Live intel Mon · 31 Aug 2026 · 06:00 ET

ThePerimeter

FOR CIOs & CISOs
VOL. 1 · ISSUE 14 Sponsored by — your logo here — Subscribers: 23,910
// Good morning, defenders.

On Wednesday evening, Okta and CrowdStrike reported earnings within about an hour of each other, and if you read only the headlines you'd think they were describing two different industries. Okta: revenue up 11%, a beat, a raise, the stock up 20% after hours, and a CEO calling the agentic AI opportunity "very early" with revenue contribution still immaterial. CrowdStrike: revenue up 26%, net new ARR up 51%, and George Kurtz declaring that securing AI is "the largest market opportunity in our history." Same market. Same night. One company is banking the identity business it already has; the other is telling you the identity business hasn't started yet.

Both can be right, which is the genuinely useful thing here — and this week you get to watch the argument resolve in real time, because Fal.Con opens today in Las Vegas. So: the week's movers with both earnings calls, then a special segment making a specific, falsifiable prediction about what CrowdStrike announces this week — built not on vibes but on job postings, because hiring is the one roadmap a company can't spin. Then a vendor assessment of Idira, the platform formerly known as CyberArk, where we're going to do some arithmetic that the acquisition headline was very good at obscuring. Let's get into it.

01

Market Movers

the week, distilled — & why it lands on your desk

Earnings+11%

Okta beats, raises, jumps 20% — and calls agentic identity "very early"

Q2 FY27 (quarter ended July 31, reported Aug 26): revenue $805M, up 11%, ahead of the ~$795M consensus. Subscription revenue $793M (+12%) and now 99% of total. Non-GAAP EPS $1.05 against $0.97 expected; GAAP net income $116M, up from $67M. RPO climbed 17% to $4.86B, beating $4.70B. Free cash flow $227M, 28% of revenue. Full-year guidance raised to $3.22–3.23B. Shares rose about 20% after hours.

Two details the headline missed. First, professional services revenue fell 29% to $12M as Okta pushes services to GSI partners — a deliberate roughly one-point revenue headwind traded for deeper partner reach. Second, and more interesting: management reported record bookings while explicitly declining to lean on agentic AI as a growth story. Todd McKinnon called the opportunity "very early" with contribution immaterial to current revenue.

Why it matters: a 20% pop on 11% growth tells you expectations were low and the core business is healthier than the market assumed. For buyers, the honest read is the one Okta gave: its agentic products are new, and the company itself isn't yet claiming they're driving revenue. Price the core, not the roadmap.
Earnings+51%

CrowdStrike's net new ARR grows 51% — and management raises guidance by 630bps

Same evening, different posture. Q2 FY27: revenue $1.47B (+26%), ending ARR $5.84B (+25%), and record net new ARR of $332.8M, up 51%. Falcon Flex ARR passed $2.29B, up 101%. Management raised FY27 net new ARR growth guidance by 630 basis points to 34% at the midpoint. Kurtz's framing: "Every enterprise will run on AI, and securing it is the largest market opportunity in our history." For scale, CrowdStrike cites IDC putting identity security at roughly $29B in 2025 growing to $56B by 2029, and its own identity line was already north of $435M ARR a year ago.

Why it matters: the growth gap between these two is the whole competitive story in identity right now. Okta owns the installed base; CrowdStrike is growing into it from the runtime side and telling investors it intends to keep going. Whichever you buy, understand you're picking a side in an argument about whether identity is a governance problem or a detection problem.
Events10K+

Fal.Con opens today, sold out at record pace

Aug 31 – Sep 3 at Mandalay Bay, themed "Securing the AI Revolution," with 10,000+ attendees from 4,000 organizations across 71 countries and a record 150+ sponsors. CrowdStrike's own release names the lead sponsors as AWS, Accenture, Anthropic, Dell, EY, Google Cloud, Horizon3, Intel, NVIDIA and OpenAI. Worth noting who isn't on that lead list: Okta and Zscaler participate as sponsors but not headliners. Kurtz opens; President Mike Sentonas takes Day 2; a new "Day Zero Threat Research Summit" debuts.

Why it matters: the lead-sponsor roster is a map of who CrowdStrike considers partners versus competitors. Three cloud providers and two model labs at the top, identity incumbents in the back. That's a positioning statement before anyone takes the stage.
PlatformIdira

Palo Alto's CyberArk rebrand keeps generating buyer confusion

Palo Alto completed the ~$25B CyberArk acquisition on Feb 11 and rebranded the portfolio to Idira on May 12. Months later, practitioners are still fielding the same question. One chief architect on a very large deployment put it bluntly: "I have answered the same question in almost every customer meeting since May: did we buy something new? No. You renamed what you already have." Licences carry over, the vault and connectors are unchanged, and the new agentic and machine-identity capabilities are licensed separately.

Why it matters: if your renewal conversation frames Idira as a new platform requiring a new commercial construct, push back. The rebrand is real; the product discontinuity mostly isn't. See this issue's spotlight.
Market$56B

Everyone now agrees identity is the prize — which is exactly when to get skeptical

IDC's identity-security number (~$29B now, ~$56B by 2029) is being quoted in earnings calls by companies that until recently described themselves as endpoint, network, or workflow vendors. CrowdStrike, Palo Alto, ServiceNow, Cisco and Microsoft have all made identity a stated platform pillar within eighteen months. The vendors who were already identity companies now find themselves defending share against buyers with vastly larger balance sheets and existing enterprise agreements.

Why it matters: more competitors is good for your pricing and bad for your architecture. Bundled identity from a platform vendor is rarely as deep as the specialist it replaced — the gap usually shows up in governance workflows, not in the demo.
ThreatAgents

"The adversaries aren't breaking in; they're logging in" is now the industry's shared sentence

The phrase appeared in CrowdStrike materials, Palo Alto's Idira launch quotes, and ServiceNow's Veza rationale within the same year — Idira's Peretz Regev used almost exactly that construction at launch, and Palo Alto claims machine identities now outnumber human ones 109-to-1. When three of the largest security vendors independently converge on identical phrasing, either the market has genuinely reached consensus or everyone is reading the same analyst deck.

Why it matters: shared vocabulary is a sign of a maturing category, and also a sign that positioning has stopped being differentiating. Ask vendors what they do that the other two can't — the answers get much more specific, much faster.
02

The Bold Call

what CrowdStrike announces this week — and why the job board says so

Fal.Con 2026 · Aug 31 – Sep 3
Read the job postings, not the teasers

Every vendor controls its pre-event messaging. Almost none of them think to control the careers page. Hiring is the roadmap a company can't spin — you can't announce a product line you haven't staffed, and you can't hide one you have. So we went looking at what CrowdStrike is actually building for.

Open roles
~210–290varies by source
SGNL closed
$627.9Mcash, Feb 20 2026
Seraphic
GAJul 1, 2026
XM Cyber IP
45+patents, Jul 2026
The prediction, stated plainly so you can hold us to it

Our call: Continuous Identity — the dynamic-authorization engine from the SGNL acquisition — reaches general availability this week and becomes the identity headline of Fal.Con, pitched as the identity control plane for the agentic enterprise, with AI-agent authorization as the hero use case. We'd put that at roughly 80%.

The supporting evidence is a sequence, not a hunch. CrowdStrike signed for SGNL on Jan 7 and closed Feb 20 for $627.9M in cash net of acquired cash, plus $8.9M in replacement equity awards. It pre-launched "Continuous Identity for AI Agents" at Identiverse on June 15 — a teaser with no GA date. And CrowdStrike's own pre-event blog on that product ends by pointing readers at Fal.Con, which is about as close to a save-the-date as a public company gets.

The tell nobody reads

There is a live posting for a "Sr. Project Manager, Continuous Identity (Remote)." Companies don't staff a dedicated program manager for a feature. They staff one for a product line with a launch calendar, cross-functional dependencies, and a GA date somebody is accountable for. That single posting moves this from "likely" to "they've already committed."

The rest of the slate, ranked by confidence
ConfidencePredictionThe evidence behind it
~85% Charlotte AI / AgentWorks and AIDR advancements — "agentic SOC" as the platform narrative AIDR ARR grew >250% sequentially in Q1 FY27; live postings for "Sr. AI Agent Developer" and "Sr. AI/LLM Threat Researcher, Agentic Systems – AIDR"
~80% Continuous Identity reaches GA — extending zero-standing-privilege beyond AD/Entra into AWS IAM, Okta and SaaS Dedicated program-manager role; Identiverse pre-launch in June; blog explicitly points to Fal.Con
~75% A unified endpoint → browser → cloud fabric, with Falcon Secure Access featured Seraphic went GA as Falcon Secure Access Jul 1; a Tel Aviv cluster of browser-security roles posted Jul–Aug 2026
~60% Exposure-management leap built on XM Cyber attack-path IP 45+ patents and source code acquired in July — but no corresponding hiring cluster, consistent with an IP-only deal and early integration
~50% At least one new acquisition or new-category launch Base rate: Fal.Con 2024 announced Adaptive Shield, 2025 announced Pangea. New CPO, acquisitive posture
~45% A cloud entitlement management / NHI governance product A posting states verbatim that CrowdStrike is "establishing a new cloud engineering team that will build a new product focused on cloud entitlement management… at its infancy"
The line that should actually interest a governance buyer

That last row is the one worth your attention, and it's where we'll be watching hardest. CrowdStrike is not currently building classic IGA. There are no product roles for access certification, attestation campaigns, joiner-mover-leaver lifecycle provisioning, role modelling, or SOX entitlement governance. The IAM postings that exist are internal enterprise-IT roles managing CrowdStrike's own 12,000+ users — easy to misread as a governance build-out, and not one.

But "cloud entitlement management… at its infancy" is CIEM territory, and CIEM is governance-adjacent. Combine that with CrowdStrike's NHI messaging — "Who owns this identity? Can I disable it?" — and you get a company circling the entitlement layer from the runtime side while pointedly declining to build certification workflows.

The competitive read, stated carefully

The sharpest anti-incumbent framing to date came from SGNL's own farewell post, which said the team had spent four years "proving that continuous, context-aware authorization could replace legacy PAM and IGA at Fortune 50 scale." That is a direct philosophical challenge to the certification-centric model: access as a real-time control problem rather than a periodic-review problem. Whether it's true is a separate question — periodic attestation exists partly because auditors require it, and no runtime engine has yet made a SOX control go away.

What to watch for, in order of what it would mean

Yellow flag: a cloud entitlement management or NHI governance product ships. That puts CrowdStrike into the fastest-growing part of the SailPoint and Saviynt roadmaps and makes machine identity genuinely contested.

Red flag: CrowdStrike ships access certification, attestation campaigns, or lifecycle provisioning. That is direct IGA competition and would change the category. Our base case is that this does not happen in 2026 — there's no hiring to support it.

Green (for incumbents): everything stays in authorization, ITDR and NHI without governance workflows. Adjacent, not direct.

Listen specifically for four words in the Kurtz and Sentonas keynotes: governance, certification, entitlement, lifecycle. The first use of any of them from a product stage — not a slide about partners — is the moment the competitive picture changes. And note that the most direct casualties of CrowdStrike's current push aren't the IGA vendors at all. They're PAM and access: this issue's spotlight, Idira, and Okta.

METHOD & CAVEATS: These are predictions, not reporting. As of publication the detailed Fal.Con session catalog and keynote specifics were not public and CrowdStrike had not pre-announced product names. Confidence levels reflect base rates from Fal.Con 2024/2025, acquisition sequencing, and public job postings — not disclosed roadmaps, and we have no non-public information. Acquisition terms per CrowdStrike's SEC filings (SGNL: $627.9M cash net of $9.4M acquired cash, plus $8.9M replacement equity awards, closed Feb 20 2026). Job-posting counts vary materially by source (~210–290) and aggregator figures are inflated by third-party recruiters; treat the existence of specific roles as the signal, not the totals. Note also that CrowdStrike's own materials carry future-product disclaimers and past announcements have shipped GA later — a Fal.Con "launch" may be a preview. We'll grade ourselves in the next issue.
03

Vendor Spotlight

the pitch vs. the reality, synthesized from the people who run it

Idira (formerly CyberArk)
Palo Alto Networks (NASDAQ: PANW) · ~$25B, closed Feb 11 2026 · rebranded May 12 2026 · PAM + secrets + certificates + agent identity
VERDICT: BEST-IN-CLASS PAM, INCOMPLETE IDENTITY STACK
Product / Capability
8.0/10
Implementation Ease
4.8/10
Vendor Stability
9.2/10
Governance Completeness
5.0/10

The arithmetic the acquisition headline obscured

The growth story FY2024 →
FY2025
Strip out the acquisitions and CyberArk's growth was decelerating hard

CyberArk's reported numbers going into the Palo Alto deal looked excellent. Q4 2024: revenue up 41%, ARR up 51% to $1.169B. That is a spectacular headline for a company of that size — and it is not what the underlying business was doing.

The company's own Q4 2024 materials disclose that FY2024 ARR "includes $166 million in ARR as of December 31, 2024 from the acquisition of Venafi," which closed October 1, 2024. CEO Matt Cohen's framing at the time was that total ARR was "driven by organic ARR crossing $1 billion and the outperformance from Venafi." Do that subtraction and organic ARR was roughly $1.003B against an implied prior-year base near $774M — call it ~30% organic growth against 51% reported. Then CyberArk acquired Zilla Security in February 2025, adding a second inorganic contributor to the 2025 comparisons.

Read: this is not an accusation of anything improper — the disclosures are right there in the filings, which is how we did the math. It is an observation that the number most people quoted was flattered by roughly 20 points of acquired ARR, and the trajectory underneath was a good-but-normal enterprise software business decelerating toward the twenties.
The trajectory FY2025
By the final independent year, the deceleration was visible even in reported numbers

FY2025 closed with total revenue of $1.361B, up 36% — but that full year still carried Venafi and Zilla contributions the prior year lacked. The cleaner signal is the quarterly exit rate: Q4 2025 revenue grew 19%, down from 41% in Q4 2024. ARR guidance for year-end 2025 was $1.410–1.420B, representing 21% growth — less than half the prior year's reported rate. And Q1 2025 net new ARR was $46M on a $1.215B base.

FY2024 ARR growth — as reported51%
FY2024 ARR growth — organic, ex-Venafi~30%
FY2025 ARR growth — guided21%
Q4 2024 revenue growth41%
Q4 2025 revenue growth19%
Derived from CyberArk's own earnings releases and investor presentations. The organic figure subtracts the $166M Venafi ARR the company itself disclosed for FY2024 against an implied FY2023 base. Zilla Security (closed Feb 2025) adds a further inorganic contribution to 2025 comparisons that the company does not separately size.
Read: a business decelerating from ~30% organic toward ~20% is a perfectly good business. It is also a very different business from the one a 51% headline implies — and a rational moment for a founder-era board to accept $25 billion.
The install base disclosed
Q4 2025
The mix tells you who the customers actually are

Q4 2025 subscription revenue grew 28% overall — but the split underneath is the story. SaaS revenue grew 40%. Self-hosted subscription revenue grew 12%. A large, slow-growing self-hosted line in 2025 is not a cloud-native customer base; it's an on-premises install base being carried forward.

How did that base get built? Substantially through compliance and insurance pressure, and CyberArk said so itself. Its Core Privileged Access Security received a Cyber Catalyst designation from a Marsh-convened panel of cyber insurers. Its own customer case studies lead with the motivation — Indiana University Health's VP of infrastructure and cybersecurity is quoted saying the organization needed to "satisfy cyber insurance requirements," in an announcement headlined around reducing cyber insurance costs by prioritizing PAM.

Read: insurance-driven procurement is real procurement — those are signed contracts. But it buys differently than problem-driven procurement. It optimizes for having the control, not necessarily for operating it, which is how you end up with the pattern below.
The shelfware question ongoing
An entire industry exists to help customers use the CyberArk they already bought

This is the most telling evidence, and it isn't a review — it's a market. There is a substantial third-party ecosystem whose entire value proposition is helping organizations extract value from a PAM deployment they've already paid for. One vendor, Ignimission Protec, markets itself explicitly to "PAM managers" to "accelerate CyberArk adoption and deployment" and maximize "ROI," with a client list of CAC 40 institutions. Systems integrators including GuidePoint staff dedicated CyberArk implementation practices. Independent guides describe the platform as one that "frequently requires full-time teams to operate."

Even genuinely positive reviews carry the caveat. A five-year G2 reviewer calls it "powerful and reliable… highly secure, scalable, and well suited for enterprise environments" — then adds, unprompted, "while the implementation can be complex."

Read: when a services and tooling economy grows up around adoption rather than around extension, that is the market telling you deployment friction is the binding constraint. Products people are successfully using don't need a third-party accelerator with a CAC 40 client list.
SOURCING: All financial figures from CyberArk's own earnings releases, investor presentations and SEC filings (Q4 2024, Q1 2025, Q2 2025, Q3 2025, Q4/FY 2025). The $166M Venafi ARR contribution is disclosed verbatim in CyberArk's Q4 2024 earnings presentation. Deal terms ($45 cash plus 2.2005 PANW shares per share, ~$25B, closed Feb 11 2026) per Palo Alto Networks and contemporaneous reporting. Rebrand date (May 12 2026) per Palo Alto Networks. Cyber Catalyst designation per Marsh/BusinessWire; the IU Health quote per CyberArk's own customer announcement. Third-party tooling and SI evidence per vendor marketing materials and public job postings. The organic-growth calculation is our arithmetic on disclosed figures, not a company-reported metric; CyberArk did not break out organic ARR growth as a line item, and Zilla's contribution is not separately sized. Palo Alto Networks was not contacted and did not review this assessment.

The Pitch vs. The Reality

What Idira says
  • "One trusted platform for your modern privileged access, endpoint and identity governance needs"
  • Zero standing privilege — persistent access replaced by dynamic provisioning from a central control plane
  • Privileged-grade protection extended to every identity: human, machine, and AI agent
  • Existing CyberArk customers keep what they run — "you'll just notice a new logo and design"
What the evidence shows
  • The PAM core is genuinely best-in-class and nearly 30 years mature — this part is not in dispute
  • That maturity carries accumulated complexity; independent guides call it the biggest single complaint
  • "Identity governance needs" is doing heavy lifting — Zilla is modern IGA, not enterprise IGA depth
  • New agentic and machine-identity capabilities are licensed separately, not included in the rebrand
  • The install base skews self-hosted, with that line growing 12% against SaaS at 40%

Community Pulse — synthesized signal

Practitioners · the PAM core genuinely strong
"Powerful and reliable for managing and securing privileged access. Strong password vaulting, session monitoring, and credential rotation. While the implementation can be complex, the platform itself is highly secure, scalable, and well suited for enterprise environments."
— five-year user, G2 (Jan 2026). This is the consensus: the vault works, the session isolation works, the compliance reporting works. Nobody serious argues CyberArk's PAM is weak. The caveat about implementation appears inside a positive review, which is exactly how deeply it's baked into the product's reputation
capable, complex
The adoption economy a market signal
"Helps PAM managers gain total control over their CyberArk projects. Accelerates CyberArk adoption and deployment, while increasing control over your PAM environment and budget… maximizing your ROI."
— third-party vendor marketing, deployed across CAC 40 institutions including major European banks and insurers. Read that as market evidence rather than opinion: a commercially viable product exists purely to help enterprises finish deploying software they already own
deployment friction
The rebrand reception confusion, not anger
"I have answered the same question in almost every customer meeting since May: did we buy something new? No. You renamed what you already have."
— chief architect on one of the largest deployments of the platform. The practical summary from the same source: the vault, connectors and agents kept running; licences carried over; what moved was the brand plus some product names. Note that the certificate business went somewhere else entirely — CyberArk Certificate Manager became Palo Alto's Next-Generation Trust Security, inside network security rather than identity
continuity, with noise
Insurance-driven demand documented, not inferred
"IU Health needed to secure both our IT team and our vendors — as well as satisfy cyber insurance requirements."
— VP of infrastructure and cybersecurity operations, quoted in CyberArk's own customer announcement, headlined around reducing cyber insurance costs. Combined with the Marsh Cyber Catalyst designation from a panel of cyber insurers, this is a well-evidenced demand driver — and one that tends to produce compliance-shaped deployments
real, but compliance-shaped
The governance gap structural
"Whether the new platform reduces governance complexity or simply repackages an already complex estate."
— independent analysis of the rebrand. Idira's marketing claims "identity governance needs," but the governance asset is Zilla Security — a modern, mid-market-oriented IGA acquired in Feb 2025, not a peer to SailPoint or Saviynt on certification depth, entitlement modelling, SoD, or complex on-prem application governance
the real gap
METHOD: Synthesized from CyberArk/Palo Alto financial disclosures, G2 and AWS Marketplace verified reviews, independent rebrand analyses, third-party tooling and SI market evidence, and company customer announcements, as of Aug 2026. A note on the axes. We replaced our usual sentiment score with Governance Completeness (5.0) because that is the specific question a buyer faces here: Idira markets an identity platform, and the PAM half of it is excellent while the governance half is thin. Implementation Ease (4.8) is our lowest score on that axis for any vendor assessed — lower than Saviynt's 5.8 — and we want to be precise: this reflects deployment and operational burden, not product quality. A platform that requires full-time teams and a third-party adoption industry is a genuinely harder buy, and pretending otherwise would not help anyone. Vendor Stability (9.2) is close to definitional now that it sits inside Palo Alto Networks.

The Signal Read

Trajectory: an excellent PAM business bought at the top of its story, now anchoring an identity stack that isn't finished. Let's be fair to the asset first. CyberArk built the definitive privileged access platform. The vault, session isolation, credential rotation and compliance reporting are the reference implementation, and thirty years of enterprise deployment is not something a startup replicates with a Series B. Palo Alto did not overpay for nothing.

But the growth story was flattered, and the install base is heavier than the narrative. Reported ARR growth of 51% became roughly 30% once you subtract the $166M of Venafi ARR the company itself disclosed, then 21% guided the following year, with Q4 revenue growth falling from 41% to 19%. Meanwhile self-hosted subscription revenue grew 12% against SaaS at 40% — an on-premises base being carried, not converted. Much of that base arrived through compliance and cyber-insurance pressure, and insurance-driven buying produces deployments optimized for having the control. That is the mechanism behind the adoption-services economy: not that the product is bad, but that a meaningful share of customers bought a requirement rather than a project.

Which brings us to what Idira actually is today: a superb privileged access platform with an identity governance claim it cannot yet fully support. Zilla Security is a real acquisition and a capable modern IGA, but it is not a peer to SailPoint or Saviynt on certification campaigns, entitlement modelling, separation of duties, or governing complex on-premises applications — the unglamorous depth that enterprise governance programs actually run on. Palo Alto has bought PAM, secrets, certificates and a machine-identity story. It has not bought governance at the depth its "one platform for identity governance needs" language implies.

Speculation — clearly labelled

So does Palo Alto buy an IGA vendor next? We think the structural logic is strong. Palo Alto has demonstrated it will spend at scale ($25B for CyberArk, $3.35B for Chronosphere), it has explicitly named identity a platform pillar, and it now has a visible gap between what Idira markets and what Idira governs. Every competitor is closing that same gap by acquisition — ServiceNow bought Veza, Cisco bought Astrix and WideField, CrowdStrike bought SGNL, SailPoint bought Entro, Cyera is buying Oasis.

Two shapes seem plausible. A true IGA acquisition would close the governance gap directly and put Palo Alto head-to-head with SailPoint — the deepest fix, and the most expensive. An NHI or agent-identity acquisition would be cheaper and more on-narrative: Lumos (modern IGA sitting on top of Okta/Entra), C1 (whose CrowdStrike Falcon Fund position we flagged in Issue 12 — a competitive complication, not a disqualifier), Linx Security (Issue 10), or Token among others. Our read leans toward the second shape in the near term: it fits the agentic narrative Palo Alto is already telling, it's affordable, and it doesn't require absorbing an enterprise governance business with a very different sales motion.

This is opinion, not reporting. We have no knowledge of any process at any of these companies and nothing here should be read as a claim that discussions exist. For a buyer, the practical takeaway is the same one we've given for five issues: if you're evaluating any of the named challengers, negotiate change-of-control protections now.

Buy the story if…
  • You need reference-grade privileged access — vaulting, session isolation, rotation — and can staff it properly
  • You're already a Palo Alto shop and cross-platform consolidation has real economic value to you
  • Your estate is genuinely hybrid or on-prem heavy, where Idira's heritage is strongest
  • Vendor durability is a hard requirement — this is now inside a company with PANW's balance sheet
Do your homework on…
  • Don't buy "identity governance" here without a bake-off against a true IGA on certification, SoD and entitlement depth
  • Budget the operating model honestly — this platform has historically required dedicated full-time staff
  • Confirm what the agentic and machine-identity capabilities cost; they're licensed separately from the rebrand
  • If you're renewing, resist any attempt to reprice the rebrand as a new platform — your licences carried over
  • Ask where certificate management now sits; it moved into Palo Alto's network security portfolio, not identity
04

The Stack

a category, tool, or idea worth knowing this week

Diligence technique

Subtract the acquisitions before you believe the growth rate

This issue's spotlight is the case study: 51% reported ARR growth became roughly 30% once you removed the $166M of acquired ARR the company itself disclosed. The disclosure is always in the filings — vendors are legally required to tell you, they're just not required to headline it. Before you accept any private or public vendor's growth number as evidence of momentum, find the acquisitions in the comparison period and do the subtraction. It takes ten minutes and it changes the conversation.

Signal to read

Job postings are the roadmap a vendor can't spin

Pre-event messaging is controlled by marketing. The careers page is controlled by whoever needs to fill a req. A dedicated program manager for a named product line means a launch calendar exists; a "new team… at its infancy" for an unannounced product tells you what's coming next quarter; and the absence of hiring in a category tells you the roadmap claim is aspirational. Before any major vendor event, spend fifteen minutes on their job board. You'll know more than the analyst preview did.

Category to watch

The adoption-services economy as a product smell

When a third-party market grows up around helping customers finish deploying a product — not extend it, not integrate it, but simply use what they bought — that's the market pricing deployment friction. It's a genuinely useful signal because it's revealed preference rather than opinion. Before you buy any operationally heavy platform, search for who sells accelerators for it. A thriving ecosystem there means budget for a longer runway than the vendor's timeline suggests.

05

Boardroom

one line to sound three moves ahead in your next exec meeting

Say this

Separate the control you own from the control you operate

Somewhere in your estate is a security platform that was purchased to satisfy an auditor or an insurer, deployed to the minimum viable scope, and has not been meaningfully expanded since. Every organization has at least one. Your board almost certainly believes it's fully deployed, because the line item says so. The gap between licensed and operating is the most under-discussed risk on the security balance sheet — and the cheapest to close, because you already paid for it.

"Before we buy anything else, I want an honest inventory of what we already own and what percentage of it is actually operating. My guess is we can close more risk by finishing three deployments than by starting a fourth."
06

Overheard

a spicy anonymized take from the community this week

"We've owned the PAM platform for six years. We vault the domain admins, we pass the audit, and roughly nine thousand service accounts have never been onboarded because the project ran out of budget in year two. Every renewal I get asked what more we'd like to buy. Nothing. I would like to finish."
— head of identity, regional bank · overheard in a peer Slack, lightly paraphrased