Independent assurance for Okta Workflows
Know exactly what your identity automation does.
Assay reads your Okta Workflows export and writes the whole estate down: every flow as plain logic, the architecture it forms, and a grade against 51 controls, signed so an auditor can check it.
- No account
- No access to your Okta
- Export not kept
Assay Lens + Assist · in the Okta Workflows designer
Build it right the first time.
Lens is a read-only Chrome extension for the people who build flows. Open a flow in Okta Workflows and Lens marks the cards that have a problem; Assist shows how to fix it, reviews the change and helps design the next flow — before any of it reaches production.
- On the card. Badges on every card with a finding; click one for the problem, what it leads to, and the fix.
- Fix guide. The worst place the flow can fail, what that leaves half-done, and the cards that make it safe — with how Okta’s own templates do it.
- Change review. What your edit changed, which findings it adds or fixes, and a sign-off by someone else before it goes live.
- Design help. Describe a process in a sentence; get the trigger, the flows and every card in order, error handling included.
- Explain & ask. Any flow in plain sentences, and a guide to every card. Connect your own AI model for written answers — optional, never required.
Assist works in the designer through Lens, and in your Assay workspace for teams who review exports.
- Read-only — never writes to Okta
- Checks run on your Assay server
- A key per browser
Real Lens output on an Okta catalogue template (Google Workspace offboarding), shown on an illustrative canvas.


What you get
Your automation, written down at last.
Every flow, written down
Each flow read back as plain logic, including the loop and error-handler bodies your console shows as a single card.
How it all connects
The call graph, the derived architecture, and every flow nothing can start, so you change a helper knowing what runs through it.
A grade you can trace
A to E, set by counting open findings rather than averaging. Every result points to a fact in your file.
Right while it is built
Lens puts the checks on the cards in the Workflows designer; Assist guides the fix, reviews the change and helps design the next flow.
What ran, and what changed
Stream Okta’s execution log to see whether a flagged call failed, and keep versions to see what changed and when.
Independence
Independent, and provable.
A goldsmith cannot certify their own gold.
An assay office strikes a hallmark that carries weight because the seller did not issue it. Assay has no commercial relationship with Okta and does not sell the fixes for what it finds.
It also says what it cannot tell you. The export has no owner field and no last-run date, so those controls are reported as not assessed, never passed.
4f9c 8b21
Checkable without us.
Each report is signed over its conclusions. Change a finding and the signature fails. Anyone with our public key can verify it offline.
Pricing
Start free. Pay when you need the evidence.
Your architecture and your grade
Draw your estate in about a minute, with no account, and ask for your A to E grade.
Draw your estateThe full findings, signed
Every control result and finding, the improvement register and a signed report.
Book an assessmentHosted, and kept current
Re-assess anytime, history, runtime evidence, sign-in with your Okta, quarterly signed reports.
Start a workspacePriced by the workflows your console lists, never by what Assay finds. How pricing works →
Start with the export you already have.
Draw your architecture free, or use every screen in the live demo first.
Okta Workflows today · SailPoint, Saviynt and Microsoft Entra ID next