Skip to content
Identity and access

The directory the rest of the stack has to obey.

Okta is the identity provider that authoritatively answers who someone is, and increasingly what a non-human identity is permitted to do. Our work is single sign-on, provisioning, governance, and bringing non-human identities into the same lifecycle as people.

Okta decides who someone is. Every other system in the estate resolves access through that decision, which is why it sits at the bottom of the Stack. Okta Activate Partner.

What is in it.

layer
vendor
tag

Adaptive MFA

What Atlas Bench does with Okta Adaptive MFA: designing verification policy by population, starting with privileged access.

API Access Management

What Atlas Bench does with Okta API Access Management: inventorying machine callers and scoping the tokens they hold.

Cross App Access

What Atlas Bench does with Okta Cross App Access: replacing ad-hoc integration consent with policy the identity provider enforces.

Device Access

What Atlas Bench does with Okta Device Access: policy design and the exception paths that decide whether it survives contact with contractors.

Identity Governance

What Atlas Bench does with Okta Identity Governance: designing and running the access certification cycle that produces audit evidence.

Lifecycle Management

What Atlas Bench does with Okta Lifecycle Management: directory-driven provisioning so joiners, movers, and leavers change access automatically.

Okta for AI Agents

What Atlas Bench does with Okta for AI Agents: giving non-human identities an owner, a scope, and a lifecycle before an agent rollout.

Privileged Access

What Atlas Bench does with Okta Privileged Access: finding the privileged population and designing time-bounded elevation with a record.

Single Sign-On

What Atlas Bench does with Okta Single Sign-On: federating the whole estate so offboarding actually closes every path.

Universal Directory

What Atlas Bench does with Okta Universal Directory: attribute design that drives group membership and provisioning across the estate.

What it is

Okta is the identity provider that authoritatively answers who someone is, and increasingly what a non-human identity is permitted to do. Its agent products are the first mainstream attempt to give an agent a first-class identity rather than a borrowed credential.

We are an Okta Activate Partner. In practice most of our Okta work arrives alongside an Atlassian estate, where the two have to be configured as one model rather than two lists that quietly disagree.

identity owner expires one owner recorded, five unaccounted L1 L2 L3 L4

Where it fits

Okta is L1, identity and access, and that is the whole of it. It does not run the work, hold the change record, or execute an agent. It decides who and what may reach the systems that do. Because every other layer resolves access through it, a weakness here is not contained here: it is inherited by L2, L3, and L4 without anyone deciding that it should be.

Proof

109:1

Machine identities per human in the enterprise, up from 45:1 two years earlier.

Palo Alto Networks, 2026 Identity Security Landscape, 2,930 respondents. Earlier ratios: CyberArk Identity Security Threat Landscape, 2024 and 2025.

81%

Of security leaders worry about excessive access held by non-human identities.

Okta Global CISO Insights, 2026.

Questions we get

We have Okta already. What is left?
Usually the connection to everything else. Okta answering who someone is does not decide which groups exist in Atlassian, who owns them, or when access is reviewed.
Does this replace Atlassian Guard?
No. Okta is the identity provider, Guard is how Atlassian obeys it. Configured separately they diverge, which is the common failure.

Find out who can reach what.

Fixed scope. The assessment starts at the identity layer: human and non-human access, the accounts nobody owns, and what has to be true before an agent gets one. You get the findings, the ownership gaps, and the order to close them in.