AtomationDocsFAQ

Atomation Okta Assessment FAQ

Common questions from customer sponsors, IAM owners, and security teams during onboarding and first-scan preparation.

Customer handoffOkta assessmentEvidence ready

Scope

What does Atomation Okta Assessment review?

Atomation reviews Okta posture, evidence, alert coverage, and report context across users, groups, applications, policies, admin roles, service access, and relevant System Log windows.

Which frameworks can a customer select during onboarding?

Customer-selectable framework lenses are HIPAA, SOX ITGC, SOC 2, GLBA/FFIEC, and ISO 27001. Customers can also provide their own controls for scopes that are not listed.

Access

How is assessment access different from SSO and SCIM?

The Okta API Services app is the assessment data connection. SSO and SCIM are optional workspace access controls for customer users signing in to Atomation. They are configured and verified separately.

Who creates the Okta API Services app?

The customer Okta administrator creates the app, grants the approved read scopes, assigns the approved app role, and pastes the Client ID into Atomation for verification.

Evidence

Why are manual answers and uploads needed?

Some controls are not fully visible through Okta APIs. The customer uses the Security Checklist and upload areas for SIEM exports, policies, screenshots, approvals, exceptions, and business-decision notes.

What is a potential risk?

A potential risk is a finding or recommendation that should be reviewed. Some are direct security gaps. Others are business decisions where Atomation can explain the tradeoff and the customer decides whether to remediate, accept, or track.

Reports

What should an accepted business decision include?

Accepted decisions should include a short owner note explaining why the customer accepted the risk or chose a different control. That keeps the final report clear for leadership and audit review.

Support

Where does a customer start?

Start with the welcome email from [email protected], sign in to the customer workspace, then follow the client onboarding guide and the Okta API access guide.