Declare the intended posture before the tenant exists — expected integrations, required conditions, operating targets. As the system is configured and integrated, Panaptico observes live provider state and verifies every tracked field against that declaration. Handoff is evidence-backed results, and every change after feeds a go/no-go gate a human owns.
Intended posture · declared
14 integrations declared before stand-up — the expected population.
Workday
HRIS — source of truth
GitHub
Source control
AWS
Cloud — 3 accounts
Snowflake
Data warehouse
Slack
Collaboration
Zoom
Meetings
Netsuite
Finance ERP
Jira
Delivery
+ 6 more in the declared scope
Verified against target
live provider state
Tenant foundation
11 fields · 4 conditions · 6 evidence
Identity source
18 fields · 7 conditions · 12 evidence
Policy model
22 fields · 9 conditions · 14 evidence
Integrations
26 fields · 11 conditions · 22 evidence
Cutover
7 fields · 3 conditions · 9 evidence
The gap
01
The stand-up ends with a slide that says “configured.” Nobody can show, field by field, that the live tenant matches what was signed off — or when anyone last checked.
02
Fourteen systems are supposed to bind to this tenant. Without a declared expected population, the two that never bound aren’t failures — they’re just absent. No denominator, no miss.
03
A session lifetime changes on a Tuesday. Six months later nobody remembers the target value — and the deck from go-live has no idea reality moved.
Declared before day one
Declare the intended posture up front — expected integrations, required conditions, operating targets. As the tenant is configured and integrated, Panaptico observes live provider state and verifies every tracked field against that declaration. Gaps surface as named divergence, not surprises.
OKTA-TENANT-0001 · declared day 0 · 84 tracked fields · 14 expected integrations
Handoff deck
Asserted · a snapshot nobody re-checks
32
claims
Verification contract
Declared target · verified against live state
84
tracked fields · verified or Unknown
Verification-gated stand-up
Your team stands the system up; Panaptico verifies each phase against the declared target. Every gate has a named owner, an evidence bundle, and an exit condition — you don’t slide into the next phase, a human opens the gate on verified results.
Day 0 – 5
Tenant foundation
Org profile, domain verification, admin role model, break-glass accounts, vault-bound recovery keys — verified field by field against the declared target.
Gate owner
IT Lead · CISO
Day 5 – 14
Identity source
Workday declared as source of truth. Attribute mappings, eventing, joiner/mover/leaver rules, contractor split — each checked against its declared value.
Gate owner
IT Lead · HRIS Owner
Day 14 – 24
Policy model
Auth policies, MFA factors, session TTL, device trust, network zones, risk-based step-up — current state compared to target, field by field.
Gate owner
CISO · Compliance
Day 24 – 48
Integrations
14 downstream systems in the expected population — SAML, SCIM, custom attributes, group-to-entitlement mappings. Each binding verified or Unknown, never silent.
Gate owner
App Owners × 14
Day 48 – 60
Cutover
Pilot cohort verified clean, phased enablement gated on evidence, legacy IdP decommission confirmed in live state, handoff as results.
Gate owner
IT Lead · Exec sponsor
The declared target
Six months later when someone asks why WebAuthn is mandatory for admins, the answer is a record — the target value, the rationale, the signer, and the scope it still binds. And when live state moves off a target, drift shows the before and after values with attribution.
OKTA-TENANT-0001 · 38 declared targets · signed · definition-versioned
MFA factor order
Okta Verify (push) · WebAuthn · TOTP · SMS disabled
SMS removed — vendor compromise class. WebAuthn mandated for admin roles.
CISO · 2026-04-08
scope · 14 apps · admin role pool
Session lifetime — workforce
12h active · 30d refresh
Balances UX with risk-based step-up on Zscaler posture change.
CISO · IT Lead · 2026-04-09
scope · all SSO apps · device trust
Break-glass accounts
2 accounts · rotated quarterly · vaulted in 1Password
Recovery path if Okta is unreachable; minimum two so one person can't lock the tenant.
CISO · CFO · 2026-04-10
scope · tenant admin · console URL fallback
Contractor identity split
Separate group · no device trust · 90d forced rotation
Contractors don't ride the MDM fleet — can't assume device posture.
IT Lead · HRIS Owner · 2026-04-12
scope · Workday eventing · Slack guest policy
Admin role model
4-tier: Super · Org · Help-desk · Read-only
Help-desk can reset factors but not read tokens; read-only for auditors.
CISO · 2026-04-13
scope · tenant RBAC · audit trail
CrowdStrike risk → Okta
High risk = force re-auth · Critical = session kill
Identity + endpoint signal converged; CS Falcon ZTA score used in auth policy.
CISO · CrowdStrike Owner · 2026-04-15
scope · all sessions · SOC escalation path
Day-one handoff
Most stand-ups end with a zip file of screenshots and a person who knows things. Panaptico hands over verified results — every tracked field with its target, its evidence, its freshness, and its history, queryable from day one. And the system stays continuously verified after the handoff.
01
84 tracked fields · 14 integrations · 38 targets
Scope, target conditions, coverage, freshness, definition version, history. The same contract your ops team queries for the next five years.
02
5 phase bundles · 63 artifacts · signed
Provider reads, evaluated conditions, gate sign-offs, before-and-after values — bound to the field they verify, not loose in a folder.
03
84 of 84 fields evaluated · freshness < 24h
Every expected field evaluated or explicitly Unknown. What wasn’t checked is named, not missing — silence never becomes a pass.
Declare the target before the system exists. Verify every field as it stands up. And after handoff, every change opens a verification window — evidence decides go or no-go.