Okta connection
Routine tokens request 31 assessment reads. The permanent app also holds Super Administrator and org-level okta.appGrants.manage, which is excluded from scans.
Boundary-aware output.
Atomation hosts the application, scans, reports, backups, releases, and partner portals. Each client uses a tenant-addressed workspace and connects to Okta with read-scoped runtime access. This page does not claim a separately audited every-query isolation guarantee.

Atomation hosts the portal, control plane, scans, reports, backups, releases, and operations. Control-plane connector private keys and supported stored connector secrets use AES-256-GCM encryption at rest.
Approved pilot partners get a hosted portal at {partner-slug}.atomation.io. Partner records link users to customer workspaces; final authorization hardening and validation must finish before live client onboarding.
Each client gets a tenant-addressed hosted workspace at {client-slug}.atomation.io with its own connected Okta orgs, scans, findings, reports, and selected application audit events. The public product does not promise an enforced retention tier.
Current setup assigns Super Administrator to the permanent API Services app and grants 31 assessment reads plus okta.appGrants.manage. Routine scan tokens request only the reads. Okta's management scope is org-level, not self-only; Atomation reserves it for a future reviewed workflow targeting the configured connector app.
Atomation is a hosted service. We minimize collected assessment data, bind customer-facing requests to workspace and role context, protect supported stored connector secrets with AES-256-GCM, and record selected application events. We do not claim complete operator-access logging or an independent tenant-isolation audit that has not been completed.
Open security modelRoutine tokens request 31 assessment reads. The permanent app also holds Super Administrator and org-level okta.appGrants.manage, which is excluded from scans.
Boundary-aware output.
Snapshots, findings, reports, exports.
Boundary-aware output.
Current report paths are deterministic and run inside the Atomation-hosted service.
Boundary-aware output.
Point-in-time PDF or Markdown output; supported inventory views also export CSV.
Boundary-aware output.

Deterministic checks decide findings. Optional summaries explain the result inside the hosted workspace boundary.