Skip to content
Atomation
Platform
OverviewDashboard, finding queue, evidence, and reports.Product modelConnection, snapshot, finding, and report output.Evidence & reportsSource trails, screenshots, exports, and report views.
Trust & coverage
What we checkRepresentative checks plus assessment trust model.Feature postureWhich Okta features are on, off, and worth enabling.Security modelRead-only scans, exact connector grants, no remediation.DeploymentHosted Atomation workspace model, partner portals, and assessment boundaries.
See it liveOkta Assessment demoWalk a real finding queue, evidence drawers, and reports — no signup, open demo.Explore the live demo
SolutionsDocsPartnersPricingLive demoDemoContact usContact
Product
Product overview
PlatformOverviewProduct modelEvidence & reports
Trust & coverageWhat we checkFeature postureSecurity modelDeployment
SolutionsDocsPartnersPricingLive demoContact usCall 727-999-1813
Okta Assessment / Hosted Model

Run Okta assessments in Atomation-hosted workspaces.

Atomation hosts the application, scans, reports, backups, releases, and partner portals. Each client uses a tenant-addressed workspace and connects to Okta with read-scoped runtime access. This page does not claim a separately audited every-query isolation guarantee.

Okta Identity Engine onlyHosted SaaSPartner portalsChild workspaces31-read scan tokens
Atomation dashboard — combined Okta posture, health score, and open findings across orgs
Hosted workspace model

One platform, tenant-addressed workspaces.

01 / Atomation-hosted SaaS

Atomation-hosted SaaS

Atomation hosts the portal, control plane, scans, reports, backups, releases, and operations. Control-plane connector private keys and supported stored connector secrets use AES-256-GCM encryption at rest.

02 / Partner portal

Partner portal

Approved pilot partners get a hosted portal at {partner-slug}.atomation.io. Partner records link users to customer workspaces; final authorization hardening and validation must finish before live client onboarding.

03 / Client workspaces

Client workspaces

Each client gets a tenant-addressed hosted workspace at {client-slug}.atomation.io with its own connected Okta orgs, scans, findings, reports, and selected application audit events. The public product does not promise an enforced retention tier.

04 / Assessment data boundary

Assessment data boundary

Current setup assigns Super Administrator to the permanent API Services app and grants 31 assessment reads plus okta.appGrants.manage. Routine scan tokens request only the reads. Okta's management scope is org-level, not self-only; Atomation reserves it for a future reviewed workflow targeting the configured connector app.

Trust boundary

The hosted boundary applies to assessment data, reports, exports, and partner access.

Atomation is a hosted service. We minimize collected assessment data, bind customer-facing requests to workspace and role context, protect supported stored connector secrets with AES-256-GCM, and record selected application events. We do not claim complete operator-access logging or an independent tenant-isolation audit that has not been completed.

Open security model
Boundary layer

Okta connection

Routine tokens request 31 assessment reads. The permanent app also holds Super Administrator and org-level okta.appGrants.manage, which is excluded from scans.

Boundary-aware output.

Boundary layer

Assessment data

Snapshots, findings, reports, exports.

Boundary-aware output.

Boundary layer

Narrative summaries

Current report paths are deterministic and run inside the Atomation-hosted service.

Boundary-aware output.

Boundary layer

Report artifacts

Point-in-time PDF or Markdown output; supported inventory views also export CSV.

Boundary-aware output.

Atomation reports — auditor-ready assessment report views
Summary boundary

Reports explain findings without changing how findings are decided.

Deterministic checks decide findings. Optional summaries explain the result inside the hosted workspace boundary.

  • Disclosed connector access
  • Deterministic findings
  • No third-party AI data egress
Atomation

Okta posture and evidence without changing your tenant. Find access risk and evidence gaps before audit week.

Veteran owned — securing Okta orgsBuilt for Okta Identity Engine
[email protected]727-999-1813
ProductOverviewHow it worksPricingLive demo
ResourcesDocumentationFrameworksSecurity & privacyBlogOkta setupFAQ
CompanySolutionsPartnersAboutContact
LegalPrivacyTermsData retentionSubprocessorsAccessibility
© 2026 Atomation LLC · atomation.io
LinkedInInstagramFacebook