How it works
You send a file. You get your estate written down.
Assay reads the file Okta gives you. It never connects to your tenant and never asks for credentials — there is nothing to grant, nothing to revoke. Okta Workflows today; the same method applies to other identity platforms as we build them.
Export a folder
In the Okta Workflows console, open a folder and choose Actions → Export. You get a
.folder file. Okta strips every connection credential during export, so the file
contains structure and no secrets.
We read it
We parse the export and walk the whole estate, including the flows embedded inside loop bodies and error handlers. You get the full inventory, every flow as readable code, the call graph and a robustness score.
You keep the evidence
When you need evidence rather than a reading, we issue a dated, hashed signed report with the improvement register, and re-attest on a schedule so drift is measured rather than discovered.
What Assay does with the file
Four passes over the export, each producing part of the deliverable.
Discovery
The supplied evidence is normalized into a common identity-automation model: objects, relationships, execution paths, controls and supporting metadata. In Okta this includes recursive flow discovery; other adapters apply the same principle to their native configuration structures.
Structure
Platform-specific objects are mapped to the common model so the engine can follow relationships without pretending different products work the same way.
Controls
Each control runs against that model deterministically. Where an evidence source cannot answer a control, the result is marked not assessed rather than guessed.
Evidence & rendering
The same model produces the control results, plain-language findings, diagrams, operation traces and score — so the narrative remains tied to evidence.
What you get back
The exact sections vary by platform, but what you get back is the same shape every time: inventory, evidence, controls, risk, improvement and methodology. Versioned output makes successive reviews comparable.
Executive summary
Estate size declared and actual, the control pass rate, and the three findings that matter most.
Estate inventory
Every relevant object, relationship and automation path surfaced by the platform adapter.
Relationship map
Dependencies, entry points, privileged paths and objects referenced by nothing else where the source exposes them.
Operation traces
Each business operation followed end to end, as a sequence diagram and as readable code.
Control results
Every control with its result, the evidence behind it, and a plain statement of what it checks.
Robustness score
Six weighted dimensions, each traced to a specific fact rather than a judgement call.
Improvement register
Prioritised items with effort estimates and the result of acting on each one.
Methodology
What was assessed, what could not be, and the SHA-256 of the exact file you supplied.
Start with Okta. Build toward the whole identity estate.
The free reading takes thirty seconds for Okta Workflows today. Tell us which identity platforms matter next for your environment.
