AtomationDocsOkta setup overview

Okta integration docs overview

Use this page to choose the right Atomation Okta setup guide. API access powers assessment scans; SAML SSO controls workspace sign-in; SCIM handles lifecycle and role groups.

API accessSAML SSOSCIM provisioningRoles

Choose the right Okta guide

Atomation's Okta setup now has dedicated docs for each connection type. Start with the guide that matches the job you are doing.

Okta API access

Required for assessment scans. Use this guide to configure the Okta API Services app Atomation uses to read posture evidence from each connected Okta org. Automated setup assigns Super Administrator to the permanent app and grants 31 assessment reads plusokta.appGrants.manage. Routine scans request only the reads; Atomation reserves the org-level management scope for a future reviewed workflow targeting the configured connector app. Setup must revoke the temporary Okta API token (SSWS) created by a Super Administrator.

Open the API access guide.

How the Okta pieces fit

API access, SAML, SCIM, and roles solve different setup problems. Keeping them separate avoids mixing scan access with user login or provisioning.

Setup areaWhat it doesWhere to go
Assessment data connectionCreates one Okta API Services app per scanned Okta org to collect assessment evidence without modifying the org.Okta API access guide
Workspace sign-inLets users sign in to Atomation through Okta SAML 2.0 for the primary identity org.Okta SAML SSO guide
User lifecycleCreates, updates, deactivates, and groups users through SCIM 2.0 provisioning.Okta SCIM provisioning guide
Role mappingMaps Okta groups to Atomation workspace roles after you know the intended access model.Roles and permissions reference

Recommended setup order

1

Connect the assessment data plane

For the first scan, start with Okta API access. This is the required scan connection and stays separate from workspace login. If you have an .oktapreview.com org, connect and scan it before production to validate the setup, findings, framework mappings, and report workflow.

Preview orgs count toward connected-org allowances and retain only the most recent completed scan and generated report. Download a Preview report before rescanning if you need to keep the earlier result.

2

Add SAML SSO when you want Okta workspace login

Use the SAML SSO guide for the primary identity org. Do not use the API access setup as a substitute for SAML login.

4

Repeat API access for additional scan-only orgs

Multi-org customers configure a separate API Services app for each scanned Okta org. SAML and SCIM remain tied to the workspace's selected primary identity org.

OIN and customer setup boundary

For SAML and SCIM review or configuration, use the dedicated SAML SSO and SCIM provisioning guides. The Okta API access guide is the customer assessment data connection and is intentionally documented separately.

Current separation: API access is for assessment evidence. SAML SSO is for workspace authentication. SCIM is for user lifecycle and group-to-role mapping. Roles are documented in the roles and permissions reference.

Support