All integrations
OK
Identity
Okta
Groups, app assignments and admin roles
Okta is where most teams already keep people and groups, so it is usually the first thing connected. Clavra reads your groups and who is in them, then adds and removes people from groups when a grant starts and ends.
What Clavra can change
Only group membership, and only for groups you mark as requestable. Clavra never edits policies, sign-on rules or MFA settings.
Before you connect
Create an API service app with the okta.groups.manage scope. Admin roles such as Help desk admin can be requested too, but they need a second approver by default.
Category
Identity
Sync
Reads groups and people every 5 minutes. Writes group membership for timed grants.
Setup time
10 min