Inside the Okta Assessment product model.
Atomation's scanner requests only assessment reads, captures the Okta state, produces deterministic findings, and packages the evidence into reports and exports. One disclosed management grant is excluded from scans and reserved under Atomation policy for a future reviewed workflow targeting the configured connector app.

Four stages. Each stage creates reviewable output.
Configure the exact 31-read plus connector-maintenance grant boundary, org, report audience, and Atomation-hosted workspace.
Users, groups, apps, policies, admins, tokens, service apps, log-stream configuration, and supplied review context.
Versioned checks produce findings. Narrative summaries explain; they do not decide findings.
Dashboard, finding queue, evidence drawer, reports, exports, and service handoff context.
The queue is the product center of gravity.
The dashboard gets attention, but the real value is the reviewable finding record: source evidence, affected scope, owner context, and the next step.


One assessment record, multiple review views.
Separate production behavior from planned monitoring.
On-demand scans
No public automatic-deletion or tier-retention guarantee; any retention or deletion commitment must be written into the engagement Assessment reports in PDF and Markdown, plus CSV on supported inventory viewsOn-demand scans
Download PDF or Markdown reports before rescanning when you need to preserve earlier Preview results Each Preview org counts toward the workspace's connected-org allowance, including partner-managed client workspacesScheduling is not live in production
Enforced plan-based retention tiers are planned, not currently guaranteed by the portal Current export formats remain PDF and Markdown reports plus supported inventory CSV viewsThe workspace boundary is part of the product decision.
Atomation hosts the portal, control plane, scans, reports, backups, releases, and operations. Control-plane connector private keys and supported stored connector secrets use AES-256-GCM encryption at rest.
Disclosed connector accessApproved pilot partners get a hosted portal at {partner-slug}.atomation.io. Partner records link users to customer workspaces; final authorization hardening and validation must finish before live client onboarding.
Deterministic findingsEach client gets a tenant-addressed hosted workspace at {client-slug}.atomation.io with its own connected Okta orgs, scans, findings, reports, and selected application audit events. The public product does not promise an enforced retention tier.
No third-party AI data egressCurrent setup assigns Super Administrator to the permanent API Services app and grants 31 assessment reads plus okta.appGrants.manage. Routine scan tokens request only the reads. Okta's management scope is org-level, not self-only; Atomation reserves it for a future reviewed workflow targeting the configured connector app.
Tenant-bound application accessEvaluate the product by the output it creates.
The assessment should make the finding, evidence, report, and next step easier to review.