Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

All integrations
OK
IDENTITY·GA

Okta

OAuth-based read of your workforce directory and connected applications.

WHAT IT DOES

What ScopeMantle can do with Okta.

  • Inventory every assigned application across all Okta groups and individual assignments
  • Pull per-app user rosters with role, profile, and last-active context from the directory
  • Stream system log events into the ScopeMantle normalized event schema in near real time
  • Surface admin role assignments, federated identity providers, and authentication policies
  • Trigger deprovisioning checklists when an Okta user is suspended or deactivated

LEAST PRIVILEGE

What we read, and what we don't.

We read
  • okta.users.readEnumerate the user directory for app rosters
  • okta.apps.readList assigned and unassigned applications
  • okta.groups.readResolve group-mediated app assignments
  • okta.logs.readStream system log events into the platform
  • okta.policies.readIdentify authentication and assurance policies
We never
  • Modify user profiles, group memberships, or assignments unless you explicitly enable a write policy
  • Reset or change credentials, MFA factors, or session tokens
  • Initiate authentication on behalf of users or impersonate identities
  • Reach into downstream applications via Okta, we connect to those directly through their own APIs

SETUP

Connect in a few steps.

  1. 01

    Create a ScopeMantle OAuth service application in Okta

    From your Okta admin console, create a new API services integration scoped to the read-only permissions listed above. Issue a private key and note the client ID.

  2. 02

    Authorize ScopeMantle as a tenant admin

    In ScopeMantle, choose Connect → Okta and paste the client ID and key. We exchange a JWT-bearer assertion for a short-lived access token; refresh tokens are sealed with AES-GCM at rest.

  3. 03

    Run the first inventory sync

    First sync typically completes in under 15 minutes for tenants up to 10,000 users. Subsequent syncs run incrementally on the system log event stream.

  4. 04

    Wire system log delivery (optional)

    Enable the system log event stream destination to feed governance events into ScopeMantle in real time. Webhook delivery is HMAC-signed end to end.

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.