Connect Okta so Coworker can resolve identities accurately across every other source. Okta is admin-connected and identity-only.
Okta Data in Coworker
Indexedinto the knowledge graph
Users in all lifecycle states, including deprovisioned accounts — builds a verified Person entity and anchors identity resolution across every other connected source
Available to users, but kept out of the graph
These stay in the raw warehouse and are never surfaced as searchable graph content:
Groups and group memberships
Apps and app assignments, per user and per group
System log — a security-relevant projection (event type, actor, target, outcome). IP address, geolocation, and device data are stripped and never collected.
Never collected
Beyond the IP/geo/device stripping above, Coworker never collects compensation and salary data, bank details, review and feedback text, private-goal descriptions, identity documents, emergency contacts, birthdays, or home addresses from any HRIS connector — these are excluded at the API-scope and code level and never reach the warehouse, the graph, or a prompt.
Before you start
You must be a Coworker Network Admin and an Okta administrator
You need your Okta domain plus one of: an SSWS API token, or an OAuth service app (client ID and private key)
Okta is a beta connector — beta connectors may need enabling for your workspace
Connect as an admin
Open Data Sources from the admin settings in Coworker and select Okta.
Enter your Okta domain.
Paste an SSWS token, or supply the service app's client ID and private key.
Save.
Connect as a member
Okta has no per-user connection flow.
Good to know
An SSWS token inherits the Okta administrator who created it. Deactivating that user revokes the token, and insufficient admin rights can produce partial directory visibility.
Okta expires API tokens after prolonged inactivity, so a dormant connection may need a replacement token.
The service-app route avoids depending on a human admin account, but the app needs both granted API scopes and assigned Okta admin roles. Scopes alone are not enough.
The Okta domain must match the organization in either mode.
