Deployment

Your Okta data stays in a boundary you control.

Deployment should match the sensitivity of the environment. Atomation can start simple or move the data plane closer to the customer-approved or partner-approved boundary when needed.

Okta Identity Engine only Optional AI summaries Hosted or self-hosted capable
Data models

Three ways to run the assessment.

Atomation-hosted

Fastest path for most customers. Atomation hosts the portal and data plane, with tenant isolation, encrypted credentials, immutable snapshots, and controlled access.

Customer or partner self-hosted

Run the data plane in a Docker-based environment you or a partner controls. This is the right pattern when identity data must remain inside your boundary.

Hybrid control plane and data plane

Keep sensitive snapshot and report processing in your environment while centralizing configuration, update delivery, and operator workflows where appropriate.

AI boundary

The executive summary does not require raw identity data leaving your environment.

Atomation's narrative layer is designed around findings, not raw user exports. The AI provider is pluggable so customers can use a local model, an enterprise-approved model, or a partner-controlled deployment pattern.

What stays controlled
  • Okta snapshots and findings remain in the selected deployment boundary.
  • AI receives a controlled findings summary, not raw identity data.
  • Reports are frozen artifacts so exports remain consistent over time.
Get started

Need the Okta assessment to run inside a specific boundary?

Book a free discovery call. We'll map your workflow, find the highest-value automation, and show you the smallest useful first build — no obligation.