Resources

Docs, guides, and proof in one organized hub.

Technical setup, report guides, framework lenses, partner material, FAQ, and company references stay available here while the marketing story stays focused.

Atomation reports — auditor-ready assessment report views
Start by task

Buyers, operators, auditors, and partners need different doors.

Technical docs

Setup and product docs stay live.

The consolidation removes repeated marketing routes, not technical detail.

Doc
Okta setup overview

Start here to choose API access, SAML SSO, SCIM provisioning, or role-mapping docs.

Open
Doc
Okta API access

The Okta Admin Console steps for the assessment connector — values to paste, scopes to grant, and how to verify.

Open
Doc
Okta SSO setup

Set up SAML 2.0 sign-in for the primary workspace identity org.

Open
Doc
SCIM provisioning setup

Configure user lifecycle, group provisioning, and group-to-role linking.

Open
Doc
Roles and permissions

What each Atomation role can do, and how Okta groups map to them.

Open
Doc
Partner program and delivery

Hosted pilot partner portal onboarding, tenant-addressed client workspaces, pricing scope drivers, customer approval boundaries, and the remaining authorization-validation gate.

Open
Doc
Okta Assessment overview

What Atomation assesses, who the reports are for, and how the first baseline becomes a reviewable product output.

Open
Doc
Getting started

How the first assessment is scoped, connected, scanned, and turned into reports.

Open
Doc
Client onboarding

Customer handoff packet for first login, org profile, framework selection, automated API setup, org SSO metadata when needed, manual evidence, and first-scan readiness.

Open
Doc
What we check

Representative Okta coverage areas across access, policy, service credentials, alerts, evidence, and licensing.

Open
Doc
FAQ

Common questions on assessment scope, data handling, deterministic findings, retention, and reports.

Open
Doc
Automated evidence

A buyer-facing view of evidence automation, report artifacts, screenshots, and example findings.

Open
Doc
Reading reports

Report structure, export formats, summary versus operator detail, and evidence appendix behavior.

Open
Doc
Evidence and finding examples

Representative screenshots and examples for group-rule dependencies, finding cards, control mapping, and licensing signals.

Open
Doc
Alert coverage review

Customer-supplied System Log and SIEM evidence, alert routing, owners, and monitoring gaps; no raw System Log collection by the assessment connector.

Open
Doc
Licensing review

Observed usage signals, cleanup candidates, customer agreement context, and renewal-planning questions.

Open
Doc
Framework lenses

HIPAA, SOX ITGC, SOC 2, GLBA/FFIEC, ISO 27001, PCI DSS, CIS Controls v8, NIST 800-53, and customer-provided control mapping.

Open
Doc
Compliance best practices

The 8 standards that ask for Okta evidence and the security best practices auditors actually check.

Open
Doc
Hosted workspace model

Hosted Atomation workspaces, partner portals, tenant-addressed client workspaces, and bounded Okta assessment-access claims.

Open
Doc
Security model

Assessment access limited to evidence collection, deterministic findings, tenant-bound request context, and exact stored-connector-secret encryption wording.

Open
Doc
Plans, retention, and scope

Current history and export behavior, contractual retention boundaries, and roadmap-only monitoring features.

Open
Framework lenses

Control language stays organized by framework.

FrameworkReview contextPage
HIPAA

For healthcare and healthcare-adjacent teams that need practical identity evidence around access control, workforce access, activity review, and secure operations.

Open framework page
SOX ITGC

For finance, SaaS, and public-company teams that need stronger evidence around access governance, privileged access, change risk, and sensitive business apps.

Open framework page
SOC 2

For SaaS and service organizations that need identity evidence around logical access, privileged access, change control, monitoring, and user lifecycle governance.

Open framework page
GLBA / FFIEC

For financial services and advisory teams that need clear identity evidence for safeguarding customer information and managing privileged access risk.

Open framework page
ISO 27001

For teams that want Okta identity evidence aligned to an information security management system and repeatable access-control review process.

Open framework page
PCI DSS

For merchants, processors, and SaaS teams in PCI scope that need identity evidence around access restriction, unique user identification, MFA, and administrative accountability.

Open framework page
CIS Controls v8

For teams that benchmark against CIS Controls v8 and want Okta evidence organized around account, access, MFA, and log management safeguards.

Open framework page
NIST 800-53

For security programs built on NIST 800-53 that need Okta evidence tied to AC, IA, and AU family controls without reworking raw exports.

Open framework page