AtomationDocsPartner guide

Atomation Partner Onboarding Guide

A practical guide for pilot partners using Atomation's hosted Okta assessment portal for client workspaces, Okta assessment connections, scans, findings, and reports. Final partner authorization hardening must be validated before live client onboarding.

Hosted pilot portalOkta assessment accessPDF version

What Atomation Is

Atomation Okta Assessment helps teams turn Okta configuration, access posture, and compliance evidence into a deterministic, auditor-ready report. The assessment connector is built for Okta Identity Engine orgs and does not auto-remediate inside the customer's Okta org.

Primary useOkta posture review

Run assessment scans across users, groups, apps, policies, admins, devices, and other Okta configuration evidence.

Partner outputReport-ready findings

Deliver prioritized findings, evidence, framework mappings, and remediation context without rebuilding a spreadsheet assessment.

Commercial modelQuoted scope

Pricing is based on the partner program scope, client workspaces, org count, report depth, scan cadence, and support needs.

Access modelNo remediation write-back

Setup configures the Atomation connector app; assessment scans do not change users, groups, policies, apps, or settings.

The Hosted Partner Model

Atomation hosts everything. As a partner, you get a partner portal at {partner-slug}.atomation.io running on Atomation infrastructure. There is nothing to install, patch, or operate.

AreaHow It Works
Partner accountAtomation creates the partner account and sends the technical contact a one-time setup link.
Client workspacesEvery client gets a tenant-addressed workspace at {client-slug}.atomation.io with its own connected orgs, scans, findings, reports, and selected application audit events. No public enforced retention tier is promised today.
Partner accessPartner records link users to client workspaces and carry role context. Final role enforcement, session invalidation, and authorization validation must be completed before live client onboarding.
Okta connectionEach client connects an Okta API Services app for assessment evidence. When a client has an Okta Preview org, connect and scan it before production to validate setup, findings, framework mappings, and report handoff. Okta Identity Engine orgs only; no auto-remediation path.
UpdatesRule and collector changes are reviewed, tested, bundled, signed, and released deliberately. Atomation does not claim an automated release-note watcher changes production rules.
Optional workspace identitySSO and SCIM can be configured for the partner team's access to the portal after the base account is active.

Onboarding Flow

  1. Atomation creates the partner record with business, billing, and technical contacts.
  2. The technical contact receives a welcome email with a one-time setup link.
  3. The technical contact creates a login, enrolls MFA, and completes the first full login.
  4. The partner account moves from pending to active after setup is complete.
  5. Atomation walks through the partner portal, client workspace creation, access model, and first workspace setup.
  6. The partner adds or requests the first client workspace slug.
  7. The client connects an Okta API Services app in its own workspace, starting with an available .oktapreview.com org before production.
  8. Atomation verifies the connection, runs the first scan, and reviews the findings with the partner and approved client contacts.
  9. Optional SSO and SCIM are configured for the partner team after the core account and first workspace are stable.

Preview orgs in partner-managed client workspaces

A Preview org is a separate connected org and counts toward the client workspace's org allowance. Preview testing is included in delivery planning rather than treated as unlimited extra capacity.

One retained Preview scan and report

Each .oktapreview.com org retains only its most recent completed scan and generated report. A partner or approved client user may rescan, but the newly completed scan and report replace the previously retained Preview result. Download each PDF or Markdown report before rescanning when the client needs an earlier record.

Data Protection

Atomation is a hosted service, and we're honest about what that means. Assessment evidence is minimized to the identifiers needed for findings, while workspace identity profiles managed through SSO or SCIM are a separate surface. Customer-facing requests carry workspace and role context. Control-plane connector private keys and supported stored connector secrets use AES-256-GCM encryption at rest. Selected application actions are audited. This guide does not claim that every internal query, every operator access path, or the full partner authorization model has completed independent verification. Atomation is working toward SOC 2.

Production backups are maintained operationally, but this public guide does not promise a fixed customer backup-retention window or claim restore testing that has not been evidenced for the engagement. Retention, deletion, recovery, and support commitments belong in the written partner agreement. Runtime scans request only the approved assessment reads, so a workspace can run another on-demand assessment without remediating the Okta org.

Hard Product Boundaries

  • The permanent connector has 31 assessment read grants plus okta.appGrants.manage, an org-level management scope Atomation excludes from scans and reserves for a future reviewed workflow targeting the configured connector app.
  • No auto-remediation or customer-tenant write-back.
  • No third-party data egress for raw identity evidence.
  • Current finding and report paths are deterministic and do not send customer identity data to an AI model.
  • Reports are point-in-time PDF or Markdown artifacts generated from captured assessment evidence.
  • Preview orgs count toward connected-org allowances and retain only the most recent completed scan and generated report.
  • Partner records link users to approved client workspaces; final authorization validation is required before live client onboarding.
  • Remediation services and customer-specific support commitments must be separately scoped in writing.

Next Steps

For a partner conversation, bring the target customer profile, expected client workspace count, Okta org count, desired manual follow-up, report audience, billing contact, technical contact, and whether the partner expects to provide remediation services after the report.

Start at Contact Atomation and include that you want to discuss the hosted partner program.