Atomation Okta Assessment FAQ
Common questions from customer sponsors, IAM owners, and security teams during onboarding and first-scan preparation.
Scope
Atomation reviews Okta posture and report context across users, groups, applications, policies, admin roles, service access, and log-stream configuration. Alert coverage is a manual review of customer-supplied System Log and SIEM evidence; the assessment connector does not collect raw System Log events.
Customer-selectable framework lenses are HIPAA, SOX ITGC, SOC 2, GLBA/FFIEC, ISO 27001, PCI DSS, CIS Controls v8, and NIST 800-53. Customers can also provide their own controls for scopes that are not listed.
Access
The Okta API Services app is the assessment data connection. SSO and SCIM are optional workspace access controls for customer users signing in to Atomation. They are configured and verified separately.
The customer creates a temporary Super Admin SSWS token, which has full Super Administrator privileges while active. Atomation uses it once to create/configure the app, assign Super Administrator to the permanent app, grant 31 reads plus org-level okta.appGrants.manage, verify the exact grants, and confirm revocation before setup succeeds. Routine scans request only the reads; Atomation reserves the management scope for a future reviewed workflow targeting the configured connector app.
Evidence
Some controls are not fully visible through Okta APIs. The customer uses the Security Checklist and notes for policies, approvals, exceptions, and business-decision context. The SIEM alert baseline is provided as a handoff PDF instead of an upload workflow.
A potential risk is a finding or recommendation that should be reviewed. Some are direct security gaps. Others are business decisions where Atomation can explain the tradeoff and the customer decides whether to remediate, accept, or track.
Reports
Accepted decisions should include a short owner note explaining why the customer accepted the risk or chose a different control. That keeps the final report clear for leadership and audit review.
Support
Start with the welcome email from [email protected], sign in to the customer workspace, then follow the client onboarding guide and the Okta API access guide.