Current behavior and roadmap are documented separately.
The production portal supports on-demand scans, point-in-time findings, and current report exports. Automated schedules, drift comparison, trend reporting, and enforced plan-based plan-based retention tiers are roadmap work. Cancelled workspaces now follow the public 30-day suspended offboarding and verified deletion policy; a written order may add narrower customer-specific terms.
Do not present roadmap limits as production enforcement.
| Status | Scan cadence | Snapshots | Retention | Exports |
|---|---|---|---|---|
| Production orgs | On-demand scans | Latest completed assessment data plus up to 25 recent scan runs shown in the client history view | No public automatic-deletion or tier-retention guarantee; any retention or deletion commitment must be written into the engagement | Assessment reports in PDF and Markdown, plus CSV on supported inventory views |
| Preview orgs | On-demand scans | Only the most recent completed Preview scan and generated report are retained; a rescan replaces the prior retained result | Download PDF or Markdown reports before rescanning when you need to preserve earlier Preview results | Each Preview org counts toward the workspace's connected-org allowance, including partner-managed client workspaces |
| Automated monitoring (roadmap) | Scheduling is not live in production | Drift comparison and trend views are planned, not current product behavior | Enforced plan-based retention tiers are planned, not currently guaranteed by the portal | Current export formats remain PDF and Markdown reports plus supported inventory CSV views |
Written scope covers size, data handling, follow-up, and support.
The baseline lifecycle is published in the Data Retention and Deletion Policy. Customer-specific retention, deletion, backup, or support commitments require a written scope.
- Number of Okta orgs
- Okta Production versus Okta Preview environments
- User, group, app, policy, admin, API token, and log-stream configuration volume
- Baseline assessment versus manual follow-up reviews
- Written data-retention or deletion requirements
- Framework mapping depth
- Alert and SIEM evidence review
- Licensing analysis
- Report package requirements
- Hosted Atomation workspace, partner portal, child workspaces, or direct customer access
Written terms may add storage, implementation, support, or professional-services cost. The portal does not currently enforce the roadmap plan tiers shown in older product plans.
Runtime scans request only the 31 approved assessment read scopes. The permanent connector also holds okta.appGrants.manage, an org-level application-grant management scope that Atomation excludes from scans and reserves for a future reviewed workflow targeting the configured connector app. Atomation does not store customer secrets in exports or automatically remediate the Okta org. Follow-up implementation work is a separate, customer-approved services scope.
An .oktapreview.com org retains only its most recent completed scan and generated report. When a rescan completes, the new result replaces the previously retained Preview scan and report. Download the PDF or Markdown report before rescanning when you need to keep an earlier record. Each Preview org counts toward the connected-org allowance for direct customers and partner-managed client workspaces.
Need a scope that does not fit the default limits?
Request a scoped Okta assessment. We'll align the baseline around your org count, reporting needs, evidence requirements, and delivery model.