as CyberArk, where we're going to do some arithmetic that the acquisition headline was very good at obscuring. Let's get into it.
the week, distilled — & why it lands on your desk
Q2 FY27 (quarter ended July 31, reported Aug 26): revenue $805M, up 11%, ahead of the ~$795M consensus. Subscription revenue $793M (+12%) and now 99% of total. Non-GAAP EPS $1.05 against $0.97 expected; GAAP net income $116M, up from $67M. RPO climbed 17% to $4.86B, beating $4.70B. Free cash flow $227M, 28% of revenue. Full-year guidance raised to $3.22–3.23B. Shares rose about 20% after hours.
Two details the headline missed. First, professional services revenue fell 29% to $12M as Okta pushes services to GSI partners — a deliberate roughly one-point revenue headwind traded for deeper partner reach. Second, and more interesting: management reported record bookings while explicitly declining to lean on agentic AI as a growth story. Todd McKinnon called the opportunity "very early" with contribution immaterial to current revenue.
Same evening, different posture. Q2 FY27: revenue $1.47B (+26%), ending ARR $5.84B (+25%), and record net new ARR of $332.8M, up 51%. Falcon Flex ARR passed $2.29B, up 101%. Management raised FY27 net new ARR growth guidance by 630 basis points to 34% at the midpoint. Kurtz's framing: "Every enterprise will run on AI, and securing it is the largest market opportunity in our history." For scale, CrowdStrike cites IDC putting identity security at roughly $29B in 2025 growing to $56B by 2029, and its own identity line was already north of $435M ARR a year ago.
Aug 31 – Sep 3 at Mandalay Bay, themed "Securing the AI Revolution," with 10,000+ attendees from 4,000 organizations across 71 countries and a record 150+ sponsors. CrowdStrike's own release names the lead sponsors as AWS, Accenture, Anthropic, Dell, EY, Google Cloud, Horizon3, Intel, NVIDIA and OpenAI. Worth noting who isn't on that lead list: Okta and Zscaler participate as sponsors but not headliners. Kurtz opens; President Mike Sentonas takes Day 2; a new "Day Zero Threat Research Summit" debuts.
Palo Alto completed the ~$25B CyberArk acquisition on Feb 11 and rebranded the portfolio to Idira on May 12. Months later, practitioners are still fielding the same question. One chief architect on a very large deployment put it bluntly: "I have answered the same question in almost every customer meeting since May: did we buy something new? No. You renamed what you already have." Licences carry over, the vault and connectors are unchanged, and the new agentic and machine-identity capabilities are licensed separately.
IDC's identity-security number (~$29B now, ~$56B by 2029) is being quoted in earnings calls by companies that until recently described themselves as endpoint, network, or workflow vendors. CrowdStrike, Palo Alto, ServiceNow, Cisco and Microsoft have all made identity a stated platform pillar within eighteen months. The vendors who were already identity companies now find themselves defending share against buyers with vastly larger balance sheets and existing enterprise agreements.
The phrase appeared in CrowdStrike materials, Palo Alto's Idira launch quotes, and ServiceNow's Veza rationale within the same year — Idira's Peretz Regev used almost exactly that construction at launch, and Palo Alto claims machine identities now outnumber human ones 109-to-1. When three of the largest security vendors independently converge on identical phrasing, either the market has genuinely reached consensus or everyone is reading the same analyst deck.
what CrowdStrike announces this week — and why the job board says so
Every vendor controls its pre-event messaging. Almost none of them think to control the careers page. Hiring is the roadmap a company can't spin — you can't announce a product line you haven't staffed, and you can't hide one you have. So we went looking at what CrowdStrike is actually building for.
Our call: Continuous Identity — the dynamic-authorization engine from the SGNL acquisition — reaches general availability this week and becomes the identity headline of Fal.Con, pitched as the identity control plane for the agentic enterprise, with AI-agent authorization as the hero use case. We'd put that at roughly 80%.
The supporting evidence is a sequence, not a hunch. CrowdStrike signed for SGNL on Jan 7 and closed Feb 20 for $627.9M in cash net of acquired cash, plus $8.9M in replacement equity awards. It pre-launched "Continuous Identity for AI Agents" at Identiverse on June 15 — a teaser with no GA date. And CrowdStrike's own pre-event blog on that product ends by pointing readers at Fal.Con, which is about as close to a save-the-date as a public company gets.
There is a live posting for a "Sr. Project Manager, Continuous Identity (Remote)." Companies don't staff a dedicated program manager for a feature. They staff one for a product line with a launch calendar, cross-functional dependencies, and a GA date somebody is accountable for. That single posting moves this from "likely" to "they've already committed."
| Confidence | Prediction | The evidence behind it |
|---|---|---|
| ~85% | Charlotte AI / AgentWorks and AIDR advancements — "agentic SOC" as the platform narrative | AIDR ARR grew >250% sequentially in Q1 FY27; live postings for "Sr. AI Agent Developer" and "Sr. AI/LLM Threat Researcher, Agentic Systems – AIDR" |
| ~80% | Continuous Identity reaches GA — extending zero-standing-privilege beyond AD/Entra into AWS IAM, Okta and SaaS | Dedicated program-manager role; Identiverse pre-launch in June; blog explicitly points to Fal.Con |
| ~75% | A unified endpoint → browser → cloud fabric, with Falcon Secure Access featured | Seraphic went GA as Falcon Secure Access Jul 1; a Tel Aviv cluster of browser-security roles posted Jul–Aug 2026 |
| ~60% | Exposure-management leap built on XM Cyber attack-path IP | 45+ patents and source code acquired in July — but no corresponding hiring cluster, consistent with an IP-only deal and early integration |
| ~50% | At least one new acquisition or new-category launch | Base rate: Fal.Con 2024 announced Adaptive Shield, 2025 announced Pangea. New CPO, acquisitive posture |
| ~45% | A cloud entitlement management / NHI governance product | A posting states verbatim that CrowdStrike is "establishing a new cloud engineering team that will build a new product focused on cloud entitlement management… at its infancy" |
That last row is the one worth your attention, and it's where we'll be watching hardest. CrowdStrike is not currently building classic IGA. There are no product roles for access certification, attestation campaigns, joiner-mover-leaver lifecycle provisioning, role modelling, or SOX entitlement governance. The IAM postings that exist are internal enterprise-IT roles managing CrowdStrike's own 12,000+ users — easy to misread as a governance build-out, and not one.
But "cloud entitlement management… at its infancy" is CIEM territory, and CIEM is governance-adjacent. Combine that with CrowdStrike's NHI messaging — "Who owns this identity? Can I disable it?" — and you get a company circling the entitlement layer from the runtime side while pointedly declining to build certification workflows.
The sharpest anti-incumbent framing to date came from SGNL's own farewell post, which said the team had spent four years "proving that continuous, context-aware authorization could replace legacy PAM and IGA at Fortune 50 scale." That is a direct philosophical challenge to the certification-centric model: access as a real-time control problem rather than a periodic-review problem. Whether it's true is a separate question — periodic attestation exists partly because auditors require it, and no runtime engine has yet made a SOX control go away.
Yellow flag: a cloud entitlement management or NHI governance product ships. That puts CrowdStrike into the fastest-growing part of the SailPoint and Saviynt roadmaps and makes machine identity genuinely contested.
Red flag: CrowdStrike ships access certification, attestation campaigns, or lifecycle provisioning. That is direct IGA competition and would change the category. Our base case is that this does not happen in 2026 — there's no hiring to support it.
Green (for incumbents): everything stays in authorization, ITDR and NHI without governance workflows. Adjacent, not direct.
Listen specifically for four words in the Kurtz and Sentonas keynotes: governance, certification, entitlement, lifecycle. The first use of any of them from a product stage — not a slide about partners — is the moment the competitive picture changes. And note that the most direct casualties of CrowdStrike's current push aren't the IGA vendors at all. They're PAM and access: this issue's spotlight, Idira, and Okta.
the pitch vs. the reality, synthesized from the people who run it
CyberArk's reported numbers going into the Palo Alto deal looked excellent. Q4 2024: revenue up 41%, ARR up 51% to $1.169B. That is a spectacular headline for a company of that size — and it is not what the underlying business was doing.
The company's own Q4 2024 materials disclose that FY2024 ARR "includes $166 million in ARR as of December 31, 2024 from the acquisition of Venafi," which closed October 1, 2024. CEO Matt Cohen's framing at the time was that total ARR was "driven by organic ARR crossing $1 billion and the outperformance from Venafi." Do that subtraction and organic ARR was roughly $1.003B against an implied prior-year base near $774M — call it ~30% organic growth against 51% reported. Then CyberArk acquired Zilla Security in February 2025, adding a second inorganic contributor to the 2025 comparisons.
FY2025 closed with total revenue of $1.361B, up 36% — but that full year still carried Venafi and Zilla contributions the prior year lacked. The cleaner signal is the quarterly exit rate: Q4 2025 revenue grew 19%, down from 41% in Q4 2024. ARR guidance for year-end 2025 was $1.410–1.420B, representing 21% growth — less than half the prior year's reported rate. And Q1 2025 net new ARR was $46M on a $1.215B base.
Q4 2025 subscription revenue grew 28% overall — but the split underneath is the story. SaaS revenue grew 40%. Self-hosted subscription revenue grew 12%. A large, slow-growing self-hosted line in 2025 is not a cloud-native customer base; it's an on-premises install base being carried forward.
How did that base get built? Substantially through compliance and insurance pressure, and CyberArk said so itself. Its Core Privileged Access Security received a Cyber Catalyst designation from a Marsh-convened panel of cyber insurers. Its own customer case studies lead with the motivation — Indiana University Health's VP of infrastructure and cybersecurity is quoted saying the organization needed to "satisfy cyber insurance requirements," in an announcement headlined around reducing cyber insurance costs by prioritizing PAM.
This is the most telling evidence, and it isn't a review — it's a market. There is a substantial third-party ecosystem whose entire value proposition is helping organizations extract value from a PAM deployment they've already paid for. One vendor, Ignimission Protec, markets itself explicitly to "PAM managers" to "accelerate CyberArk adoption and deployment" and maximize "ROI," with a client list of CAC 40 institutions. Systems integrators including GuidePoint staff dedicated CyberArk implementation practices. Independent guides describe the platform as one that "frequently requires full-time teams to operate."
Even genuinely positive reviews carry the caveat. A five-year G2 reviewer calls it "powerful and reliable… highly secure, scalable, and well suited for enterprise environments" — then adds, unprompted, "while the implementation can be complex."
Trajectory: an excellent PAM business bought at the top of its story, now anchoring an identity stack that isn't finished. Let's be fair to the asset first. CyberArk built the definitive privileged access platform. The vault, session isolation, credential rotation and compliance reporting are the reference implementation, and thirty years of enterprise deployment is not something a startup replicates with a Series B. Palo Alto did not overpay for nothing.
But the growth story was flattered, and the install base is heavier than the narrative. Reported ARR growth of 51% became roughly 30% once you subtract the $166M of Venafi ARR the company itself disclosed, then 21% guided the following year, with Q4 revenue growth falling from 41% to 19%. Meanwhile self-hosted subscription revenue grew 12% against SaaS at 40% — an on-premises base being carried, not converted. Much of that base arrived through compliance and cyber-insurance pressure, and insurance-driven buying produces deployments optimized for having the control. That is the mechanism behind the adoption-services economy: not that the product is bad, but that a meaningful share of customers bought a requirement rather than a project.
Which brings us to what Idira actually is today: a superb privileged access platform with an identity governance claim it cannot yet fully support. Zilla Security is a real acquisition and a capable modern IGA, but it is not a peer to SailPoint or Saviynt on certification campaigns, entitlement modelling, separation of duties, or governing complex on-premises applications — the unglamorous depth that enterprise governance programs actually run on. Palo Alto has bought PAM, secrets, certificates and a machine-identity story. It has not bought governance at the depth its "one platform for identity governance needs" language implies.
So does Palo Alto buy an IGA vendor next? We think the structural logic is strong. Palo Alto has demonstrated it will spend at scale ($25B for CyberArk, $3.35B for Chronosphere), it has explicitly named identity a platform pillar, and it now has a visible gap between what Idira markets and what Idira governs. Every competitor is closing that same gap by acquisition — ServiceNow bought Veza, Cisco bought Astrix and WideField, CrowdStrike bought SGNL, SailPoint bought Entro, Cyera is buying Oasis.
Two shapes seem plausible. A true IGA acquisition would close the governance gap directly and put Palo Alto head-to-head with SailPoint — the deepest fix, and the most expensive. An NHI or agent-identity acquisition would be cheaper and more on-narrative: Lumos (modern IGA sitting on top of Okta/Entra), C1 (whose CrowdStrike Falcon Fund position we flagged in Issue 12 — a competitive complication, not a disqualifier), Linx Security (Issue 10), or Token among others. Our read leans toward the second shape in the near term: it fits the agentic narrative Palo Alto is already telling, it's affordable, and it doesn't require absorbing an enterprise governance business with a very different sales motion.
This is opinion, not reporting. We have no knowledge of any process at any of these companies and nothing here should be read as a claim that discussions exist. For a buyer, the practical takeaway is the same one we've given for five issues: if you're evaluating any of the named challengers, negotiate change-of-control protections now.
a category, tool, or idea worth knowing this week
This issue's spotlight is the case study: 51% reported ARR growth became roughly 30% once you removed the $166M of acquired ARR the company itself disclosed. The disclosure is always in the filings — vendors are legally required to tell you, they're just not required to headline it. Before you accept any private or public vendor's growth number as evidence of momentum, find the acquisitions in the comparison period and do the subtraction. It takes ten minutes and it changes the conversation.
Pre-event messaging is controlled by marketing. The careers page is controlled by whoever needs to fill a req. A dedicated program manager for a named product line means a launch calendar exists; a "new team… at its infancy" for an unannounced product tells you what's coming next quarter; and the absence of hiring in a category tells you the roadmap claim is aspirational. Before any major vendor event, spend fifteen minutes on their job board. You'll know more than the analyst preview did.
When a third-party market grows up around helping customers finish deploying a product — not extend it, not integrate it, but simply use what they bought — that's the market pricing deployment friction. It's a genuinely useful signal because it's revealed preference rather than opinion. Before you buy any operationally heavy platform, search for who sells accelerators for it. A thriving ecosystem there means budget for a longer runway than the vendor's timeline suggests.
one line to sound three moves ahead in your next exec meeting
Somewhere in your estate is a security platform that was purchased to satisfy an auditor or an insurer, deployed to the minimum viable scope, and has not been meaningfully expanded since. Every organization has at least one. Your board almost certainly believes it's fully deployed, because the line item says so. The gap between licensed and operating is the most under-discussed risk on the security balance sheet — and the cheapest to close, because you already paid for it.
a spicy anonymized take from the community this week