Verdict
Their public materials emphasize different workflows. Permiso gives detailed attention to runtime identity attribution. 8Layers documents an investigation timeline and causality graph alongside a dedicated identity-control evidence module.
This comparison uses vendor-published information only. It does not establish that either product is better. Buyers should confirm required capabilities and integration coverage in a proof of concept.
Verified comparison
The table summarizes the public documentation reviewed. The sections below explain the scope and qualifications behind each entry.
What 8Layers publicly documents
8Layers describes three modules built on a shared identity-data layer:
- Thor for ITDR, historical signal correlation, investigation timelines, causality graphs, and response actions.
- Octagon for identity inventory, posture (ISPM), compound risk scoring, and remediation.
- Compass for validating connected identity controls and organizing evidence against ENS, NIS2, identity-related ISO 27001 controls, and SOC 2 identity-access criteria.
What Permiso publicly documents
Permiso describes an identity-security platform built on its Universal Identity Graph, covering human, non-human, and AI identities across identity providers, IaaS, PaaS, SaaS, and on-premises environments.
Its public pages document identity inventory, posture and risk scoring across behavior, likelihood, and impact, privilege reduction, real-time threat detection, investigation with runtime and control-plane context, real-time AI-agent attribution (agent runs, tool calls, MCP invocations), and response controls including session freeze and step-up authentication.
Documented strengths and review limitations
8Layers
Documented strengths: Connected ITDR and ISPM modules, investigation timelines, causality graphs, direct response actions, and identity-control evidence through Compass.
Review limitations: Public pages do not provide an action-by-connector matrix or numeric pricing. Response coverage should be tested for each required integration.
Permiso
Documented strengths: Runtime attribution across human, non-human, and AI identities, plus risk scoring, privilege reduction, investigation context, and response controls.
Review limitations: The reviewed pages do not document a dedicated compliance-evidence module. Numeric pricing was not displayed.
Which product should you evaluate?
Consider 8Layers when you specifically need:
- ITDR and ISPM built on the same identity-data layer.
- An investigation timeline and causality graph.
- Identity-control evidence for ENS, NIS2, ISO 27001, or SOC 2.
Consider Permiso when you specifically need:
- Runtime attribution across human, non-human, and AI identities.
- Visibility into AI-agent runs, tool calls, MCP activity, and data access.
- Identity risk scoring and privilege-reduction workflows.
These are evaluation criteria, not findings from independent product testing.
Pricing
Neither vendor displayed numeric pricing on the official pages reviewed. Ask both vendors to quote the same identity scope, environments, integrations, retention, response requirements, and AI-agent coverage.
Methodology and limitations
We reviewed current first-party product and solution pages on 31 July 2026. We did not test either platform, review customer-only documentation, or infer that an undocumented capability is absent.
Vendor claims and integration-specific behavior should be validated during evaluation.
Star ratings and review counts are not included because this review did not verify a consistent, current third-party dataset for both vendors.
Sources reviewed
8Layers sources
FAQs
Yes. Both vendors publish threat-detection and identity-posture capabilities. The depth, deployment model, and integration coverage should be tested against your environment.
This review does not make that claim. The reviewed public product pages did not provide enough detail to compare evidence workflows with 8Layers Compass.
8Layers says AI agents can be inventoried, risk-scored, posture-checked, behaviorally monitored, and governed alongside other identities.