For Okta administrators

Know how your Okta is configured, and who changed it.

Idelvo backs up your Okta configuration, tracks every change back to the person who made it, compares tenants, and audits for risky settings. It runs on your own infrastructure and only ever reads from Okta.

  • Self-hosted
  • Read-only to Okta
  • Your data stays with you
Features

Everything you wish the Admin Console kept for you

Okta shows you how things are today. Idelvo keeps how they were, who changed them, and whether they're safe.

Configuration backup

Users, groups and group rules, apps and assignments, policies and rules, authenticators, network zones, device assurance and more, synced on a schedule. Every change is kept as a version, with a field-by-field diff and point-in-time JSON export.

Change tracking with names

The Okta System Log is collected continuously and kept well beyond Okta's 90 days. Each change Idelvo detects shows who made it, and every object shows the events that touched it. Filter by actor, target, event type and outcome.

Tenant diff

Compare production with preview, or any of your tenants. Objects are matched by what they are, not by ID, and references are compared by name, so you see real configuration drift instead of noise.

Security and hygiene audits

More than 50 built-in rules, evaluated after every sync, with thresholds you can tune and rule packs you can write yourself.

  • Weak policies, one-factor access, overly broad zones
  • Unused apps, inactive users, never-hit policy rules
  • Empty, unused and duplicate groups; broken group rules

Admin and API surface

See who holds admin roles and how they're protected, and what can reach your Okta APIs.

  • Admins without phishing-resistant MFA
  • API tokens owned by inactive users or Super Admins
  • Old client secrets and expiring certificates

Alerts and SIEM

Findings reach you by email or webhook (Slack, Teams or JSON), as one digest per audit, never repeated. Accept a finding with a reason and an expiry, and it stays quiet. The tool's own audit log streams to your SIEM.

Ask your AI assistant

A built-in MCP server lets assistants such as Claude answer questions like "who changed our MFA policy last week?" from your data. Access uses personal tokens that can't exceed your role, and nothing it does can change Okta.

Many tenants, one place

Register production, preview and development orgs side by side. Switch between them, compare them, and keep each one's history and findings separate.

Deployment model

Runs on your infrastructure. Reads, never writes.

Idelvo isn't a SaaS. You run it next to your other tools, and your Okta configuration and logs never leave your environment.

  • Self-hosted with Docker ComposeA web app, an API, a background worker and PostgreSQL, behind the reverse proxy of your choice. One server is enough to start.
  • Read-only to OktaIt connects as an Okta service app with private-key JWT and read scopes only. Production tenants are held to read-only scopes, and no feature writes to Okta.
  • No secrets keptClient secrets, hook credentials, key material and admins' phone numbers are dropped before anything is stored. Its own keys are referenced from files or the environment, never kept in the database.
  • Your identity, your rolesSign in with your own Okta, with Admin, Auditor and Viewer roles mapped from your groups, and a break-glass local admin for emergencies.
  • Accountable by defaultEvery action in the tool lands in its own append-only audit log, which you can export or stream to your SIEM.
  • Kind to rate limitsIt uses only a set share of each Okta rate-limit bucket (half by default), so your other integrations keep working.
Your environment
Web appAdmin, Auditor, Viewer
API and MCPREST and AI assistants
WorkerSyncs, log polling, audits
PostgreSQLVersions, events, findings
Read-only API calls (private-key JWT, read scopes)
Your Okta orgsProduction, preview, development
How it works

Up and running in an afternoon

Connect

Create a read-only service app in each Okta org and register it in Idelvo. Idelvo checks which read scopes Okta granted and turns on what it can collect.

Collect

The first sync takes a full snapshot and backfills the System Log Okta still holds. After that, configuration syncs on a schedule and the log is polled about every minute.

Review

Browse history, see who changed what, compare tenants and work through findings. Alerts tell you when something new needs attention.

FAQ

Questions

Can Idelvo change anything in Okta?

No. It connects with read scopes only, and no feature writes to Okta. Actions in Idelvo, such as accepting a finding or starting a sync, only change Idelvo itself.

Is it a cloud service?

No. You run it on your own server or cloud account with Docker Compose. Your configuration, System Log and findings stay in your database, and nothing is sent to us.

How long is history kept?

Configuration versions are kept indefinitely. System Log events are kept for 13 months by default, configurable per tenant, including forever.

Can I restore configuration from a backup?

Today, Idelvo shows every earlier version of an object, field by field, and exports snapshots as JSON, so you can see exactly what to put back. It never writes to Okta itself.

Can I add my own audit rules?

Yes. Rules are short YAML files with conditions written in CEL. You can tune the built-in rules' thresholds in the app, turn rules off, or load your own rule packs.

When can I try it?

Idelvo is in active development. Join the interest list and we'll let you know when it's ready to try.

Interest list

Be first to try Idelvo

Leave your email and we'll tell you when Idelvo is ready. We'll only use it for news about Idelvo, and you can ask us to remove it at any time.