Skip to content
Atomation
Platform
OverviewDashboard, finding queue, evidence, and reports.Product modelConnection, snapshot, finding, and report output.Evidence & reportsSource trails, screenshots, exports, and report views.
Trust & coverage
What we checkRepresentative checks plus assessment trust model.Feature postureWhich Okta features are on, off, and worth enabling.Security modelRead-only scans, exact connector grants, no remediation.DeploymentHosted Atomation workspace model, partner portals, and assessment boundaries.
See it liveOkta Assessment demoWalk a real finding queue, evidence drawers, and reports — no signup, open demo.Explore the live demo
SolutionsDocsPartnersPricingLive demoDemoContact usContact
Product
Product overview
PlatformOverviewProduct modelEvidence & reports
Trust & coverageWhat we checkFeature postureSecurity modelDeployment
SolutionsDocsPartnersPricingLive demoContact usCall 727-999-1813
Security and privacy

The assessment boundary should be obvious before connection.

Atomation is built around disclosed access boundaries, tenant-bound request context, deterministic findings, point-in-time report output, and controlled summary generation.

31-read scan runtimeNo auto-remediationTenant-bound request contextScoped reports
Atomation posture — Okta security posture by category with snapshot inventory
Trust principles

Security claims stay specific and reviewable.

The page should make the access boundary, evidence boundary, and report boundary clear before a customer connects Okta.

Principle 01

Disclosed connector access

A temporary Super Admin SSWS token inherits full privileges while active, configures the permanent app with Super Administrator and the approved 32 grants, and must be revoked before setup succeeds. Routine scan tokens request only the 31 reads and do not auto-remediate.

Applies to assessment setup, point-in-time data processing, finding output, and report delivery.

Principle 02

Deterministic findings

Findings are produced by versioned checks against captured point-in-time evidence. Current report paths are deterministic; narrative context never determines whether a finding exists.

Applies to assessment setup, point-in-time data processing, finding output, and report delivery.

Principle 03

No third-party AI data egress

Current finding and report paths are deterministic and do not require an external AI service. Customer identity data is not sent to third-party AI services for report generation.

Applies to assessment setup, point-in-time data processing, finding output, and report delivery.

Principle 04

Tenant-bound application access

Portal requests carry workspace and role context, and customer-facing routes are intended to remain tenant-bound. This claim does not imply a completed independent isolation audit or that every internal query has been separately proven.

Applies to assessment setup, point-in-time data processing, finding output, and report delivery.

Principle 05

Careful compliance claims

Security controls are being designed with third-party assurance expectations in mind, but Atomation does not claim certifications, authorizations, endorsements, or partner statuses it does not hold.

Applies to assessment setup, point-in-time data processing, finding output, and report delivery.

Access model

Assessment access does not mean write-back.

Remediation is a separate approved service path with separate scope and controls.

01

Okta connection

Okta API Services app configured for assessment evidence and connector grant maintenance.

02

Org changes

Setup configures the Atomation connector app; runtime scans do not change users, groups, policies, apps, or settings.

03

Finding logic

Deterministic checks decide findings; summaries explain output.

04

Report artifacts

Reports are generated from a point-in-time assessment record. The current portal exports PDF and Markdown reports; supported inventory views export CSV.

How the connection works

Hardened by construction, not by promise.

The Okta connection is the entire attack surface of an assessment tool, so ours is deliberately narrow and independently checkable from your own Okta admin console.

01

App type

Okta API Services app using OAuth 2.0 client credentials — no user login flow, no browser extension, no agent in your environment.

02

Client authentication

private_key_jwt with an asymmetric key pair. No shared client secret exists to leak or rotate.

03

Token binding

DPoP (demonstrating proof of possession) is enabled by default, so access tokens are sender-constrained and resistant to token theft and replay.

04

Admin role

Current guided setup assigns Super Administrator to the permanent service app for complete assessment visibility. Okta evaluates both requested scopes and the assigned admin role.

05

Scopes

Routine scan tokens request 31 assessment read scopes. The app also holds okta.appGrants.manage, an org-level grant-management scope that Atomation excludes from scans and reserves for a future reviewed workflow targeting the configured connector app.

06

Self-audit

The engine audits its own service app on every scan and raises a finding if the connection drifts beyond the approved assessment and connector-maintenance grant list.

Data handling

What we store — and what we never touch.

Atomation is hosted. Customer-facing requests carry workspace and role context, but this page does not claim that every internal query or every operator access path has completed independent isolation testing. Traffic uses TLS; stored connector private keys and supported connector secrets use AES-256-GCM encryption at rest.

What we store

Configuration assessment data

Point-in-time captures of observed Okta configuration such as policies, apps, groups, zones, and authenticators. Atomation does not claim cryptographic immutability.

Assessment identifiers

Assessment evidence uses login, email, and Okta ID where a finding needs an account reference. Portal SSO and SCIM profiles are a separate workspace identity surface and can contain profile attributes.

Findings and reports

Rule results with evidence references and point-in-time PDF or Markdown report output. The portal does not publish an enforced automatic-retention tier today.

Encrypted connector secrets

Control-plane connector private keys and supported stored connector secrets use AES-256-GCM encryption at rest. The temporary setup token is not stored as the connector credential.

What we never touch

Okta tenant passwords or MFA secrets

The assessment scopes cannot read Okta user passwords or MFA secrets, and the assessment scanner does not collect them.

Unneeded assessment profile fields

Assessment collection is PII-minimized to the identifiers needed for evidence. This is distinct from workspace identity profiles provisioned through SSO or SCIM.

Third-party AI report generation

Current finding and report paths are deterministic and do not send customer identity data to an external AI service, model API, or browser extension.

Standing remediation access

The connector is not an auto-remediation path. Remediation is a separately scoped consulting engagement performed by you or with you, never by standing automation.

Your data is yours

Export the supported report and inventory formats.

The active portal exports assessment reports as PDF or Markdown and offers CSV export on supported inventory views. It does not expose DOCX, raw JSON, or raw snapshot downloads. Cancelled workspaces enter a 30-day suspended offboarding period by default and are then permanently purged, with an authorized immediate-purge option. See the publicData Retention and Deletion Policy for the verified lifecycle, backup boundary, and exceptions; a signed agreement may add customer-specific terms.

A deterministic, versioned engine

Findings are produced by versioned, code-based rules — each result cites the exact Okta object it observed. Rule and collector changes are reviewed, tested, bundled, signed, and released deliberately. Atomation does not claim that a release-note watcher automatically changes production rules.

Compliance claim discipline

Atomation helps assess identity controls. It does not claim certifications, authorizations, or hosting statuses it does not hold — and we'd rather show you the boundary than sell you an acronym.

Reporting a security concern

Found something that worries you — on this site, in the product, or in how we handle data? Email [email protected] and it goes straight to the founder. Good-faith reports get a fast, human response.

Get started

Review the security model before connecting Okta.

Request a scoped Okta assessment. We'll align the baseline around your org count, reporting needs, evidence requirements, and delivery model.

Request an Okta assessmentCall 727-999-1813
Atomation

Okta posture and evidence without changing your tenant. Find access risk and evidence gaps before audit week.

Veteran owned — securing Okta orgsBuilt for Okta Identity Engine
[email protected]727-999-1813
ProductOverviewHow it worksPricingLive demo
ResourcesDocumentationFrameworksSecurity & privacyBlogOkta setupFAQ
CompanySolutionsPartnersAboutContact
LegalPrivacyTermsData retentionSubprocessorsAccessibility
© 2026 Atomation LLC · atomation.io
LinkedInInstagramFacebook