All right. Excellent. Hey, thanks so much for joining us at the Okta session, day two of the Goldman Sachs Communacopia + Technology Conference. My colleague Callie Valenti and I, really excited to have Eric Kelleher, President and COO of Okta. Hey, thanks for joining us today.
Thanks for having me. It's great to be here.
Eric, I thought maybe the way we could start this conversation is to imagine that we're one of your larger enterprise customers, and the customer calls you up or calls up their salesperson and says, "Look, we're really concerned. We want to do all this cool stuff with agents, but everything we hear on the news is terrifying. You are our trusted identity partner. Make our problems go away." Talk to us about what that customer conversation journey looks like.
Yeah. Our leadership with customers is typically to help them understand the problem. Todd talked about this on earnings, but the biggest competitor we really have right now is just confusion. For an enterprise trying to navigate the technology landscape today, it's never been more volatile, and the security landscape has never been scarier. Every vendor is pitching to them all the various ways they're going to solve all their problems. One of the first steps that we've taken to help customers is just to simplify the landscape. We published what we call the Blueprint for the Secure Agentic Enterprise. Hey, we want to do something with agents. You don't know how to navigate this. We've given them a blueprint, and the blueprint tells them they need to solve for three things. One is they need to know, where are my agents?
There is a problem of discovery, of understanding where agents have been activated by employees, where they exist within the company. Where are my agents? The second challenge they need to solve is knowing what can these agents connect to. So what systems have these agents been allowed to connect to talk to? And the third thing they need to solve is what can they do? What have they been authorized to take? Can they read? Can they write? Can they delete? So those three questions, where are my agents? What can they connect to? What can they do? Those are the three things that customers need to be able to address to give them confidence in their, what we call their security posture, as it relates to agents.
Not surprisingly, our implementation to address the blueprint maps to our product offerings with Okta for AI Agents, and we help them do exactly those three things.
I want to ask you an architectural question, which is, we hear particularly from new entrants in the identity space, that the way that you do identity access for agents is fundamentally different from the way you do it for humans. And the reason that is because agents are ephemeral. It is really tricky to take an architecture like Okta's and make it work for an agentic architecture because of this change in scalability throughput, ephemeral-ness, for lack of a better word. Maybe push back against that hypothesis.
Yeah. I was going to say, we don't agree with that, so that's not surprising. First of all, not all agents are ephemeral. Part of the challenge in this landscape is the word agent means many things to many people, and vendors reapply it to whatever it's going to suit, whatever narrative that they want to share. At its core, we have over 20,000 customers today that trust Okta to secure identity. Securing identity started for them with securing their human identities, with their workforce, and then their extended workforce, and then their customers. From that base, we've earned the trust of customers that we have the capabilities and the know-how to secure identity and keep them secure. It's a natural extension of that trust to be able to talk about how we're going to help secure their agentic identities.
Agents, pieces of autonomous software that typically today run on behalf of a human. In the future, we could all see a future where that's less the case, but today they run on behalf of a human that's enacted them. They need an identity. Whether they're ephemeral, they come on and off as they're needed, or whether they're permanent, they're running 24/7, the agents need to have an identity. As a company, I need to know what agents exist. I need to know who created them. I need to know what they've been given access to and what actions they're authorized to take. To do all of that, I need to have an identity for that agent. Okta provides a Universal Directory of identities, and historically, those identities were human. First workforce, then customer, then service accounts, and now agentic.
That directory has expanded into this use case that allows people to manage that. Once you have the identities in your directory, all of the capabilities of the Okta Identity Security Fabric apply. Single sign-on, we just launched Agent SSO a couple of weeks ago. It's now GA to all of our customers on our workforce platform, which means customers can now add agentic identities into their directory at no charge with their existing platform. Our governance capability, which allows people to provision and deprovision accounts. In the case of an ephemeral agent, just-in-time provisioning and then deprovisioning, turn it on when it's needed, turn it off when it's not, so it doesn't have standing privileges. Things like auditability. Who authorized an agent to access this system? Who gave it delete access?
All of that's captured in our governance product, which does all of that for human identity and will now also do it for agentic identities. The Identity Security Fabric story has never been more real than right now with this new category of identity, which we've elevated as a first-class identity category in our stack. All of the use cases for humans are now available to agents as well.
I want to ask you a little bit about what separates out the customers who are signing the multimillion-dollar deals from those that are still deliberating and evaluating and saying, "Look, the technology is changing so quickly, we don't want to commit right now." How do you get more customers from the evaluation, uncertainty, confusion stage through to they sign the multimillion-dollar deal?
Yeah. The sample size is still small, so I'll speak to the examples that we have. But we announced with our quarterly call. We've done dozens of transactions on this product. Remember, this product went GA April 30th, so we're less than 120 days in at this point. Actually, just crossed 120 days. So we're still learning how to shape this product and how to shape the transactions, and how to shape the pricing in a way that's going to get people over the hurdle. But I'll say there's a couple different categories of what causes first movers. One is we have some enterprise CIOs and CISOs who are very forward-looking in their vision, and they see where the market is going, and they know that this is something that they have to solve more so than their peer group, and they're investing ahead.
We have some customers that have seen agentic activity that's caused them concern, and that gives them an acute need to make sure that they're investing ahead. We have some customers that surprise themselves. One of the examples Todd talked about on the call was a multimillion-dollar deal we booked in the quarter with a Fortune 50 healthcare company. One of the specifics he shared on the call is we had a discovery call with them to talk about Okta for AI Agents and what we could do. At the moment of that initial discovery call, we asked them how many agents that they had deployed, and it was 50. They had 50 agents deployed. We came back to them a few weeks later for a follow-on call, and that number had increased from 50 to 1,500.
So that realization, the customer's realization, they can't wait. This wasn't a problem that they could wait. They saw the path, and that was a catalyst for them. Another thing that we're doing to help convert people is we made it easy to buy. A lot of vendors that are in this space right now are experimenting with pricing models, and they're exploring agent-based pricing models, but you create a chicken and an egg where you ask people how many agents they're going to have, but they don't know how many agents they're going to have.
Not all agents are created the same.
Not all agents are the same. An agent that monitors your email is different than an agent that runs your quote-to-cash process. What ends up happening is your buying cycles become very long and very detailed and very onerous. We've removed all that complexity right now. Our pricing model today is simply an uplift on the per-user pricing, which is imperfect from an agent architecture standpoint, but it's really easy to buy. Our customers know that there's a predictable purchase amount. This is what we're going to pay with Okta to allow us to secure agentic identities. Our agreement with these first transactions is we're mostly doing one-year transactions.
The one you mentioned is a multi-year, but we're mostly doing one-year transactions and very open expectations with the customer that, hey, a year from now, you're going to have better information on how you're using agentic identity and securing that with Okta, and we'll have better information on what it's costing us to manage that security. The pricing model will likely evolve. Today, we're making it really easy to get started, which is what our CISOs need. They need to be able to get started to secure this challenge that they have.
Let me ask you one more on pricing, and then I'll hand it over to Callie. How did you pick the pricing uplift given all of the moving pieces that you just outlined?
In close collaboration with early customers. We've created a specialist team for securing agentic identity that has these conversations all day, every day. We've talked to many hundreds of large enterprise customers who have an acute need and a need to buy and a procurement process and a budget. We have set the price to value based upon what these customers have shaped with us. We feel right now very good about where we're starting, and we're very confident we will evolve this over time.
Okay. I wanted to ask, a year ago, we were having a conversation on which part of the identity stack was going to benefit most as a result of agentic. It feels like what you guys have come out with is kind of grabbing a little bit from each of those categories. You've talked a little bit about the PAM functionality.
Yeah.
We know that at some point, organizations are going to have to prove that agents don't have access to parts of an organization that they're not supposed to and prove that to regulatory agencies. With all that being said, how do you think about what that product looks like today versus what you would need to secure a human?
I talked about this, I think, last time we were here. Our user conference every year is in September, and it's coming up in a couple of weeks. We'll have a bunch of exciting stuff to announce, so pay attention. But last year, our headline for our user conference, only 12 months ago, was the Okta Identity Security Fabric. The security fabric story was our very common narrative with customers that what I hear from customers is the complexity in their fragmented environment causes them to feel insecure. Looking for an identity partner that can solve for all their categories of identity across all of their identity use cases, from access management to governance to privileged access to development is very important to them. That was our headline a year ago at our conference, and our subtext, our secondary topic was securing IaaS.
And boy, how the world has changed in the 12 months since then, where we continue to provide Okta's Identity Security Fabric. We continue to innovate very aggressively. I feel great about our product philosophy right now. We've continued to acquire technologies which improve our product capabilities. So our Permiso acquisition, which we closed the day of earnings, is going to significantly accelerate our product roadmap for our Identity Threat Protection product. These are all exciting innovations into that Identity Security Fabric. But the conversation that's been most vocal is the conversation about this need to figure out what's going on with agents and how we secure agents. But both of them are very real. So for us, the way that we look at the landscape, the security fabric is still the core.
People don't need to solve just token management or just just-in-time provisioning or just access management or just on behalf of auditability. They need to solve all of that. And our product portfolio is the most broad portfolio to address all of those use cases. So we'll be talking more about that this year at Oktane as well, which is in two weeks. But yeah, I guess that's how I would respond to that.
And then identity M&A has become very popular, both from companies that sit in security, but maybe haven't traditionally been part of that identity stack—
Yeah.
—and also for companies that are outside of that security definition, I would say.
Yeah.
How has that changed the competitive landscape? Where do you see the pros of Okta's positioning versus those other companies? Maybe as part of that, you can talk a little bit about the importance of being independent.
Yeah. We think it's really validating. We've been saying for 17 years that identity is the fundamental perimeter, and there are different players that have felt network was the perimeter or that felt that systems were the perimeter or endpoint was the perimeter. We have long established identity as a perimeter and how to ensure you have a secure enterprise corporation. So the steps that you just mentioned, recent acquisitions, are really validating to that view that you have to be with identity to secure it. We have a 17-year head start on establishing that, and broad distribution with our customer base to demonstrate our ability to deliver on that. We've been very successful with that. That being said, we also partner with everyone. You mentioned the importance of neutrality.
The stack vendors, whether it's an application stack or a security stack or a network stack, the stack vendors that are dabbling in identity are just that, they're dabbling. Everything that they build in their roadmap is going to evolve to perpetuating their stack. We're the only provider that has identity as a perimeter that integrates with everything. There's over 8,000 integrations with Okta out of the box. People have come to Okta to integrate their technologies with us because they see us as the identity layer, as the perimeter, and because of that, buyers that buy into Okta know that they have flexibility. They know that they can use best-of-breed technologies wherever they want to because they'll all work with Okta. Right now, we are seeing more volatility in the tools than we've ever seen.
If you look at the frontier models right now, they're leapfrogging each other every 30, 45 days. So our buyers are seeing this need to be agile, the need to be able to adjust the technologies that are in their environment more acutely than they've ever felt it before, which makes neutrality that much more important, which speaks to a core differentiator for us.
Yeah. I wanted to ask about CrowdStrike specifically. I think they've had some identity offerings out in the market for a long time, but I think labeling it as identity versus what Okta does, they almost fit a little bit next to each other versus overlapping. If you could walk a little bit through how some of these tools are complementary to Okta versus competitive, that would be helpful.
Yeah. We have thousands of mutual customers with CrowdStrike as an example, and we expect that to continue. Their positioning in endpoint in particular is uniquely strong, and they're a provider of shared signals into our threat detection product, and we continue to leverage that. So we believe there's plenty of room for their stake in what they're doing, and we're Okta sanitizing.
Yeah.
We haven't seen any material change in our competitive dynamics on that front with CrowdStrike.
Yeah. Developer ecosystem has been a very popular topic of conversation recently. Auth0 has had that outsized developer mindshare for a long time now. How are you leveraging that mindshare that that product already has in this new agentic world, and walk us through that Auth0 for AI Agents too.
Yeah. One of the missing factors in the industry right now with securing agentic identity is the early lack of standards. The challenge has been that there hadn't previously been standards that developers could build to that would allow their agents to be deployed in a secure fashion. We saw this happening early, and a year ago, we proposed a new standard called what we call Cross App Access. Cross App Access is designed to allow agents who support it to integrate with Model Context Protocol for various applications and harnesses in a secure way where those agents can then be managed in a directory and secured. Cross App Access is an open standard. It's not an Okta standard, and we've proposed that from the beginning. It has since been embraced as an extension to the Model Context Protocol. It has been established now as a standard, is being adopted.
We have a lot of exciting announcements about this in a couple of weeks. There's broad industry interest in having a standard that can be used to build and secure agents. All of Okta's products support Cross App Access out of the box. If customers are using Auth0 for AI Agents to build their agents, those agents are able to be stored and vaulted in any IDP, including Okta's, but not exclusively Okta's. That gives developers peace of mind in knowing that they're building agents that customers actually can deploy and can deploy in a secure fashion. That's a significant differentiator for us there. We continue to serve the developer community closely. They're having an exciting time right now because their technologies have never been evolving more rapidly than what they're seeing today.
With things like fine-grained authorization, allowing agents specific access to take specific actions with specific applications, they have that in the Auth0 toolkit already.
Yeah. On that point, as AI is creating more code going forward, how do you think about making sure that AI coding agents are using Auth0 and not going off and building something on their own?
I think that is an early space, and I think the evolution of vibe coding and the SaaSpocalypse will be fun for all of us to navigate and see as this goes. Developers who are developing agents that are going to be deployed as autonomous actors in a company are going to need to have those agents built in a way that they can be managed, and Cross App Access is the key to that.
You have made several rounds of go-to-market changes over the last couple of years.
Yeah.
It feels like things have been stable for a little bit now.
I am glad it feels that way.
I hope it feels that way for you, too. Could you talk a little bit about what you have learned over the past couple of years and how you have repositioned the sales force for this new world we are in and stability and everything?
Yeah, I think our big learning, we talked a lot about 18 months ago. It feels like it was not that long, but also longer. The big learning for us was the product had grown in capability to the point where there was too much product for any one rep to do a good job with all of them. Also, we really identified that we had two distinct buying personas. We had the corporate buyer, the CIO, and the CISO, who was predominantly looking for use cases best served by the Okta platform. Then we had the developer buyer, the developer buyer persona, which was looking to build applications, whether that was B2B SaaS or whether it was an internal build, which had very distinct use cases. The big move that we made 18 months ago was to separate our sellers into platform specialists.
The majority of them are either an Okta platform specialist or an Auth0 platform specialist. Really, they are a buyer specialist, so they are a CIO/CISO persona specialist or a developer persona specialist. That has been hugely important and hugely impactful. What we have seen since we have rolled out all these changes is people see more success. You have heard us talk about pipe gen being very, very strong. People are in their accounts. They have continuity in their accounts. They are generating pipeline. They are closing more cross-sell and up-sells. So we are seeing our new products start to contribute more because reps are now specialized. They can pull in add-on products. We just shared in this quarter, what we call our new product portfolio contributed 30% of our bookings.
That is one of the outcomes of having people specialize on a platform and really focus on the cross-sell opportunities for that platform.
That has been very effective for us. As we see productivity improve, as we see tenure improve, we are very confident that the go-to-market engine is functioning the way that we designed. We are now at the point, one of the questions we got on the call was, when do we burst capacity further? We have announced right now that we feel like we have the right capacity, and one of the reasons we feel that is account continuity has been a contributor. The people that have time within their account. When we choose to burst capacity, that causes us to have to re-carve territories and reassign a bunch of accounts. There will come a time when we do that. It is not right now because we are confident in how we are executing. Overall, the motion is working.
Yeah. As you put more and more products out into market, and you have these individual specialized sales reps, how do you think about how that impacts when you try to elevate the sales conversation to the CIO or C-level?
Every multi-product tech company has this challenge, right? Where do you specialize? Where do you overlay? Where do you support with specialized sales? Where do you support with specialized pre-sales? How do you design all that? We have chosen to anchor our sellers on the buyer. We don't intend to create a new sales function every time we release a new product. That doesn't scale. We also recognize that there are some conversations that are very specific and where having a high volume of at-bats gives sellers more ability to be effective. AI right now is one of those examples. We have our CIO buyers, our CIO sellers, and we have our developer sellers, but we support them with a team of specialists in AI conversations.
That team engages with our sellers on both sides of the business, and we'll scale that team as needed to support it. We expect, as with any new product, eventually those conversations will become such a normal part of the routine that our primary sellers will require less specialization support, but we can continue to subsidize that as long as we need to.
Yeah. You spoke about the improvements that Okta's made in sales productivity and rep tenure and all these things. What are you looking for in the business when you're making these forward decisions on when to increase sales capacity? I guess the real underpinning of that question is you guys have stated that you want to accelerate growth. How do you think about what inputs you need from a sales capacity standpoint to get there?
We have a very granular planning process that is market data informed by what is the vended market, where are people spending money, where is the emerging market, and it is multidimensional. We look at segments, we look at region, we look at country, we look at different product areas. Based upon all of that, we have a set of targets that we expect to be contributing. From that, we understand how much sales capacity we need to hit each of those targets. We model it on a very scientific level down to what we call the slices. One market slice would be governance in Germany and in enterprise, as an example. Our sales capacity model comes from that. Where do we see the growth? What capacities we need to make sure we deliver that growth, and then we add that capacity.
Eric, I will ask the acceleration question in a more macro way.
Sure.
One of the questions that you get from investors is, we are at the very beginning of a very interesting secular shift towards the inference economy. Where if you look at agentic deployments in enterprise, it is still early, and you are already seeing a stabilization and potential acceleration in your revenue cadence. If I were to zoom out, yes, there is the inputs on the sales capacity side. Okta has seen these really exciting periods of secular growth before. Based on everything you know, why would that not be the case for the next three years, where you are going to ride a secular wave that drives growth to be structurally higher, at least for the medium term?
This is a very exciting moment for humanity and for technology and for Okta. Okta's really had three chapters. Our first chapter was the move to cloud computing, and we benefited from that, and we helped catalyze that. Okta helped people move to the cloud faster, and that was a significant shift in industry and something that really catapulted us in our early years. Our middle chapter has been the chapter on identity security and companies realizing that 80% of successful cyber attacks start with compromised identity. Now our buyer shifted from a CIO trying to get to the cloud to a CISO, who's trying to secure their company and have data to make it clear they needed the secure identity to be secure. That was our middle chapter.
Now we're on this frontier right now where we can see a future where human identity and service account identity continue to be important, but there's this rapidly evolving future where agentic identity becomes massive and both very exciting in our ability to innovate and also scary in the potential threats that it creates and that need to be mitigated. We think we're very well-positioned, and we've earned the right to own that market. We're working very hard on it. It's still very early days. We talked in the quarter, we have dozens of transactions for this product that's been GA now for four months. But we're very excited by the future, both in the core business, which had a very strong quarter, and for this new frontier.
Let me ask one more, and then we'll go to Q and A.
Yeah.
One of the things that I've observed about your management team, in particular, is you're very balanced and open about the things that are working and the things that are not. A couple of years ago, Todd talked about wanting to upgrade the quality of R&D internally at the company. Now we think about things like the reference design and the cadence of product innovation that you're putting out. Maybe just reflect on the quality of R&D and the engineering talent that you have, and not just the talent, but your ability to execute on product roadmap.
I am really proud of the progress that we have made there. I can take no credit for it because that is Todd and Ric. Todd brought in a new head of all of our technology a year ago, Ric Smith. He has got a storied career at Oracle and Medallia and SentinelOne, and he has brought a new culture for the R&D organization, and he has brought in new leadership across the R&D organization. That has been a very important shift for us in our own identity as who we are as an innovator. We have seen our product velocity accelerate. You have seen our technology acquisitions, our inorganic growth come in as well as we have expanded our capabilities. Things like Permiso is the most recent.
That is all part of a culture of accelerating product velocity and getting more value to customers faster, and staying grounded on the value we are bringing to customers has really led us. That said, we are not complacent. We can always be better, and so we are always looking at areas where we can bring more value. One of the areas that we talked about in Q2 is we just attained IL5 authorization for our FedRAMP business. IL5 is the highest level non-classified for operating in the federal government. Our PubSec business continues to be an area of strength. The U.S. federal continues to be an area of strength, and that opens up new doors for us further. Our innovation is both in the infrastructure and in the features and in the integration of tech tuck-ins. I feel we have made significant improvement in our velocity.
As I said, we are not complacent, so we are always looking for how we can get even better. Ultimately, we anchor ourselves in the value we are bringing to our customers and are resolving the needs that they need now.
Alex, please.
Thank you. In the core business, that is primary what is driving the growth I think in the future. You talked about the sales force and the changes you made, how that is working. What is driving the core right now, and how sustainable do you feel like that is?
The question for the webcast is what is driving the core and how sustainable are those drivers?
Yeah. What we saw in Q2 was really the fundamentals across the business. So it was a strong quarter for our workforce business. It was a strong quarter for our customer identity business, which right now it is about 59% or 41%. The mix there, the balance feels very healthy, and we expect that to continue. It was a strong quarter for large enterprise and strong execution for our small business and commercial team. It was another strong quarter in PubSec. Our partners contributed really well. We saw great partner contribution. With increased tenure and increased productivity, all those things contributed to the health of it. So the core business, in general, had a really good quarter. In addition to that, our pipeline is at record levels, and so our ability to generate pipe—
Why do you think it's doing so well besides—
Yeah.
—the sales changes?
I—
It's a good product.
I think product capabilities are a big part of it, and I think—
People are worried because of AI just in general.
I think that's newer. I think we'll see that be a stronger contributor in the future. But right now our products, our Identity Security Fabric expanded to the point where we have more land use cases. So our governance product is now a land product for us. So we're able to displace legacy deployments of long-standing on-prem deployments. That opens up new opportunities for us. But it's a combination of all the things you just mentioned.
What's the competitive landscape for agentic AI security so early?
Yeah.
You're a big company. There's startups or other big companies.
The question is, what's the competitive landscape on agentic?
On agentic identity. Todd talked about this on the call, and I think he answered it really well. Our biggest competition right now for securing agentic identity is just confusion.
Yeah.
It's really hard for an enterprise buyer —
Different from that.
—to know what's real. Our biggest differentiator with that is the fact that 20,000 companies already trust us to manage their human identity and their non-human identity, and agentic is a natural hybrid between the latter two. With that, we feel we're very well-positioned for that.
Hey, Eric, where does something like Agent 365 from Microsoft intersect on the governance point?
We don't see them a lot yet. But obviously we keep very close. Microsoft, across all of our use cases, Microsoft is our largest competitor. For people that are looking for E5 bundles or E7 bundled capabilities, and where the capabilities of the Microsoft stack are adequate, that's a viable competitor for us. But where we typically compete there is on neutrality and on the breadth of product functionality across the security fabric, which Microsoft doesn't match today.
The other question that leads nicely from Alex's question is, we have been concerned in the 2022, 2023 timeframe that the best part of the cloud cycle is actually behind you for the identity access management business. Is there another push happening from a modernization standpoint that gets you that last 15, 20 points of industry penetration, or is that sort of irrelevant to the next phase of the Okta story?
All growth is relevant, and our interest is across the board. Our core business continues to. We believe there's room left to run, and so we're continuing to invest in core workforce and core customer identity, and we believe that the most exciting additional frontier, the Horizon 2 frontier for us right now, is going to be agentic, which is why we're investing as heavily as we are in bringing a product to market for that space. We're learning with customers how to evolve that in a way that adds the most value.
Any other nuggets to preview for Oktane?
Tune in to Oktane. Some good partnership announcements, some great roadmap announcements on the Identity Security Fabric, and a keynote that, don't be surprised, is going to talk a lot about agentic identity.
Hey, please join me and Callie in thanking Eric for his time. Eric.
Thank you.