Diagnose access problems
Most access tickets are a variant of “why can’t I get in”. The System Log holds the answer, and@Search Okta System Logs lets the agent read it and explain what happened in plain language.
Search system logs
Search system logs
@Search Okta System LogsInput fields:userEmail(required) - filter logs to events where this user is the actor or target.since- ISO 8601 start timestamp for the time range. Defaults to 24 hours ago.until- ISO 8601 end timestamp for the time range.eventType- filter by a single Okta event type, for exampleuser.session.startorpolicy.evaluate_sign_on.keyword- free-text search across event fields.limit- maximum events to return (1-100). Defaults to 50.
events- each event’spublishedtimestamp,eventType,displayMessage,severity,actor,outcome, andtarget. Theoutcome.reasonfield usually names the exact cause of a failure.totalCount- how many events came back.
- Explain a failed sign-in or a locked account
- Find the MFA prompt a user started but never completed
- Show when someone lost a group membership, and what they lost access to with it
- Confirm whether a just-granted app assignment took effect
When someone reports they cannot sign in or an app is denying them access, use @Search Okta System Logs for their email over the last 24 hours before replying. Tell them what the log shows in plain language, for example a failed MFA challenge or a removed group membership. If the fix is a password or MFA reset, offer it. Only escalate if the log does not explain the failure.
okta.logs.read scope on your Okta app. If the scope is missing, the tool fails when the agent first calls it rather than at setup, so grant it before you write rules that depend on it.Common event types
Useful values for theeventType filter when you want to narrow a search:
Look up people and groups
Get user
Get user
@Get Okta UserInput fields:userEmail(required) - the user to look up.
found-truewhen the user exists in Okta.firstName,lastName,email- the user’s profile.status- account status:ACTIVE,SUSPENDED,DEPROVISIONED, or similar Okta statuses.
- Confirm an account exists before resetting credentials or changing access
- Check whether an account is locked or suspended before trying to unlock it
- Verify the status of a newly created or recently deprovisioned account
Before resetting credentials or changing a user's access, use @Get Okta User to confirm the account exists and check its current status. If the status is DEPROVISIONED, tell the requester the account is gone and suggest activating it first.
List user groups
List user groups
@List Okta User GroupsInput fields:userEmail(required) - the user whose groups to list.
groups- each group’snameanddescription.totalCount- how many groups the user belongs to.
- Show a user which groups they are currently in
- Identify the missing group when someone cannot access a resource
- Audit group membership during offboarding
When someone asks what they have access to in Okta, use @List Okta User Groups to fetch their group membership and summarize it. If they mention a specific app or resource, explain which group would grant access and whether they are in it.
Check group membership
Check group membership
@Check Okta Group MembershipInput fields:userEmail(required) - the user to check.groupName(required) - the name of the Okta group.
isMember-truewhen the user is in the group.
- Confirm membership before adding or removing someone to avoid a no-op error
- Check whether a user is in the group that grants access to a specific resource
- Verify a group change took effect
Before adding or removing a user from an Okta group, use @Check Okta Group Membership to confirm their current status. If they are already a member when adding, or already absent when removing, tell the requester nothing needs to change.
Verify identity with Okta Verify push
Verify identity with Okta Verify push
@Verify Identity with Okta Verify PushInput fields:userEmail(required) - the user whose identity to verify. The push goes to their enrolled Okta Verify device.
verified-truewhen the user approved the push.status-approved,rejected,timed_out,no_factor, oruser_not_found.message- explanation of the outcome to relay to the requester.
- Confirm identity before a password or MFA reset when the request comes over chat
- Gate sensitive group or app changes behind a second factor
- Detect impersonation: a
rejectedstatus means the account owner denied the request
When someone asks you to reset their Okta password or MFA, tell them a push notification is coming, then use @Verify Identity with Okta Verify Push. If status is approved, proceed with the reset. If rejected, stop and tell them someone may be impersonating them. If timed_out, offer to try again. If no_factor, skip push verification and escalate to a human.
Fix credentials
Reset password
Reset password
@Reset Okta MFA in the same rule.Tool name: @Reset Okta PasswordInput fields:userEmail(required) - the user to reset.
- Reset a forgotten password
- Re-trigger the password reset email when the first one expired
- Reset credentials before reactivating a suspended account
When someone says they forgot their Okta password, use @Reset Okta Password for their email and confirm that a reset email is on its way. If they also mention losing MFA access, use @Reset Okta MFA in the same response.
Reset MFA
Reset MFA
@Reset Okta MFAInput fields:userEmail(required) - the user to reset.
- Clear factors when a user gets a new phone or replaces a lost device
- Remove a compromised factor before asking the user to re-enroll
- Unblock a user who cannot pass a second factor after a device change
When someone says they have a new phone or lost their MFA device, use @Reset Okta MFA to clear their enrolled factors and tell them they will be prompted to re-enroll on their next sign-in. If they also forgot their password, use @Reset Okta Password in the same response.
Unlock user
Unlock user
@Get Okta User to confirm the account is actually locked before unlocking.Tool name: @Unlock Okta UserInput fields:userEmail(required) - the user to unlock.
- Unblock a user who hit the maximum failed login attempts
- Unlock an account after a brute-force lockout
- Restore access without changing credentials
When someone says their Okta account is locked, use @Get Okta User to confirm the status is LOCKED_OUT, then use @Unlock Okta User and tell them they can try signing in again. If the account is not locked, explain what you found instead.
Generate password reset link
Generate password reset link
@Generate Okta Password Reset LinkInput fields:userEmail(required) - the user to generate a link for.
- Send a reset link directly to a user without putting it in the ticket
- Reset a password for a user who cannot receive the standard reset email
- Give an admin a way to hand someone a reset link privately
When someone needs an Okta password reset link, use @Generate Okta Password Reset Link for their email. The link is sent by private Slack DM. Refer to the recipient by name or email in your reply, not as 'you', since you may be helping an admin reset someone else's account.
Manage access
Add user to group
Add user to group
@Check Okta Group Membership to avoid an error when the user is already in the group.Tool name: @Add User to Okta GroupInput fields:userEmail(required) - the user to add.groupName(required) - the name of the Okta group.
- Grant access to a resource controlled by a group
- Add a new hire to their team’s groups during onboarding
- Restore group membership after an accidental removal
When someone requests group access in Okta, use @Check Okta Group Membership to confirm they are not already a member, then use @Add User to Okta Group. Confirm the change in the reply and tell them what access the group grants.
Remove user from group
Remove user from group
@Remove User from Okta GroupInput fields:userEmail(required) - the user to remove.groupName(required) - the name of the Okta group.
- Revoke access to a resource controlled by a group
- Remove someone from a team’s groups when they change roles
- Clean up group membership during offboarding
When someone's group access needs to be removed, use @Check Okta Group Membership to confirm they are in the group, then use @Remove User from Okta Group and confirm the removal in the reply.
Add user to application
Add user to application
@Add User to Okta ApplicationInput fields:userEmail(required) - the user to assign.appName(required) - the name of the Okta application.
appName- the application name as resolved by Okta.exactMatch-truewhen the name matched exactly. Whenfalse, the tool returned candidates; confirm the resolved name with the requester before taking further action.
- Grant access to a SaaS app during onboarding
- Assign a user to an app after they join a new team
- Restore an app assignment removed during an access review
When someone requests access to an Okta application, use @Add User to Okta Application with the app name from the request. If exactMatch is false, confirm the resolved application name with the requester before proceeding.
Remove user from application
Remove user from application
@Remove User from Okta ApplicationInput fields:userEmail(required) - the user to remove.appName(required) - the name of the Okta application.
appName- the application name as resolved by Okta.exactMatch-truewhen the name matched exactly. Whenfalse, confirm the resolved name with the requester before reporting the change as done.
- Revoke app access when someone changes teams or leaves a project
- Remove an app assignment during offboarding
- Clean up unused app assignments after an access review
When an admin asks to remove someone's access to an Okta application, use @Remove User from Okta Application. If exactMatch is false, confirm the resolved name with the requester before telling them the change is done.
Create group
Create group
@Create Okta GroupInput fields:groupName(required) - the name for the new group.description- what the group is for.
groupId- the new group’s Okta ID.groupName- the created group’s name.
- Create a group for a new team or project
- Set up a group to control access to a new application
- Provision a group as part of bulk onboarding
When someone asks to create an Okta group, confirm the name and purpose with them, then use @Create Okta Group. Reply with the group name and its Okta ID so the requester can reference it.
Delete group
Delete group
@Delete Okta GroupInput fields:groupName(required) - the name of the group to delete.
- Remove a group after a project ends
- Clean up unused groups during an access audit
- Delete a group created by mistake
When a request comes in to delete an Okta group, repeat the group name back to the requester and ask them to confirm before running @Delete Okta Group.
Activate user
Activate user
@Get Okta User first to check the current status.Tool name: @Activate Okta UserInput fields:userEmail(required) - the user to activate.
- Activate a new account that was staged but never activated
- Reactivate someone returning from leave whose account was deprovisioned
- Restore access for a rehire
When a manager requests that a returning employee's Okta account be reactivated, use @Get Okta User to check the current status, then use @Activate Okta User and confirm the account is now active.
Deactivate user
Deactivate user
@Deactivate Okta UserInput fields:userEmail(required) - the user to deactivate.
- Suspend access at the end of an employee’s last day
- Disable an account during a security investigation
- Lock an account pending offboarding completion
When HR confirms an employee's last day, confirm the name and email with the requester, then use @Deactivate Okta User on their account and confirm the deactivation in the reply.
Create user
Create user
@Create Okta UserInput fields:email(required) - the primary email for the new user.firstName(required) - the user’s first name.lastName(required) - the user’s last name.secondaryEmail- optional recovery email address.
userId- the Ravenna user ID for the created account. Use it in follow-up calls to assign groups or apps.
- Create accounts for new hires from an onboarding request
- Provision a contractor account quickly from a ticket
- Create a user as the first step of a multi-step onboarding rule
When an onboarding ticket comes in, use @Create Okta User with the new hire's email, first name, and last name. After creation, use @Add User to Okta Group to assign their team groups and @Add User to Okta Application for each app they need. Reply with the new user's email and a summary of access granted.
Remove user
Remove user
@Get Okta User first so the agent confirms the target exists and checks the current status.Tool name: @Remove Okta UserInput fields:userEmail(required) - the user to remove.
- Complete offboarding by removing an account after its data has been transferred
- Delete a duplicate or test account
- Remove a deactivated account as part of a periodic access review
When an offboarding ticket is ready for final cleanup, use @Get Okta User to confirm the account status. If it is deactivated, ask the requester to confirm deletion, then use @Remove Okta User. If it is still active, use @Deactivate Okta User first, then offer to delete.
Set user password
Set user password
@Reset Okta Password (email link) or @Generate Okta Password Reset Link (private Slack DM).Tool name: @Set Okta User PasswordInput fields:userEmail(required) - the user.password(required) - the new password to set.
- Set an initial password during a bulk user import
- Synchronize a credential with another system that requires a specific value
- Set a temporary password to hand to a user directly before they change it
When a bulk import is complete and users need initial passwords set, use @Set Okta User Password for each account, then notify the users privately. For individual forgotten-password requests, use @Reset Okta Password or @Generate Okta Password Reset Link instead.
Setup
Connect Okta
Grant the log scope
okta.logs.read to your Okta app’s granted scopes. Without it, every other tool here still works and only log search fails.Check the agent's tools
Write a rule
Best practices
- Search the log before escalating. A rule that reads the log first turns most “I can’t get in” tickets into an answer instead of a handoff.
- Start without an event type filter. The unfiltered last 24 hours usually contains the cause. Narrow only when the result is noisy.
- Verify identity before sensitive actions. Use
@Verify Identity with Okta Verify Pushbefore a password or MFA reset when the request comes over chat and you cannot confirm who is asking. - Check membership before changing it. Pair
@Check Okta Group Membershipwith the add and remove tools so the agent reports what actually changed. - Name the person, not “you”. An admin often asks on someone else’s behalf, so rules should refer to the target user by name.
- Gate the destructive tools. Put
@Delete Okta Group,@Deactivate Okta User, and@Remove Okta Userbehind Requires approval in any rule an agent can reach on its own.