Okta Assessment

The flagship page for Okta posture, evidence, and follow-through.

One read-only assessment record becomes a dashboard, finding queue, evidence package, report, supported export, and delivery plan.

Okta Identity Engine31-read scan runtimeDeterministic findingsExportable reports
Atomation dashboard — combined Okta posture, health score, and open findings across orgs
AssessmentUsers, groups, apps, policies, admins, log-stream configuration, and service access.
FindingsSeverity, affected scope, evidence trail, and recommended review.
ReportsExecutive, operator, framework, export, and handoff-ready views.
OptionsBaseline, manual follow-up review, or remediation support.
Product shape

A review console instead of a brochure grid.

The platform story is organized around the work teams actually do: review the queue, open the evidence, route the owner, and export the report.

Capture
Capture the Okta state

Users, groups, apps, policies, admins, log-stream configuration, service access, and supplied context.

Product
Explain
Package the finding

Severity, affected objects, source evidence, screenshot, and recommendation.

Evidence
Route
Move into review

Executive summary, operator detail, framework language, exports, and handoff notes.

Reports
Atomation findings queue — severity-ranked findings with evidence across connected Okta orgs
Coverage

Representative checks, grouped for scanning.

Public pages show the review shape without publishing the full detection playbook.

AreaWhat it answersExample signals
Administrators and privileged access

Privileged access is where small Okta mistakes become major exposure.

Super Admin exposure, Admin role drift, Powerful service-app access
Access model and lifecycle posture

Review stale access, group sprawl, and sensitive app assignments.

Stale access signals, Group and assignment sprawl, Sensitive app access review
Authentication and policy posture

Check policy coverage, MFA posture, exceptions, and assurance levels.

Policy coverage gaps, Exception and overlap review, Admin and high-value app assurance
API tokens, service apps, and integrations

Non-human access, integration access, and service credentials are reviewed for ownership, privilege, and hygiene.

Ownership and privilege review, Stale or concentrated access, Integration hygiene
Alerting, evidence, and compliance support

Review log-stream configuration and customer-supplied monitoring evidence without claiming raw System Log collection.

Log-stream configuration, Customer-supplied alert evidence, Framework and control mapping
Licensing and utilization signals

Surface renewal and cost questions tied to observed usage.

Utilization patterns, Stale entitlement signals, Renewal planning context
Atomation reports — auditor-ready assessment report views
Evidence path

Screenshots, objects, findings, and reports stay connected.

The assessment does not make teams reassemble raw exports. Evidence is packaged around the finding and reused in reports, framework mapping, and the supported export formats.

Open evidence page
Service models

Choose a service path without losing the evidence trail.

Start with the smallest useful review and expand only when cadence or support justifies it.

Atomation posture — Okta security posture by category with snapshot inventory
Point-in-time
Baseline Health Check

A focused Okta assessment for audit prep, diligence, renewal planning, implementation handoff, incident review, or a leadership update.

Compare
Roadmap
Automated Monitoring

Planned scheduled re-scans, drift comparison, and trend reporting. These capabilities are not part of the current production portal and should not be sold as live.

Compare
Services
Remediation Support

Scoped follow-up help for teams that want Atomation-supported review, prioritization, and resolution planning after the first report.

Compare
Frameworks and boundary

Same evidence, different review lenses.

Findings can be organized around framework language, the hosted workspace boundary, written data-handling terms, and customer-approved routing.

HIPAASOX ITGCSOC 2GLBA / FFIECISO 27001PCI DSSCIS Controls v8NIST 800-53
Hosted layerWhat it doesBoundary
Atomation-hosted SaaS

Atomation hosts the portal, control plane, scans, reports, backups, releases, and operations. Control-plane connector private keys and supported stored connector secrets use AES-256-GCM encryption at rest.

Atomation-hosted
Partner portal

Approved pilot partners get a hosted portal at {partner-slug}.atomation.io. Partner records link users to customer workspaces; final authorization hardening and validation must finish before live client onboarding.

Atomation-hosted
Client workspaces

Each client gets a tenant-addressed hosted workspace at {client-slug}.atomation.io with its own connected Okta orgs, scans, findings, reports, and selected application audit events. The public product does not promise an enforced retention tier.

Atomation-hosted
Assessment data boundary

Current setup assigns Super Administrator to the permanent API Services app and grants 31 assessment reads plus okta.appGrants.manage. Routine scan tokens request only the reads. Okta's management scope is org-level, not self-only; Atomation reserves it for a future reviewed workflow targeting the configured connector app.

Atomation-hosted
Get started

Use this page as the product story. Keep docs for technical detail.

The older technical setup, framework, report, and security pages stay available under Resources for buyers and operators who need them.