Board-readable drift monitor for Okta access policies, MFA gaps, stale exceptions, dormant users, privileged applications, risky sign-ins, and identity-risk remediation posture.
Identity risk gets dangerous when access exceptions age quietly. Leaders need a simple answer:
- Which Okta policy lanes have the highest drift?
- Where are MFA gaps, stale exceptions, dormant users, and privileged apps compounding?
- Which remediation route should move before the next audit, board review, or incident?
This repo turns synthetic Okta-style policy telemetry into a board-readable identity-risk register.
npm install
npm run verify
npm run demonpx okta-access-policy-drift-monitor fixtures/okta-policy-sample.json --format markdown
npx okta-access-policy-drift-monitor fixtures/okta-policy-sample.json --format jsonEach lane tracks MFA coverage, stale exceptions, dormant users, risky sign-ins, privileged app counts, group sprawl, evidence completeness, and business criticality.
This strengthens the identity/security lane with an Okta-specific signal: access policy drift translated into board-ready remediation sequencing.