How it works

You send a file. You get your estate written down.

Assay reads the file Okta gives you. It never connects to your tenant and never asks for credentials — there is nothing to grant, nothing to revoke. Okta Workflows today; the same method applies to other identity platforms as we build them.

STEP 01

Export a folder

In the Okta Workflows console, open a folder and choose Actions → Export. You get a .folder file. Okta strips every connection credential during export, so the file contains structure and no secrets.

STEP 02

We read it

We parse the export and walk the whole estate, including the flows embedded inside loop bodies and error handlers. You get the full inventory, every flow as readable code, the call graph and a robustness score.

STEP 03

You keep the evidence

When you need evidence rather than a reading, we issue a dated, hashed signed report with the improvement register, and re-attest on a schedule so drift is measured rather than discovered.

Try it on your own export

What Assay does with the file

Four passes over the export, each producing part of the deliverable.

PASS 01

Discovery

The supplied evidence is normalized into a common identity-automation model: objects, relationships, execution paths, controls and supporting metadata. In Okta this includes recursive flow discovery; other adapters apply the same principle to their native configuration structures.

PASS 02

Structure

Platform-specific objects are mapped to the common model so the engine can follow relationships without pretending different products work the same way.

PASS 03

Controls

Each control runs against that model deterministically. Where an evidence source cannot answer a control, the result is marked not assessed rather than guessed.

PASS 04

Evidence & rendering

The same model produces the control results, plain-language findings, diagrams, operation traces and score — so the narrative remains tied to evidence.

What you get back

The exact sections vary by platform, but what you get back is the same shape every time: inventory, evidence, controls, risk, improvement and methodology. Versioned output makes successive reviews comparable.

01

Executive summary

Estate size declared and actual, the control pass rate, and the three findings that matter most.

02

Estate inventory

Every relevant object, relationship and automation path surfaced by the platform adapter.

03

Relationship map

Dependencies, entry points, privileged paths and objects referenced by nothing else where the source exposes them.

04

Operation traces

Each business operation followed end to end, as a sequence diagram and as readable code.

05

Control results

Every control with its result, the evidence behind it, and a plain statement of what it checks.

06

Robustness score

Six weighted dimensions, each traced to a specific fact rather than a judgement call.

07

Improvement register

Prioritised items with effort estimates and the result of acting on each one.

08

Methodology

What was assessed, what could not be, and the SHA-256 of the exact file you supplied.

Start with Okta. Build toward the whole identity estate.

The free reading takes thirty seconds for Okta Workflows today. Tell us which identity platforms matter next for your environment.

Request a reading See pricing