Skip to main content
Okta Identity Governance (OIG) sync brings the requestable access in your OIG catalog into Ravenna as access levels. Users request that access in Ravenna, and Ravenna files the request in OIG. OIG then runs its own approval and provisioning. Use it when OIG is the system of record for access approvals and you want users to request access from Ravenna.

Prerequisites

  • An Okta tenant with Okta Identity Governance and Access Requests enabled
  • The Okta integration connected with either setup method
  • Okta applications and groups already synced into Ravenna. Ravenna maps catalog entries to them, so entries for unsynced apps or groups are skipped until they sync.

Required scopes and role

OIG sync needs three scopes beyond the standard set, plus the Access Requests Administrator admin role on the app.
  • Client Secret: the Ravenna app from the Okta OIN marketplace sets up the scopes and the role for you, so there’s nothing to configure.
  • Private Key: grant the scopes on your Okta API service app alongside the standard scopes, then assign the role. In Okta, open the app under Applications > Applications, grant the scopes on the Okta API Scopes tab, and assign the role on the Admin Roles tab. The role also includes app assignment management.
All three are required. Ravenna requests them together for every OIG call, so a missing scope blocks the sync and requests alike.
OIG uses the v2 Access Requests API, which rejects the older okta.governance.accessRequests.* scope names. Grant the okta.accessRequests.* scopes listed above.
The governance scopes are optional for everything else. Ravenna checks for them only when OIG sync is turned on, and integrations that don’t use OIG keep working without them.

Turn on OIG sync

1

Grant the scopes and role

With Private Key, grant the three okta.accessRequests.* scopes and assign the Access Requests Administrator role to your Okta API service app. With Client Secret, skip this step.
2

Enable the setting

Go to Settings > Integrations, open the ⋯ menu on the Okta integration, and choose Configure. Turn on Sync OIG requestable access as access levels.
3

Run a sync

Choose Resync from the same ⋯ menu, or wait for the next scheduled sync (every 6 hours by default). If Ravenna can’t read the OIG catalog, the integration status turns yellow and its tooltip shows a Missing Okta Identity Governance access warning.

How the sync works

On each Okta sync, after groups sync, Ravenna reads the OIG catalog and turns every requestable entry into an access level. If the group sync fails, Ravenna skips the catalog for that run.
  • Application entries: an entry under an Okta application becomes an access level on the matching Ravenna application.
  • Group entries: an entry tied to an Okta group becomes an access level on each Ravenna application that group grants. Ravenna also maps the access level to that group. Entries for groups that grant no application are skipped.
Synced access levels use the External provisioning method. Okta owns them, so every field except Access Policy is read-only in Ravenna. New levels attach to your default access policy, which decides who can request the level and whether the request needs approval in Ravenna before it’s filed in OIG. When an entry leaves the OIG catalog, Ravenna archives its access level. If the entry returns, Ravenna unarchives it. A level isn’t archived while its Okta application or group is still waiting to sync into Ravenna.
Turning the setting off stops the catalog sync, but access levels it already created stay active. Requests for them are still filed in OIG.
Learn more about external access levels

How requests work

1

The user requests access in Ravenna

The user picks an external access level, and the request goes through the level’s access policy.
2

Ravenna files the request in OIG

After the request is approved in Ravenna, Ravenna files an OIG access request for the requester against the matching catalog entry.
3

OIG approves and provisions

OIG runs its own approval and provisioning. Ravenna marks the entitlement Skipped Provisioning with the reason “Filed with OIG; approval and provisioning are owned by the external system”, and tells the requester their request was forwarded. For group-based levels, the new group membership appears in Ravenna on the next Okta sync.
Ravenna doesn’t follow the OIG request after filing it. Track approval in Okta. If OIG denies the request or it expires, the entitlement stays Skipped Provisioning in Ravenna. When Ravenna revokes an entitlement that was filed with OIG, it cancels the matching OIG access request. Canceling the request doesn’t remove access OIG has already granted, so remove that access in Okta.
Ravenna files each request as a self-request for the requester. If provisioning retries, Ravenna reuses the request it already filed instead of filing a new one.

Troubleshooting

Cause: Ravenna’s connection check couldn’t read the OIG catalog. Usually a scope or the role is missing on the app.Solution:
  • With Private Key, grant okta.accessRequests.catalog.read, okta.accessRequests.request.read, and okta.accessRequests.request.manage on the app, and assign the Access Requests Administrator role
  • With Client Secret, confirm OIG and Access Requests are enabled in your Okta tenant. The app includes the scopes and role, so contact Ravenna support if the warning persists.
  • Choose Resync from the ⋯ menu on the Okta integration
Behavior: The check only reads the catalog. If the catalog syncs but requests fail, check that a Private Key app has okta.accessRequests.request.manage and the role.
Cause: Ravenna couldn’t match the entry to a synced application or group, or the entry isn’t requestable.Solution:
  • Confirm the entry is requestable in OIG
  • Confirm the Okta application or group behind it has synced into Ravenna
  • For group entries, confirm the group grants at least one application
  • Run another sync after the application or group appears in Ravenna
Cause: Ravenna couldn’t file the request in OIG. Most often the requester has no Okta user linked in Ravenna, or the app is missing okta.accessRequests.request.manage.Solution:
  • Confirm the requester has an Okta user and that it has synced into Ravenna
  • With Private Key, confirm the app has all three okta.accessRequests.* scopes and the Access Requests Administrator role
  • Submit the request again once both are in place
Cause: Ravenna filed the request, and OIG still owns approval and provisioning. Ravenna doesn’t reflect OIG approvals, denials, or expirations.Solution:
  • Find the request in OIG Access Requests and check its status
  • For group-based levels, run a sync after OIG grants access so the membership shows in Ravenna
Last modified on October 2, 2026