
July 22, 2026
Eric Kelleher – COO, Okta
Securing the Agentic Era: Eric Kelleher, President & COO of Okta
Identity has become the most critical perimeter in enterprise security, and no company is more focused on that reality than Okta. As President and Chief Operating Officer, Eric Kelleher has helped steer Okta through multiple reboots, from solving the functional problem of employee access management in the early cloud era, to repositioning the company as a core security platform, to now tackling what may be the most consequential challenge in enterprise technology: securing the identities of AI agents operating autonomously inside corporate networks. With nearly 3 billion dollars in revenue, more than 6,000 employees, and over 20,000 enterprise customers across every major industry, Okta is the infrastructure layer that organizations rely on to verify that the humans, systems, and now agents acting inside their companies are who they say they are and authorized to do what they are attempting to do. Before Okta, Kelleher helped write the SaaS playbook at Salesforce, scaling the company from roughly 50 million to 4 billion dollars in revenue, and built LinkedIn’s first customer success organization, growing the talent solutions business to 2 billion dollars.
On this episode of The Reboot Chronicles Podcast, we sit down with Eric Kelleher, president and COO of Okta, to unpack how identity became the new security perimeter, why the agentic AI wave is creating an entirely new category of security risk that most enterprises are not yet prepared for, how Okta’s open standard for cross-app access is designed to give the industry a baseline for securing agents regardless of which vendor built them, and what the next five years of identity security will look like as the workforce shifts from human to machine. Kelleher also shares the personal reboot story behind his career, including what he learned from bankrupting a SaaS company during the dot-com crash while house poor in Silicon Valley with his first child on the way.
From the Login Box to the Security Perimeter: Okta’s Three Reboots
Okta was founded in 2009 by Todd McKinnon and Freddie Kerrest, both former Salesforce executives who saw that cloud computing was going to fundamentally change how companies managed employee access to software. The first version of the problem they were solving was functional: as organizations began adopting cloud-hosted services alongside their legacy on-premise systems, there was no reliable way to grant employees consistent access across both environments. Okta was built to solve that problem, providing an identity layer and directory that allowed employees to log into both old and new systems from a single point.
That functional foundation served the company well through the early years of cloud adoption. But over the past seven to eight years, the industry’s understanding of identity has shifted dramatically. Research consistently shows that more than 80 percent of successful cyber attacks begin with some form of compromised identity, whether through stolen credentials, phishing, or social engineering. As that data became widely understood, the question of identity stopped being a feature request from IT departments and became a board-level security priority. Okta’s second reboot was repositioning itself accordingly, moving from a functional access management solution to a company that organizations rely on as the security layer specifically focused on identity as the perimeter.
The third reboot is underway now. As AI agents are deployed into production environments and begin taking autonomous actions inside corporate networks, the same authentication and authorization questions that have always applied to humans now apply to software. Is this agent who it says it is? Is it authorized to take the action it is attempting to take? IDC projects that more than one billion agents will be in production within three years. Reports indicate Microsoft already has twenty million lives. Every agent that comes online without a verified identity represents a potential security exposure, and Okta is building the infrastructure to address that at scale.
The Agentic Identity Problem Most Enterprises Are Not Ready For
The pattern Kelleher sees most consistently across the enterprise customers he works with is a familiar one. Organizations move from ignoring AI entirely, to having a wake-up moment where they realize the technology is more transformative than a new feature, to feeling existential urgency about not being left behind, to experimenting and deploying pilots rapidly. The problem emerges at the next stage. The things that have been innovated and deployed to production have not been properly architected or secured.
“Customers I talk to know that they have agents deployed inside their company,” Kelleher said, “but they don’t know where those agents are, they don’t know what they can connect to, and they don’t know what they are authorized to do.” That gap between deployment speed and security architecture is where Okta is focused. The company helps enterprises build an identity security framework around both human and agentic identities, giving organizations the confidence to deploy AI technology without putting their security posture at risk. The goal is not to slow down AI adoption but to make it sustainable, giving companies a foundation that lets them move fast without creating exposures they will have to remediate later at much higher cost.
Cross-App Access: An Open Standard for a Fragmented Market
One of the most significant moves Okta has made in response to the agentic AI wave is proposing and advocating for a new open standard called cross-app access. Rather than building a proprietary solution that only works within Okta’s ecosystem, the company proposed a standard that any identity provider and any agent developer can implement, giving the broader industry a common baseline for agent discovery and security management.
The standard has since been adopted industry wide and incorporated into the model context protocol, meaning developers building agents now have a clear path to making their agents discoverable and manageable within any compliant identity platform. Okta also maintains the Okta Integration Network, a marketplace of more than 8,000 pre-integrated applications that customers can connect to out of the box. The combination of a neutral, open standard and a broad integration ecosystem reflects a deliberate competitive strategy: in a market where AI companies are leapfrogging each other every thirty days and customers cannot predict which technologies they will be building on in five years, Okta’s value proposition is that it supports whatever stack a customer chooses and will continue to do so as that stack evolves. “Our customers really rely on us for our neutrality and for continuing to maintain security regardless of what vendors they need to plug in over time,” Kelleher said.
The SaaS-pocalypse Is Overblown: On Enterprise Software and AI
One of the most persistent narratives in enterprise technology is that AI-powered vibe coding and autonomous software generation will render traditional SaaS platforms obsolete. Kelleher’s view is direct: the narrative is overblown. Every wave of technology that has made it easier to build software has historically created more jobs, more demand, and more complexity, not less. The decades of work embedded in platforms like Salesforce covering governance, compliance, geographic requirements, and currency handling represents genuine accumulated value that no single company is going to rationally choose to rebuild from scratch.
What will happen, in Kelleher’s view, is that the large enterprise software companies will adapt. Salesforce is already moving in that direction, opening its platform so agents can operate more actively within it. The companies that survive and grow will be the ones that treat AI as a new layer to integrate rather than a threat to resist. The comparison he offers is direct: no one in an apartment building builds their own elevator. Common infrastructure with economies of scale exists because it creates value that individual reinvention cannot match. That logic does not disappear because vibe coding exists.
A Dot-Com Bankruptcy, a House He Could Not Afford, and the Lesson That Shaped Everything
Kelleher’s most formative professional moment came not from success but from failure. In 1999, he joined an early SaaS company focused on automating professional services organizations, an early convert to the benefits of multi-tenancy and subscription pricing. Over eighteen to twenty-four months, the company grew from zero to roughly fifty million dollars in ARR. Then the dot-com implosion hit in 2001, IT services firms were among the first to shut down, and the customer base effectively evaporated. The company went bankrupt.
The personal circumstances made it harder. Kelleher had recently upgraded to a home he could not afford. His wife was pregnant with their first child. He was the primary breadwinner with no job and a career path that suddenly looked uncertain. The experience forced him to make a deliberate decision about what came next. He committed to never again joining a company so narrowly focused on a single industry that one market downturn could eliminate the entire customer base. When he connected with a 200-person company selling a contact and opportunity management tool that every company in the world needed, he recognized the horizontal market appeal immediately and joined. That company was Salesforce.
The second lesson from that period was about how he thought about his own career. Rather than committing to a specific functional silo, Kelleher decided to think of himself as a builder and operator, open to taking on whatever the company needed regardless of function, as long as it was building something meaningful. That flexibility allowed him to develop fluency across nearly every part of a business, learn to think like an owner, and make the kind of trade-offs that drive companies toward their potential rather than protecting any individual domain. It is the same orientation he brings to Okta today, where the company’s current reboot, from identity management to agentic security infrastructure, requires exactly that kind of whole-company thinking.





