New Lens + Assist · checks on the card, and help to fix them →

Independent assurance for Okta Workflows

Know exactly what your identity automation does.

Assay reads your Okta Workflows export and writes the whole estate down: every flow as plain logic, the architecture it forms, and a grade against 51 controls, signed so an auditor can check it.

  • No account
  • No access to your Okta
  • Export not kept
Architecture of a sample Okta Workflows estate, derived by Assay An API endpoint starts 1. SSO App Create, which writes App Create Table and calls 2a. SAML Create App and 2b. OIDC Create App. Those call Attribute Processing, Group Assignment, Policy Assignment and Comms, which reach ServiceNow, Okta and Gmail. Numbered markers travel each call in the order it runs. STARTS IT ENTRY CALLS CALLS REACHES · STORES API endpointwhat starts it 1. SSO App Create15 cards 2a. SAML Create App69 cards 2b. OIDC Create App60 cards 2a1. Attribute Processing7 cards 3. Group Assignment43 cards 4. Policy Assignment16 cards 5. Comms21 cards ServiceNowreaches Oktareaches Gmailreaches App Create Tablestores Request arrives1 Call · SAML Create App3 Call · Attribute Processing4 Call · Group Assignment5 Call · Policy Assignment8 Call · Comms10 Assign group to app6 Update task7 Update row9 Send email11 Create row2
Nobody drew this. Derived from a sample export, numbered in the order it runs.Draw yours →
No access to your OktaYou give us an export, not a login
Not kept unless you askProcessed in memory, then discarded
Signed evidenceCheckable offline, without us
IndependentNo Okta ties, no fixes to sell

Assay Lens + Assist · in the Okta Workflows designer

Build it right the first time.

Lens is a read-only Chrome extension for the people who build flows. Open a flow in Okta Workflows and Lens marks the cards that have a problem; Assist shows how to fix it, reviews the change and helps design the next flow — before any of it reaches production.

Lenssees the problem
  1. On the card. Badges on every card with a finding; click one for the problem, what it leads to, and the fix.
Assisthelps you build it right
  1. Fix guide. The worst place the flow can fail, what that leaves half-done, and the cards that make it safe — with how Okta’s own templates do it.
  2. Change review. What your edit changed, which findings it adds or fixes, and a sign-off by someone else before it goes live.
  3. Design help. Describe a process in a sentence; get the trigger, the flows and every card in order, error handling included.
  4. Explain & ask. Any flow in plain sentences, and a guide to every card. Connect your own AI model for written answers — optional, never required.

Assist works in the designer through Lens, and in your Assay workspace for teams who review exports.

  • Read-only — never writes to Okta
  • Checks run on your Assay server
  • A key per browser

Real Lens output on an Okta catalogue template (Google Workspace offboarding), shown on an illustrative canvas.

Assay Lens on a workflow canvas: badges on the cards with findings, and the Lens side panel with the flow's grade and findings
How an Okta catalogue template uses If Error around Deactivate User, recording the failure in a table
How Okta’s own templates do it

What you get

Your automation, written down at last.

Every flow, written down

Each flow read back as plain logic, including the loop and error-handler bodies your console shows as a single card.

560 listed → 867 assessed

How it all connects

The call graph, the derived architecture, and every flow nothing can start, so you change a helper knowing what runs through it.

derived, never drawn

A grade you can trace

A to E, set by counting open findings rather than averaging. Every result points to a fact in your file.

51 controls · 7 dimensions

Right while it is built

Lens puts the checks on the cards in the Workflows designer; Assist guides the fix, reviews the change and helps design the next flow.

Lens · Assist

What ran, and what changed

Stream Okta’s execution log to see whether a flagged call failed, and keep versions to see what changed and when.

runtime · history

Independence

Independent, and provable.

A goldsmith cannot certify their own gold.

An assay office strikes a hallmark that carries weight because the seller did not issue it. Assay has no commercial relationship with Okta and does not sell the fixes for what it finds.

It also says what it cannot tell you. The export has no owner field and no last-run date, so those controls are reported as not assessed, never passed.

C
71 / 100
Needs work
signed ed25519
4f9c 8b21

Checkable without us.

Each report is signed over its conclusions. Change a finding and the signature fails. Anyone with our public key can verify it offline.

Pricing

Start free. Pay when you need the evidence.

Explore
Free

Your architecture and your grade

Draw your estate in about a minute, with no account, and ask for your A to E grade.

Draw your estate
Assessment
$2,500 one-off, from

The full findings, signed

Every control result and finding, the improvement register and a signed report.

Book an assessment
Workspace
$6,000 per year, from

Hosted, and kept current

Re-assess anytime, history, runtime evidence, sign-in with your Okta, quarterly signed reports.

Start a workspace

Priced by the workflows your console lists, never by what Assay finds. How pricing works →

Start with the export you already have.

Draw your architecture free, or use every screen in the live demo first.

Okta Workflows today · SailPoint, Saviynt and Microsoft Entra ID next