Okta Assessment / Product

Inside the Okta Assessment product model.

Atomation's scanner requests only assessment reads, captures the Okta state, produces deterministic findings, and packages the evidence into reports and exports. One disclosed management grant is excluded from scans and reserved under Atomation policy for a future reviewed workflow targeting the configured connector app.

Okta Identity Engine onlyNo remediation write-backVersioned checksExportable reports
Atomation dashboard — combined Okta posture, health score, and open findings across orgs
Product model

Four stages. Each stage creates reviewable output.

Connect
Read-only assessment runtime

Configure the exact 31-read plus connector-maintenance grant boundary, org, report audience, and Atomation-hosted workspace.

Docs
Capture
Record the identity state

Users, groups, apps, policies, admins, tokens, service apps, log-stream configuration, and supplied review context.

Docs
Detect
Run deterministic checks

Versioned checks produce findings. Narrative summaries explain; they do not decide findings.

Docs
Deliver
Package review output

Dashboard, finding queue, evidence drawer, reports, exports, and service handoff context.

Docs
Finding detail

The queue is the product center of gravity.

The dashboard gets attention, but the real value is the reviewable finding record: source evidence, affected scope, owner context, and the next step.

Atomation findings queue — severity-ranked Okta findings with owners and evidence
Atomation reports — auditor-ready assessment report views
Output objects

One assessment record, multiple review views.

Finding
Finding view

Severity, title, affected objects, owner context, and recommendation.

Guide
Evidence
Evidence view

Source object trail, screenshots, export references, and framework mapping.

Guide
Report
Report view

Executive summary, operator detail, appendix, and remediation-ready notes.

Guide
Current behavior and roadmap

Separate production behavior from planned monitoring.

StatusCadenceHistory, retention, and exports
Production orgs

On-demand scans

No public automatic-deletion or tier-retention guarantee; any retention or deletion commitment must be written into the engagement Assessment reports in PDF and Markdown, plus CSV on supported inventory views
Preview orgs

On-demand scans

Download PDF or Markdown reports before rescanning when you need to preserve earlier Preview results Each Preview org counts toward the workspace's connected-org allowance, including partner-managed client workspaces
Automated monitoring (roadmap)

Scheduling is not live in production

Enforced plan-based retention tiers are planned, not currently guaranteed by the portal Current export formats remain PDF and Markdown reports plus supported inventory CSV views
Hosted model and trust

The workspace boundary is part of the product decision.

Hosted layerWhat it meansTrust principle
Atomation-hosted SaaS

Atomation hosts the portal, control plane, scans, reports, backups, releases, and operations. Control-plane connector private keys and supported stored connector secrets use AES-256-GCM encryption at rest.

Disclosed connector access
Partner portal

Approved pilot partners get a hosted portal at {partner-slug}.atomation.io. Partner records link users to customer workspaces; final authorization hardening and validation must finish before live client onboarding.

Deterministic findings
Client workspaces

Each client gets a tenant-addressed hosted workspace at {client-slug}.atomation.io with its own connected Okta orgs, scans, findings, reports, and selected application audit events. The public product does not promise an enforced retention tier.

No third-party AI data egress
Assessment data boundary

Current setup assigns Super Administrator to the permanent API Services app and grants 31 assessment reads plus okta.appGrants.manage. Routine scan tokens request only the reads. Okta's management scope is org-level, not self-only; Atomation reserves it for a future reviewed workflow targeting the configured connector app.

Tenant-bound application access
Get started

Evaluate the product by the output it creates.

The assessment should make the finding, evidence, report, and next step easier to review.