Okta Workflows · configuration assay
Every flow you run, written out in plain logic — the complete estate, including the loop bodies and handlers your console doesn’t list. Scored, dated, and ready to hand to anyone who asks: an auditor, a new engineer, your successor. Drop a folder export and see yours in thirty seconds.
.folder export — Workflows console → open a folder → Actions → ExportLoop bodies and error handlers are stored as separate flows, so they sit outside the console list. We walk all of them. A real 18‑flow folder turned out to hold 27.
Conditions, loops, calls and API requests written out in plain logic, following the chain from one flow into the next. The documentation your team never had time to write.
Where failures are handled, where access changes are guarded, what’s traceable, what’s still referenced. Five dimensions, each traced to a specific fact in your file.
A dated, hashed attestation with a robustness score and a prioritised improvement register — written to answer an auditor asking how you know.
Automation estates don’t stay still, and every one of these arrives eventually. Each is far easier when the estate is already written down.
A baseline attestation typically pays for itself against a single audit cycle or a single handover. Continuous re‑attestation is priced against the value of always being ready — worth it if your estate keeps changing, and easy to skip if it doesn’t.
Which means no security review, no vendor onboarding and no procurement conversation standing between you and a full picture of your own estate.
Five dimensions, weighted. Every point deducted traces to a fact below, and the same calculation runs on every assay — so the number is comparable over time rather than a one-off impression.
| Dimension | Score | Basis |
|---|
Flow call graph · click any flow to inspect it
| Table | Cols | Stated purpose |
|---|
| Flow | Cards | Connectors | Findings |
|---|
Click any control to see what it checks and why the result is what it is. Controls that cannot be answered from an export are reported as not assessed rather than passed.
Open a folder in the Workflows console, choose Actions → Export, download the file. Okta strips every credential on the way out.
We walk the whole estate, including flows embedded inside loop bodies and error handlers that the console does not list.
Findings, a score, and the code your flows amount to — as one file you download. For a dated, hashed attestation, talk to us.
The export format carries no owner, no enabled or disabled marker, and no last-run timestamp. Controls depending on those are reported as not assessed rather than passed. We would rather show you a gap than a green tick you cannot rely on.