okta.users.readEnumerate the user directory for app rostersokta.apps.readList assigned and unassigned applicationsokta.groups.readResolve group-mediated app assignmentsokta.logs.readStream system log events into the platformokta.policies.readIdentify authentication and assurance policies
Okta
OAuth-based read of your workforce directory and connected applications.
WHAT IT DOES
What ScopeMantle can do with Okta.
- Inventory every assigned application across all Okta groups and individual assignments
- Pull per-app user rosters with role, profile, and last-active context from the directory
- Stream system log events into the ScopeMantle normalized event schema in near real time
- Surface admin role assignments, federated identity providers, and authentication policies
- Trigger deprovisioning checklists when an Okta user is suspended or deactivated
LEAST PRIVILEGE
What we read, and what we don't.
- Modify user profiles, group memberships, or assignments unless you explicitly enable a write policy
- Reset or change credentials, MFA factors, or session tokens
- Initiate authentication on behalf of users or impersonate identities
- Reach into downstream applications via Okta, we connect to those directly through their own APIs
SETUP
Connect in a few steps.
- 01
Create a ScopeMantle OAuth service application in Okta
From your Okta admin console, create a new API services integration scoped to the read-only permissions listed above. Issue a private key and note the client ID.
- 02
Authorize ScopeMantle as a tenant admin
In ScopeMantle, choose Connect → Okta and paste the client ID and key. We exchange a JWT-bearer assertion for a short-lived access token; refresh tokens are sealed with AES-GCM at rest.
- 03
Run the first inventory sync
First sync typically completes in under 15 minutes for tenants up to 10,000 users. Subsequent syncs run incrementally on the system log event stream.
- 04
Wire system log delivery (optional)
Enable the system log event stream destination to feed governance events into ScopeMantle in real time. Webhook delivery is HMAC-signed end to end.
Find the Context.ai in your org before the attacker does.
15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.
Book a demo to see the inventory on your own tenant.