Okta docs

Current behavior and roadmap are documented separately.

The production portal supports on-demand scans, point-in-time findings, and current report exports. Automated schedules, drift comparison, trend reporting, and enforced plan-based plan-based retention tiers are roadmap work. Cancelled workspaces now follow the public 30-day suspended offboarding and verified deletion policy; a written order may add narrower customer-specific terms.

Verified behavior

Do not present roadmap limits as production enforcement.

StatusScan cadenceSnapshotsRetentionExports
Production orgsOn-demand scansLatest completed assessment data plus up to 25 recent scan runs shown in the client history viewNo public automatic-deletion or tier-retention guarantee; any retention or deletion commitment must be written into the engagementAssessment reports in PDF and Markdown, plus CSV on supported inventory views
Preview orgsOn-demand scansOnly the most recent completed Preview scan and generated report are retained; a rescan replaces the prior retained resultDownload PDF or Markdown reports before rescanning when you need to preserve earlier Preview resultsEach Preview org counts toward the workspace's connected-org allowance, including partner-managed client workspaces
Automated monitoring (roadmap)Scheduling is not live in productionDrift comparison and trend views are planned, not current product behaviorEnforced plan-based retention tiers are planned, not currently guaranteed by the portalCurrent export formats remain PDF and Markdown reports plus supported inventory CSV views
Adjustable scope

Written scope covers size, data handling, follow-up, and support.

The baseline lifecycle is published in the Data Retention and Deletion Policy. Customer-specific retention, deletion, backup, or support commitments require a written scope.

Common reasons scope changes
  • Number of Okta orgs
  • Okta Production versus Okta Preview environments
  • User, group, app, policy, admin, API token, and log-stream configuration volume
  • Baseline assessment versus manual follow-up reviews
  • Written data-retention or deletion requirements
  • Framework mapping depth
  • Alert and SIEM evidence review
  • Licensing analysis
  • Report package requirements
  • Hosted Atomation workspace, partner portal, child workspaces, or direct customer access

Written terms may add storage, implementation, support, or professional-services cost. The portal does not currently enforce the roadmap plan tiers shown in older product plans.

What does not change

Runtime scans request only the 31 approved assessment read scopes. The permanent connector also holds okta.appGrants.manage, an org-level application-grant management scope that Atomation excludes from scans and reserves for a future reviewed workflow targeting the configured connector app. Atomation does not store customer secrets in exports or automatically remediate the Okta org. Follow-up implementation work is a separate, customer-approved services scope.

Okta Preview orgs are intentionally single-retained

An .oktapreview.com org retains only its most recent completed scan and generated report. When a rescan completes, the new result replaces the previously retained Preview scan and report. Download the PDF or Markdown report before rescanning when you need to keep an earlier record. Each Preview org counts toward the connected-org allowance for direct customers and partner-managed client workspaces.

Get started

Need a scope that does not fit the default limits?

Request a scoped Okta assessment. We'll align the baseline around your org count, reporting needs, evidence requirements, and delivery model.