💼 Business
Okta App Assignment Checklist from Org Inventory (No Invented Group Counts)
Turn an Okta org inventory into an app assignment checklist only. No invented group counts, MFA factors, or API tokens beyond the inventory.
0Reviews
Prompt
Act as an Okta identity app-assignment coordinator who only uses a pasted org inventory. You write an app assignment checklist the inventory already supports. You do not invent group member counts, MFA factor lists, API tokens, or SCIM mappings not in Inputs. This is not legal advice, not an access-review attestation, and not a security certification. You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs. Inputs: - Okta org inventory I lock (app stubs, group cues, assignment notes): [Inventory] - Okta / Identity Engine version notes I lock: [Version] - Org or tenant label I may quote (or UNKNOWN): [Workspace] - Required app names I may quote (or UNKNOWN): [SpecNames] - Application labels already present (or UNKNOWN): [AppLabels] - Group cues already present (or UNKNOWN): [GroupCues] - Assignment and policy notes already present (or UNKNOWN): [AssignNotes] - Words I must not use: [Banned] - What I must never invent (group counts, MFA factors, API tokens, SCIM maps): [Never] - Output format: [Format] - Language: [Lang] Generate: 1. Honesty ledger: Inventory nouns, Version, Workspace, SpecNames, AppLabels, GroupCues, AssignNotes, Lang. Forbidden: invented group counts, MFA factors, API tokens, SCIM maps. Banner: not legal advice; not an access-review attestation; not a security certification. 2. App assignment checklist table: one row per Inventory app stub or group cue. Missing AssignNotes write NOT IN INPUTS. Use Okta apps, groups, assignments, and sign-on policy language when Inventory supports it. Never print group-count or MFA-factor VALUES not in Inventory. 3. Spec name set: only names in SpecNames. Unnamed apps stay NOT IN INPUTS. Never invent API-token VALUES not in Inventory. 4. Version lock: print Version. Refuse Okta features newer than Version if Version is named. 5. Refuse list: inventing group counts, inventing MFA factors, inventing API tokens, inventing SCIM mappings. 6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format. Constraints: - Checklist from Inventory only. No invented group-count VALUES. Teach Okta app assignment mapping, not a generic Azure AD or JumpCloud swap. - Honor Version. No emojis.
Instructions
Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.
Generated Output
This image was generated using the prompt above.

Examples
Example Input
Inventory: app Harbor Quay Slack OIDC as pasted group cue Engineering as pasted assignment notes push groups as pasted; app River Ops Salesforce SAML as pasted group cue Sales as pasted. Group count invent NONE. MFA invent NONE. Version: Okta Identity Engine 2024 as pasted (do not invent unreleased AI assignment writer) Workspace: Harbor Quay Corp tenant as pasted SpecNames: Slack OIDC as pasted; Salesforce SAML as pasted. APIToken UNKNOWN. AppLabels: Slack OIDC as pasted; Salesforce SAML as pasted. Zoom UNKNOWN. GroupCues: Engineering as pasted; Sales as pasted. Contractors UNKNOWN. AssignNotes: push groups as pasted. SCIM mapping NOT IN INPUTS. Banned: guaranteed SSO, count invent, MFA invent, token invent Never: invent group counts, invent MFA factors, invent API tokens, invent SCIM mappings Format: ledger + table + specs + version + refuse + compliance Lang: English
Example Output
1. Ledger. Inventory: app Harbor Quay Slack OIDC group cue Engineering assignment notes push groups; app River Ops Salesforce SAML group cue Sales. Group count invent NONE. MFA invent NONE. Version Okta Identity Engine 2024. Workspace Harbor Quay Corp tenant. SpecNames Slack OIDC; Salesforce SAML; APIToken UNKNOWN. AppLabels Slack OIDC; Salesforce SAML; Zoom UNKNOWN. GroupCues Engineering; Sales; Contractors UNKNOWN. AssignNotes push groups; SCIM mapping NOT IN INPUTS. Lang English. Banner: not legal advice; not an access-review attestation; not a security certification. Forbidden: invented group counts, MFA factors, API tokens, SCIM maps, guaranteed SSO, count invent, MFA invent, token invent. 2. App assignment checklist. 1. Harbor Quay Slack OIDC | AppLabels Slack OIDC as pasted | GroupCues Engineering as pasted | AssignNotes push groups as pasted | counts NONE | MFA NONE | Okta app assignment checklist only. 2. River Ops Salesforce SAML | AppLabels Salesforce SAML as pasted | GroupCues Sales as pasted | AssignNotes beyond push groups NOT IN INPUTS | counts NONE | MFA NONE. APIToken UNKNOWN so write APIToken NOT IN INPUTS. Zoom not invented beyond AppLabels. 3. Spec name set. Slack OIDC; Salesforce SAML as SpecNames. APIToken UNKNOWN so write APIToken NOT IN INPUTS. No group-count VALUES beyond Inventory. No third app invented. 4. Version lock. Okta Identity Engine 2024 as pasted. Unreleased AI assignment writer not used. Marketplace packs NOT IN INPUTS. 5. Refuse. Count invent: refused. MFA invent: refused. Token invent: refused. SCIM invent: refused. Guaranteed SSO: refused. 6. Compliance. Banned hits none. Format ledger+table+specs+version+refuse+compliance. Gaps: APIToken decision, Zoom AppLabels, Contractors GroupCues, SCIM mapping AssignNotes, marketplace packs list if any. Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.