Integration brief · Okta ← Back to the page   Print or save as PDF
Integration brief OktaIdentity and Access

One Sign-In Across Every Vendor You Buy From

Okta sells no email system, no ERP and no video platform, and that is the reason organizations pick it. It runs in the cloud, belongs to no vendor's stack, and carries the largest catalog of pre-built application integrations in the market, which is what an organization with a wide mixed estate wants from its identity provider. Nexus joins that catalog like any other application, with Redactor, AI Intelligence Hub and AI Live Insight enabled on the same portal behind one tile.

What you can do together

01

One tile among many

Staff reach Nexus from the same Okta dashboard as everything else, and the Redactor, AI Intelligence Hub and AI Live Insight on that portal need no second sign-in.

02

Joiners and movers arrive entitled

Okta pushes the account and its groups before first sign-in, so a new hire opens the library at the right level on day one, and a transfer changes level without a ticket.

03

Leavers close in one place

Deactivating the Okta account deactivates the portal account, so an offboarding checklist gains no extra line.

04

Identity stays a separate decision

The portal speaks SAML 2.0, OAuth 2.0 and OpenID Connect, and a portal can carry more than one SSO app, so a second provider sits beside Okta rather than replacing the setup.

How it connects

Sign-in first. The portal is added as an application in Okta, and on the portal side as an SSO app under Admin, Portal Settings, Apps, labeled SAML / OIDC in the catalog and given Okta's metadata address or a client id and secret. Okta authenticates under whatever policy already applies to that person, by network, device or group, and returns claims. Attribute mapping writes those claims into profile fields, so names, departments and any custom attribute Okta carries arrive with the user.

Provisioning second, over SCIM, with the portal as the SCIM 2.0 service provider. An administrator enables provisioning, generates a portal-scoped API token with an expiry, and gives Okta the token and the base URI. Okta then pushes users and groups ahead of first use. Entitlement follows the groups. Each user lands on a Client Access License, the portal's bundle of features and permissions, from a default that rules override by matching the incoming group's display name, first match winning. Where Okta is itself fed from an HR system, the chain runs from the HR record through Okta into the portal with nobody retyping a name.

Both connections run one way. Nothing is written back to Okta, and the password never reaches the portal. Two details belong in the setup notes. Provisioning stops when the token expires, and rule order decides the outcome for anyone whose groups match more than one rule, so the narrowest rule belongs at the top.

VIDIZMO and Okta · Integration briefPage 1 of 2
How it works OktaIdentity and Access

A scenario

  1. Rollout weekThe identity team adds the application in Okta and the SSO app in Nexus, enables SCIM, and pastes the token and base URI into Okta. Three groups are pushed: Loss Prevention, Store Managers, All Employees.
  2. OvernightThe user list fills. Rules put Loss Prevention on the investigator Client Access License, Store Managers on a manager level and everyone else on the viewer default.
  3. First morning, 07:00A manager in her first week signs in from the back office, answers the factor Okta asks for off the store network, and finds her training assignments waiting. Nobody created her account. The HR record did, through Okta.
  4. MidweekAn analyst asks AI Intelligence Hub which incidents at two stores mention the same vehicle. Retrieval runs under her own token, so the answer cites only footage she may open.
  5. After the seasonThe HR system marks a temporary cohort as leavers. Okta deactivates them on its next run and their portal accounts deactivate with them.

What stays where

Okta remains the identity provider

Passwords, factors, sign-on policy and account lifecycle are governed there, and the portal never becomes a second place to manage people.

The portal is one application among hundreds

It appears on Okta's application list and in the user dashboard alongside everything else, and nothing about the others changes.

Traffic is inbound only

Claims arrive at sign-in, SCIM pushes users and groups, and Okta is never written to.

Where the portal runs is a separate choice

Okta is cloud only, and the portal can be shared SaaS, a dedicated cloud, or your own datacenter at an address Okta can reach for provisioning.

Products and solutions

Next step

See it on your own Okta instance.

We will show the connection made, the data moving and the output, then size it for your deployment.

Contact VIDIZMO

sales@vidizmo.ai

+1 571-969-2180

vidizmo.ai

Product names and logos are the property of their respective owners.Page 2 of 2