Provisioning
OnTrackio + Okta
SAML single sign-on plus SCIM 2.0 user lifecycle, wire-verified against real Okta provisioning traffic.
What you get
- SAML 2.0 sign-on from your Okta org, with just-in-time user creation on first login
- SCIM 2.0 provisioning: joiners appear, movers change, leavers are deactivated, driven by Okta
- Okta group membership mapped to OnTrackio roles, applied and revoked automatically as membership changes
- Admin-assigned roles protected from provisioning churn: a manually set role is never clobbered by a sync
- Every provisioning event in the audit log with its provenance
How it connects
Okta connects over two standard rails. SAML handles sign-on: you add OnTrackio as a SAML application, exchange metadata, and map attributes. SCIM handles lifecycle: a bearer-token SCIM 2.0 endpoint per workspace that Okta provisions into. The SCIM implementation was verified against real Okta request shapes on a live environment, including the group-driven role changes, before we called it shipped.
What it deliberately does not do
This is identity and lifecycle, not asset data: Okta does not feed the hardware register, and OnTrackio does not write back into Okta. Offboarding interplay is deliberate: a SCIM deactivation revokes access, while the hardware-return checklist stays open until the equipment is actually back.
Plan note. SAML 2.0 and SCIM 2.0 are Enterprise-tier features; see pricing. Pricing is public.
Frequently asked questions
Is OnTrackio in the Okta Integration Network?
Not yet; the listing is in progress. The integration itself does not depend on it: OnTrackio connects as a standard SAML app plus a SCIM provisioning target, which Okta supports natively, and the setup guide walks through both in about 20 minutes.
What happens when someone leaves and Okta deactivates them?
The SCIM leaver event deactivates the user and revokes access immediately. The asset side stays honest: offboarding cannot be marked complete while the person still holds hardware, licenses, or pool equipment, so the leaver event starts the return process rather than hiding it.
Can Okta groups control OnTrackio permissions?
Yes. You map Okta groups to OnTrackio roles in the admin console; membership changes grant and revoke those roles automatically. Roles an admin assigned by hand are tagged as manual and protected from sync churn, so provisioning never silently strips deliberate access.
All integrations: the full list. Identity posture, sub-processors, and residency: the security page.
See Okta connected to a live workspace
A 30-minute demo covers the setup, the day-two behaviour, and the honest boundaries. Public pricing, no discovery-call gauntlet.