Okta setup overview
Start here to choose API access, SAML SSO, SCIM provisioning, or role-mapping docs.
The setup guides are written for whoever is doing the setup — not just identity specialists. Everything else (product, evidence, reports, security) has its own section below.
Written for whoever is doing the setup — no identity background needed. Connect your first org and run the first scan.
Start here to choose API access, SAML SSO, SCIM provisioning, or role-mapping docs.
The Okta Admin Console steps for the assessment connector — values to paste, scopes to grant, and how to verify.
Set up SAML 2.0 sign-in for the primary workspace identity org.
Configure user lifecycle, group provisioning, and group-to-role linking.
What each Atomation role can do, and how Okta groups map to them.
Hosted pilot partner portal onboarding, tenant-addressed client workspaces, pricing scope drivers, customer approval boundaries, and the remaining authorization-validation gate.
Understand the assessment before any Okta connection is made.
What Atomation assesses, who the reports are for, and how the first baseline becomes a reviewable product output.
How the first assessment is scoped, connected, scanned, and turned into reports.
Customer handoff packet for first login, org profile, framework selection, automated API setup, org SSO metadata when needed, manual evidence, and first-scan readiness.
Representative Okta coverage areas across access, policy, service credentials, alerts, evidence, and licensing.
Common questions on assessment scope, data handling, deterministic findings, retention, and reports.
See how findings, screenshots, exports, and framework mappings are packaged.
A buyer-facing view of evidence automation, report artifacts, screenshots, and example findings.
Report structure, export formats, summary versus operator detail, and evidence appendix behavior.
Representative screenshots and examples for group-rule dependencies, finding cards, control mapping, and licensing signals.
Customer-supplied System Log and SIEM evidence, alert routing, owners, and monitoring gaps; no raw System Log collection by the assessment connector.
Observed usage signals, cleanup candidates, customer agreement context, and renewal-planning questions.
HIPAA, SOX ITGC, SOC 2, GLBA/FFIEC, ISO 27001, PCI DSS, CIS Controls v8, NIST 800-53, and customer-provided control mapping.
The 8 standards that ask for Okta evidence and the security best practices auditors actually check.
Choose the right data boundary and understand the security model.
Hosted Atomation workspaces, partner portals, tenant-addressed client workspaces, and bounded Okta assessment-access claims.
Assessment access limited to evidence collection, deterministic findings, tenant-bound request context, and exact stored-connector-secret encryption wording.
Current history and export behavior, contractual retention boundaries, and roadmap-only monitoring features.