Omada has acquired EmpowerID. That puts one of the most comprehensive Identity Governance and Administration (IGA) offerings together with one of the most developer-centric and AI-forward challengers in the market. Omada gains runtime authorization for AI agents, a faster way to integrate target systems, and a credible path into Policy-Based Access Management (PBAM), Privileged Access Management (PAM), and Zero Trust.
Omada's First Strategic Move Since the GRO Deal
On 24 September 2026, Omada announced that it has acquired EmpowerID, the US-based identity vendor headquartered in Dublin, Ohio. Financial terms were not disclosed. EmpowerID's technology will be integrated into Omada's IGA platform, with a focus on runtime governance of AI agents, and EmpowerID CEO and co-founder Patrick Parker joins Omada as Chief Innovation Officer.
The deal follows last year's change of ownership. On 29 April 2025, Omada announced that GRO Fund III, together with Kirk Kapital, would take a majority ownership position. That transaction provided a full exit for CVC Growth Funds and GRO Fund II, with J.P. Morgan Asset Management's Private Equity Group and Danish pension fund P+ joining as co-investors. Then-CEO Michael Garrett said Omada intended to "explore strategic M&A opportunities," and EmpowerID appears to be the first strategic acquisition to follow that commitment.
|
Acquirer |
Target |
Reported value |
Status |
Context |
|
Omada (Copenhagen, Denmark) |
EmpowerID (Dublin, Ohio, US), founded 2005 |
Not disclosed |
Announced as completed, 24 September 2026 |
Omada launched Agent Governance in June 2026. EmpowerID adds runtime authorization for AI agents, the EmpowerNow AI components, and AI-assisted connector building. |
EmpowerID Extends Omada Beyond Governance
Omada is known primarily as an IGA vendor with strong out-of-the-box capabilities, standardized user experience, and a well-defined process framework. EmpowerID has moved beyond IGA. It has expanded from identity lifecycle governance into identity services such as authorization, orchestration, and connectors, and more recently into AI agent governance.
With EmpowerID, Omada gets a foothold in markets such as PBAM, PAM, and Zero Trust, and a technical foundation for moving IGA toward real-time access control covering human identities, non-human identities (NHIs), and AI agents. This moves Omada substantially closer to being an Identity and Access Management (IAM) platform provider rather than an IGA specialist with a few adjacent capabilities. Martin Kuppinger summarized it in the announcement: "AI agents act at machine speed, and governing them after the fact is not enough." Beyond governing who is entitled to access, runtime authorization adds a check on what an agent is permitted to do at the moment it acts, which periodic certification cycles do not cover.
How the CRUD Service and EmpowerNow Complement Omada
Part of EmpowerID's EmpowerNow AI stack, the CRUD (create, read, update, delete) Service acts as a wrapper around target systems, including legacy ones. Administrators describe the capabilities of a system in YAML, and the CRUD Service exposes them to workflows and agents in a consistent way. Because the user's identity flows through to the target system, actions are executed in the right context. For Omada, this simplifies integration with target systems and helps enforce better identity information quality, which has long been one of the harder parts of IGA deployments in environments with large SAP landscapes and homegrown applications.
Closely related is AI-assisted connector building. EmpowerID states that custom connectors can be built in 15 to 30 minutes with AI assistance, working directly in AI development tools, compared to hours of traditional engineering effort. It also offers more than 300 pre-built connectors. Connectors have traditionally been the slow and expensive part of IGA projects, so if Omada and its partners can deliver more and deeper integrations at speed, including adaptations to customer-specific changes to target systems, it would shorten IGA deployments.
The EmpowerNow components also bring runtime authorization for AI agents. This covers controls for what an agent can do and delegated authority, and it allows agents to complete actions without holding reusable credentials. EmpowerID is also certified for OpenID AuthZEN 1.0. For Omada, this adds runtime enforcement to the offering and should help it make fast progress in AI security.
EmpowerID Fills Gaps in Omada's Agent and AI Roadmap
Omada launched Agent Governance in June 2026, focused on visibility, ownership, and least privilege for AI agents and NHIs, together with compliance evidence for audits. Runtime enforcement was not included in that release.
In recent conversations with Omada customers and partners, confidence in Omada's approach to agents was mixed. Several were uneasy about key capabilities sitting on the roadmap for the end of this year while other vendors have already published solutions. The broader use of AI has also been one of Omada's challenges.
From what EmpowerID has shown in vendor briefings, it brings mature capabilities in AI usage and enhancement, including integrated chatbots, role mining, flexible workflow engines, and analytics. At the same time, customers report that EmpowerID's flexibility has not always translated into robust standard functionality, an area where Omada's out-of-the-box functionality is well established.
Integration Risks Worth Watching
As with every acquisition of vendors playing the same field, there is overlap in IGA. Omada covers it from a commercial off-the-shelf (COTS) perspective with standardized user experience and process frameworks, while EmpowerID follows a developer-centric approach focused on flexible, AI-powered customization. Customers of each will want to know which path their deployment is on. Combining a standardized platform with a highly configurable one will take a while, and the goal should be more flexibility and faster delivery in customized environments without leaving customers with two overlapping ways of solving the same problem.
The benefits described above depend on Omada leveraging EmpowerID's strengths and combining both technical solutions into an integrated approach. If EmpowerID ends up as a separate product line next to Omada Identity, most customers would see little benefit from the deal.
Much of what EmpowerID and EmpowerNow have on the roadmap for agentic authorization is with Patrick Parker and his team. Bringing him in as Chief Innovation Officer and keeping that team engaged through the integration will be essential. Omada will also need to show customers quickly that the acquisition closes the gaps they have raised, especially on agents and AI-assisted governance, ideally with committed delivery dates.
Agent Governance Becomes a Baseline Requirement for IGA
Over the past year, identity vendors have been buying their way into agent and NHI security at a steady pace.
|
Deal |
Announced |
Reported value |
What the buyer gained |
|
ServiceNow / Veza |
2 December 2025 |
~$1bn (SecurityWeek) |
Access intelligence across human, machine, and AI identities |
|
SailPoint / Entro |
15 June 2026 |
~$200m (SecurityWeek) |
NHI discovery and secrets security |
|
Cyera / Oasis Security |
28 July 2026 |
~$1bn (KuppingerCole) |
NHI management for a data security platform |
|
Omada / EmpowerID |
24 September 2026 |
Not disclosed |
Runtime agent authorization, AI-assisted integration, PBAM |
These deals indicate that agent governance is turning into a standard expectation for IGA platforms. Buyers will expect their IGA platform to discover agents, assign ownership, and certify their access, and over time they will expect it to enforce what agents can do at runtime as well.
Omada's deal has a different focus from the others. Most of the other acquisitions were about gaining visibility into NHIs and agents, and EmpowerID brings runtime enforcement and integration speed on top of that.
A Broader Market Position for Omada
KuppingerCole's Leadership Compass on Identity Governance and Administration describes modern IGA moving toward continuous reconciliation and event-driven lifecycle management, with governance extending across human identities and NHIs alike. The EmpowerID acquisition pushes Omada further along that path and into adjacent areas such as policy-based authorization.
A combined Omada and EmpowerID platform points toward a real-time access solution that brings together IGA, policy-based authorization, PAM capabilities, and agent governance. That is a much broader market position than Omada has held so far, and it puts Omada in direct competition with vendors that already market themselves as identity security platforms. Over the next 12 to 18 months, Omada will need to deliver the combined roadmap while keeping the IGA foundation its customers value.
Recommendations
If you are an Omada customer, there is no need for immediate action, but you should ask Omada for a concrete roadmap on runtime agent authorization, AI-assisted role and policy building, and connector development, and for clarity on when EmpowerID capabilities will be available within your current deployment model.
If you are an EmpowerID customer, confirm support commitments and the future of the product line you run today. Where your deployment relies heavily on customizations, ask how these will be carried forward as the platforms converge.
If you are evaluating IGA, you should now treat agent governance as a mandatory requirement, and test discovery, ownership, certification, and runtime enforcement for AI agents during the evaluation. Integration speed is best assessed against your own target systems, including customized ones, since connector counts alone say little about how quickly your environment can be onboarded.
If you are a partner or integrator, AI-assisted connector building may change the economics of your IGA projects considerably, so ask Omada early how and when you will get access to these tools.
As agent governance moves into the core of IGA, Omada has given itself a good starting position, and the integration work ahead will decide how much of it reaches customers as usable capabilities