Integrations / Okta Identity Governance
Okta Identity Governance
Okta Identity Governance access certification, entitlement, grant, collection, and catalog data for access-review-aligned Telara setup proposals.
What Telara does
Capability matrix
Before you connect
Prerequisites
Vendor setup
Get the credential
Permissions Telara requests
- okta.governance.accessCertifications.readOAuth 2.0
- okta.governance.accessCertifications.manageOAuth 2.0
- okta.governance.accessRequests.readOAuth 2.0
- okta.governance.accessRequests.manageOAuth 2.0
- okta.governance.entitlements.readOAuth 2.0
- okta.governance.entitlements.manageOAuth 2.0
- okta.accessRequests.catalog.readOAuth 2.0
- okta.accessRequests.request.readOAuth 2.0
- okta.accessRequests.request.manageOAuth 2.0
In Telara
Connect in Telara
Okta OIN API Service Integration OAuth using client credentials for Identity Governance. Store base_url as the customer Okta org URL, for example https://company.okta.com.
In Telara, open Settings → Integrations, choose this connector, and click Connect. Telara sends you to the vendor to approve access, then returns you here. You do not create an OAuth app or paste a client secret.
- Base Url
- Scope
Okta API token for organizations that authorize OIG API access through SSWS. Store base_url as the Okta org URL.
In Telara, open Settings → Integrations, choose this connector, and paste the key into the fields Telara shows.
- API token
- Base Url
Knowledge
What gets indexed
| Resource | Coverage |
|---|---|
| Campaign | Partial — not every record the vendor holds is synced |
| Certification | Partial — not every record the vendor holds is synced |
Sync
Freshness & sync
| Resource | Lag | Deletions |
|---|---|---|
| Campaign | Up to 1 day | Removed records disappear on the next full sync |
| Certification | Up to 1 day | Removed records disappear on the next full sync |
Data handling
Permissions & data handling
The scopes above are the permissions this connector requests. They come from the catalog, not from a hand-written page.
Excluded from semantic search: Campaign, Certification.
After connect
Verify it worked
After you save, Telara runs a read-only check against the account. The integration shows as connected when that check succeeds.
Honesty

