AtomationDocsFAQ

Atomation Okta Assessment FAQ

Common questions from customer sponsors, IAM owners, and security teams during onboarding and first-scan preparation.

Okta assessmentSetup referenceWeb guide

Scope

What does Atomation Okta Assessment review?

Atomation reviews Okta posture and report context across users, groups, applications, policies, admin roles, service access, and log-stream configuration. Alert coverage is a manual review of customer-supplied System Log and SIEM evidence; the assessment connector does not collect raw System Log events.

Which frameworks can a customer select during onboarding?

Customer-selectable framework lenses are HIPAA, SOX ITGC, SOC 2, GLBA/FFIEC, ISO 27001, PCI DSS, CIS Controls v8, and NIST 800-53. Customers can also provide their own controls for scopes that are not listed.

Access

How is assessment access different from SSO and SCIM?

The Okta API Services app is the assessment data connection. SSO and SCIM are optional workspace access controls for customer users signing in to Atomation. They are configured and verified separately.

Who creates the Okta API Services app?

The customer creates a temporary Super Admin SSWS token, which has full Super Administrator privileges while active. Atomation uses it once to create/configure the app, assign Super Administrator to the permanent app, grant 31 reads plus org-level okta.appGrants.manage, verify the exact grants, and confirm revocation before setup succeeds. Routine scans request only the reads; Atomation reserves the management scope for a future reviewed workflow targeting the configured connector app.

Evidence

Why are manual answers needed?

Some controls are not fully visible through Okta APIs. The customer uses the Security Checklist and notes for policies, approvals, exceptions, and business-decision context. The SIEM alert baseline is provided as a handoff PDF instead of an upload workflow.

What is a potential risk?

A potential risk is a finding or recommendation that should be reviewed. Some are direct security gaps. Others are business decisions where Atomation can explain the tradeoff and the customer decides whether to remediate, accept, or track.

Reports

What should an accepted business decision include?

Accepted decisions should include a short owner note explaining why the customer accepted the risk or chose a different control. That keeps the final report clear for leadership and audit review.

Support

Where does a customer start?

Start with the welcome email from [email protected], sign in to the customer workspace, then follow the client onboarding guide and the Okta API access guide.