Questions

Frequently asked questions

If your question is not here, ask us directly — we answer every enquiry ourselves, usually within one working day.

How do we know a report came from Assay and has not been edited?

Each assessment carries a SHA-256 digest of the export that was read, a second digest over the conclusions that were drawn, and an Ed25519 signature over both together with the engine version and the timestamp. The signing key fingerprint is printed on the report.

The signature covers the conclusions rather than the PDF bytes, so re-rendering the document does not break it, but altering a finding, a control result or a score does. Verification runs on your machine against our published public key — you do not need to contact us, and we cannot change the answer after the fact.

If an engine has no signing key configured, its reports state that they are unsigned rather than implying otherwise.

Do you need access to our Okta tenant?

No. You export a folder from the Workflows console and we analyse the file. There is no API token, no OAuth grant and no admin access at any point. Okta strips all connection credentials during export, so the file contains structure but no secrets. If you ask us to connect to your tenant, we will decline.

Why does Assay find more flows than the Okta console shows?

Okta Workflows stores the body of a loop, and the contents of an error handler, as separate flow objects embedded inside the parent flow. They execute in production and can be edited, but they do not appear in the console flow list. Across 125 public Okta template folders, recursive analysis finds 867 flows where the declared list shows 560.

We already manage Okta with Terraform. Doesn't that cover this?

No, for four reasons. Terraform only reports drift on resources it manages — anything created in the console is invisible to it unless imported. The Okta Terraform provider does not model Workflows at all; it covers users, groups, applications and policies, so flows are outside its reach entirely. Even where it does have coverage, it compares attribute values on objects rather than what an automation actually does. And a terraform plan you ran yourself is not independent evidence — it is undated, unsigned and produced by the party being assessed. The two are complementary: teams already running Terraform tend to understand the gap fastest.

What exactly does a free reading give me?

The complete flow inventory, each flow rendered as readable code, a call graph of the estate, a robustness score across five dimensions, and control results with the reasoning behind each. We run it and send the result back. No credentials, no tenant access, and the file is deleted once the reading is delivered.

Does a free reading run the same checks as a paid signed report?

No. A free reading runs a core subset of the control library — enough to give you an accurate picture of your estate, the generated code and a robustness score. A paid signed report runs the full library, including the deeper structural and privilege checks, and adds the end-to-end operation traces, the improvement register and the dated, hashed evidence record. The counts and the code in a free reading are real, not a teaser — there is simply more of it in an engagement.

What is the difference between the free reading and a paid signed report?

The reading is a snapshot for you. The signed report is evidence for someone else: dated, hashed against the exact bytes you supplied, with end-to-end operation traces, a prioritised improvement register, and a stated methodology including what could not be assessed and why.

Is Assay affiliated with Okta?

No. Assay is independent and has no commercial relationship with Okta. Okta and Okta Workflows are trademarks of Okta, Inc., used for identification only. That independence is the point — a platform vendor cannot credibly certify its own configuration.

Do you fix what you find?

No, deliberately. Scoring an estate and then selling the fix for it would compromise the independence the signed report rests on. We refer remediation to implementation partners and re-attest afterwards, so the improvement is measured by someone with no stake in the outcome. Where a referral fee applies, it is disclosed in the signed report.

How long does an engagement take?

A free reading is turned around in one to two working days. A baseline signed report is typically delivered within five working days of receiving the export, faster for smaller estates.

What happens to our export after the engagement?

Files supplied for a paid engagement are held only as long as needed to produce and support the signed report, then deleted. What we retain afterwards is the derived record — control results, counts, scores, the file hash and the date — with folder and connection names redacted. This is set out in full in our privacy policy.

Which controls cannot be answered from an export?

Ownership and dormancy. The format carries no owner field, no enabled-or-disabled marker and no last-run timestamp. We report those controls as not assessed rather than passed. Ownership can be assessed if you supply a register alongside the export.

Does this work for platforms other than Okta?

Today the production analyser is for Okta Workflows. The method is platform-agnostic, with SailPoint, Saviynt and Microsoft Entra ID in the next build sequence and CyberArk, Oracle Identity and IBM Security Identity on the roadmap. Platform availability is phased; ask us about your estate.

Can we run the analysis inside our own environment?

Self-hosted deployment is available for partners who want the analyser inside their own pipeline, under licence. Ask us about it.

How is pricing calculated if our estate grows mid-engagement?

Your band is set at the baseline and holds for the term. If the estate grows into a higher band, the new band applies at renewal rather than mid-term.

Still deciding?

The free reading answers most questions faster than we can. It takes thirty seconds and needs nothing but a file you already have.

Request a reading Ask a question