Okta
The Okta app automatically updates your Okta profiles with ChartHop source data. You can configure both Okta profile fields and group memberships. Optionally, you can set the app to create Okta profiles when people are added to ChartHop.
When you install Okta, you'll need to make decisions about how you want to handle Okta profiles, whether you set a default location, and what fields you want to include in your sync.
Field | Description |
|---|---|
Okta profiles |
|
Sync new hires before start date | The number of days before a start date to begin syncing new hires |
Obtain Okta API credentials
You will need to obtain API access from Okta before you can install the app. To obtain an Okta API key, follow the steps outlined in their help document here.
- To connect Okta to ChartHop, you must be an Okta administrator.
- Once you've received the API token from Okta, do not share this information with anyone outside of your organization.
Install the Okta app
To install the Okta app, follow the steps below.
- From the left sidebar, select Apps & Bundles.
- From the sub-menu, select Apps.
- Select the Availible Apps tab.
- Locate and select the Okta app.
- Select Install.
- Follow the steps outlined in the setup wizard to connect the Okta app to ChartHop.
Configure Lifecycle & Provisioning Settings
Once the app is installed, you must configure how ChartHop handles new hires, re-hires, and departures. These settings determine when an Okta profile is created and when access is revoked.
Basic Settings
Access these by selecting Edit under the Basic Settings section of the Okta app.
Setting | Description |
|---|---|
Create Okta profiles for new hires | When enabled, ChartHop automatically creates an Okta record for any new person added to the platform. |
Re-activate Okta profiles for re-hires | When enabled, ChartHop identifies returning employees and re-activates their existing (inactive) Okta profile rather than creating a duplicate. |
De-activate Okta profiles on departures | Automates the de-activation of Okta accounts based on the termination date in ChartHop. |
De-activate same-day voluntary departures | If checked, you can set a specific deactivation Time (e.g., 11:00 PM). This allows voluntary leavers to maintain access until the end of their final day. |
Send email and activate upon creation | Determines if the account is immediately activated or remains in a "staged" state. Note: Test this to ensure it aligns with your onboarding workflow. |
Automated De-activation Logic
ChartHop performs a daily sync to manage departures based on the following rules:
- Past Departures: Any employee terminated yesterday (voluntary or involuntary) who remains active in Okta will be deactivated during the morning sync.
- Involuntary Departures: If event-based sync is active, these users are typically deactivated immediately upon the termination being entered.
- Voluntary Departures: These users are deactivated once per day at the designated cutoff time (e.g., 11:00 PM ET) to ensure they have access for their full final shift.
Run a single, on-demand sync to Okta
Any ChartHop user with sufficient permissions can trigger an on-demand sync to Okta at any time. To sync your data for the first time, or subsequently, on-demand at any time, follow the steps below.
- From the left sidebar, select Apps & Bundles.
- From the sub-menu, select Apps.
- Select the Installed Apps tab.
- Locate and select the Okta app in the list of installed apps.
- At the top of the page, select Run one-time sync.
- Select Run sync to perform the sync.
Export dry runs
Any ChartHop user with sufficient permissions can trigger a test integration between Okta and ChartHop at any time.
- From the left sidebar, select Apps & Bundles.
- From the sub-menu, select Apps.
- Select the Installed Apps tab.
- Locate and select the Okta app in the list of available apps.
- At the top of the page, select Run one-time sync.
- Select Export dry run to test the integration.
- When the integration is complete, select Download to recieve the test results file.
Create sync groups
You can create and populate Okta groups from the app config page by following the steps below.
- From the left sidebar, select Apps & Bundles.
- From the sub-menu, select Apps.
- Select the Installed Apps tab.
- Locate and select the Okta app in the list of available apps.
- Under the Advanced Settings section, select Edit.
- Under the Sync Groups section, select + Add group.
- Enter a name for the group in the Group Name field.
- Enter a corresponding Carrot query in the Include People Matching field, or use the filter controls to the left.
- Select test to confirm your query. It should open the Data Sheet in a new tab with your query applied.
- Select Save at the bottom of the page.
Create sync profile fields
For each custom Okta profile field, you may define a ChartHop field or expression to be synced. To do this, follow the steps below.
- From the left sidebar, select Apps & Bundles.
- From the sub-menu, select Apps.
- Select the Installed Apps tab.
- Locate and select the Okta app in the list of available apps.
- Under the Advanced Settings section, select Edit.
- Under the Sync Profile Fields section, select + Add field.
- Enter the name of a custom Okta profile field that you wish to populate with data.
- Enter the corresponding query or field that you wish to copy from ChartHop.
- Select Save at the bottom of the page
Common Expression Examples
Use these common expressions to map ChartHop data to Okta fields:
Okta Field Name | ChartHop Expression | Description |
|---|---|---|
managerEmail | manager.email | Pulls the primary email of the employee's direct manager. |
deptCode | department.code | Syncs the short-hand code for the department (e.g., "ENG" instead of "Engineering"). |
costCenter | custom.cost_center | Pulls a custom field value defined in your ChartHop instance. |
isManager | is_manager | A boolean (true/false) based on whether the person has direct reports. |
Supported Attributes
The following SAML attributes are supported:
Attribute name | Name format | Value |
|---|---|---|
org | unspecified | {org-slug-from-ChartHop} |
unspecified | user.email | |
first_name | unspecified | user.firstName |
last_name | unspecified | user.lastName |
ο»ΏModules: HRIS | Engagement | Goals | Performance | Compensation Reviews | Headcount Planning
