INTEGRATIONSIDENTITY PROVIDER
OktaENABLED · 28 OF 28 CAPABILITIES ASSESSED
Okta groups and app assignments are granted from Ploy
Okta knows who your people are. Ploy reads what that actually grants them: every group, app assignment and MFA factor. Then it grants, expires and revokes on your rules.
TYPE · IDPAUTH · OAUTH + SCIMDOMAIN · OKTA.COMLAST ASSESSED · 29 JUL 2026
2.1WHAT IT UNLOCKS
Three jobs this connector does on day one
OFFBOARDING
Suspended the day the end date lands
The HR system records a leaver. Ploy suspends the Okta account and removes the group memberships and application assignments that came with it.
leaver detected · 09:04
okta user suspended · 09:04
6 group memberships removed · 09:05
9 app assignments removed · 09:05
JUST IN TIME ACCESS
Group membership with a clock
Requests land in Slack, approvals write straight to the group, and the grant drops itself when the window closes. Nobody has to remember.
okta-admins-billing4H LEFT
salesforce-superuserREVOKED
REVIEWS AND EVIDENCE
Reviewers see context, not a list
Each row carries department, MFA factors and last sign-in as they were at review time. Revocations execute in Okta and land in the certificate.
Department (at review time)MFA enabled (at review time)Last sign in (at review time)
2.2CAPABILITY MATRIX
All 28 capabilities, tested weekly
Ploy runs the same assessment against every integration and shows you the result. Nothing here is aspirational.