Okta-workload-principal

16 operations, identified by eventType in the audit log.

eventTypeDescription
workload_principal.activateWorkload principal has been activated. This event can be used to track the activation of workload principals within the organization, including details about the agent and the user who performed the activation. When fired, this event contains information about the workload principal, such as its configuration, and the user who activated it.
workload_principal.ai_agent.credential.activateActivate an AI agent credential. This event can be used to track the activation of credentials for AI agents within the organization, including details about the credential and the user who performed the activation.
workload_principal.ai_agent.credential.createCreate an AI agent credential. This event can be used to track the creation of credentials for AI agents within the organization, including details about the credential and the user who performed the creation.
workload_principal.ai_agent.credential.deactivateDeactivate an AI agent credential. This event can be used to track the deactivation of credentials for AI agents within the organization, including details about the credential and the user who performed the deactivation.
workload_principal.ai_agent.credential.deleteDelete an AI agent credential. This event can be used to track the deletion of credentials for AI agents within the organization, including details about the credential and the user who performed the deletion.
workload_principal.deactivateWorkload principal has been deactivated. This event can be used to track the deactivation of workload principals within the organization, including details about the agent and the user who performed the deactivation. When fired, this event contains information about the workload principal, such as its configuration, and the user who deactivated it.
workload_principal.deleteWorkload principal has been deleted. This event can be used to track the deletion of workload principals within the organization, including details about the agent and the user who performed the deletion. When fired, this event contains information about the workload principal, such as its configuration, and the user who deleted it.
workload_principal.registerWorkload Principal has been registered. This event can be used to track the registration of workload principals within the organization, including details about the user who registered it. When fired, this event contains information about the workload principal, such as its type, configuration, and the user who registered it.
workload_principal.resource_connection.activateWorkload principal resource connection activation. This event can be used to track the activation of resource connections for workload principals within the organization, including details about the connection and the user who made the activation. When fired, this event contains information about the workload principal, the resource connection activated, and the user who performed the activation.
workload_principal.resource_connection.createWorkload principal resource connection creation. This event can be used to track the creation of resource connections for workload principals within the organization, including details about the connection and the user who made the creation. When fired, this event contains information about the workload principal, the resource connection created, and the user who performed the creation.
workload_principal.resource_connection.deactivateWorkload principal resource connection deactivation. This event can be used to track the deactivation of resource connections for workload principals within the organization, including details about the connection and the user who made the deactivation. When fired, this event contains information about the workload principal, the resource connection deactivated, and the user who performed the deactivation.
workload_principal.resource_connection.deleteWorkload principal resource connection deletion. This event can be used to track the deletion of resource connections for workload principals within the organization, including details about the connection and the user who made the deletion. When fired, this event contains information about the workload principal, the resource connection deleted, and the user who performed the deletion.
workload_principal.resource_connection.updateWorkload principal resource connection update. This event can be used to track updates made to resource connections for workload principals within the organization, including details about the changes and the user who made them. When fired, this event contains information about the workload principal, the resource connection updated, the changes made, and the user who performed the update.
workload_principal.sign_on_provider.addSign-on provider has been added to workload principal. This event can be used to track the addition of sign-on providers to workload principals within the organization, including details about the provider and the user who made the addition. When fired, this event contains information about the workload principal, the sign-on provider added, and the user who performed the addition.
workload_principal.sign_on_provider.removeSign-on provider has been removed from workload principal. This event can be used to track the removal of sign-on providers from workload principals within the organization, including details about the provider and the user who made the removal. When fired, this event contains information about the workload principal, the sign-on provider removed, and the user who performed the removal.
workload_principal.updateworkload principal has been updated. This event can be used to track updates made to workload principals within the organization, including details about the changes and the user who made them. When fired, this event contains information about the workload principal, such as its configuration changes, and the user who updated it.

workload_principal.activate

#
Namespace
Okta-workload-principal

Description

Workload principal has been activated. This event can be used to track the activation of workload principals within the organization, including details about the agent and the user who performed the activation. When fired, this event contains information about the workload principal, such as its configuration, and the user who activated it.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.ai_agent.credential.activate

#
Namespace
Okta-workload-principal

Description

Activate an AI agent credential. This event can be used to track the activation of credentials for AI agents within the organization, including details about the credential and the user who performed the activation.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.ai_agent.credential.create

#
Namespace
Okta-workload-principal

Description

Create an AI agent credential. This event can be used to track the creation of credentials for AI agents within the organization, including details about the credential and the user who performed the creation.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.ai_agent.credential.deactivate

#
Namespace
Okta-workload-principal

Description

Deactivate an AI agent credential. This event can be used to track the deactivation of credentials for AI agents within the organization, including details about the credential and the user who performed the deactivation.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.ai_agent.credential.delete

#
Namespace
Okta-workload-principal

Description

Delete an AI agent credential. This event can be used to track the deletion of credentials for AI agents within the organization, including details about the credential and the user who performed the deletion.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.deactivate

#
Namespace
Okta-workload-principal

Description

Workload principal has been deactivated. This event can be used to track the deactivation of workload principals within the organization, including details about the agent and the user who performed the deactivation. When fired, this event contains information about the workload principal, such as its configuration, and the user who deactivated it.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.delete

#
Namespace
Okta-workload-principal

Description

Workload principal has been deleted. This event can be used to track the deletion of workload principals within the organization, including details about the agent and the user who performed the deletion. When fired, this event contains information about the workload principal, such as its configuration, and the user who deleted it.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.register

#
Namespace
Okta-workload-principal

Description

Workload Principal has been registered. This event can be used to track the registration of workload principals within the organization, including details about the user who registered it. When fired, this event contains information about the workload principal, such as its type, configuration, and the user who registered it.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.resource_connection.activate

#
Namespace
Okta-workload-principal

Description

Workload principal resource connection activation. This event can be used to track the activation of resource connections for workload principals within the organization, including details about the connection and the user who made the activation. When fired, this event contains information about the workload principal, the resource connection activated, and the user who performed the activation.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.resource_connection.create

#
Namespace
Okta-workload-principal

Description

Workload principal resource connection creation. This event can be used to track the creation of resource connections for workload principals within the organization, including details about the connection and the user who made the creation. When fired, this event contains information about the workload principal, the resource connection created, and the user who performed the creation.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.resource_connection.deactivate

#
Namespace
Okta-workload-principal

Description

Workload principal resource connection deactivation. This event can be used to track the deactivation of resource connections for workload principals within the organization, including details about the connection and the user who made the deactivation. When fired, this event contains information about the workload principal, the resource connection deactivated, and the user who performed the deactivation.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.resource_connection.delete

#
Namespace
Okta-workload-principal

Description

Workload principal resource connection deletion. This event can be used to track the deletion of resource connections for workload principals within the organization, including details about the connection and the user who made the deletion. When fired, this event contains information about the workload principal, the resource connection deleted, and the user who performed the deletion.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.resource_connection.update

#
Namespace
Okta-workload-principal

Description

Workload principal resource connection update. This event can be used to track updates made to resource connections for workload principals within the organization, including details about the changes and the user who made them. When fired, this event contains information about the workload principal, the resource connection updated, the changes made, and the user who performed the update.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.sign_on_provider.add

#
Namespace
Okta-workload-principal

Description

Sign-on provider has been added to workload principal. This event can be used to track the addition of sign-on providers to workload principals within the organization, including details about the provider and the user who made the addition. When fired, this event contains information about the workload principal, the sign-on provider added, and the user who performed the addition.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.sign_on_provider.remove

#
Namespace
Okta-workload-principal

Description

Sign-on provider has been removed from workload principal. This event can be used to track the removal of sign-on providers from workload principals within the organization, including details about the provider and the user who made the removal. When fired, this event contains information about the workload principal, the sign-on provider removed, and the user who performed the removal.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #

workload_principal.update

#
Namespace
Okta-workload-principal

Description

workload principal has been updated. This event can be used to track updates made to workload principals within the organization, including details about the changes and the user who made them. When fired, this event contains information about the workload principal, such as its configuration changes, and the user who updated it.

Fields #

NameDescription
actor.idUnique ID of the actor performing the event.
actor.typeType of actor: User, Client, System, PublicClientApp, etc.
actor.alternateIdUsername or email of the actor.
actor.displayNameDisplay name of the actor.
target[].idID of each target object (user, group, application, ...).
target[].typeType of each target object.
target[].alternateIdUsername or email of each target object.
outcome.resultResult: SUCCESS, FAILURE, SKIPPED, ALLOW, DENY, CHALLENGE, UNKNOWN.
outcome.reasonHuman-readable reason for the outcome.
client.ipAddressIP address of the client.
client.userAgent.rawUserAgentRaw user agent string.
client.geographicalContext.countryCountry of origin for the request.
securityContext.isProxyWhether the request came through a proxy or anonymizer.
authenticationContext.externalSessionIdSession ID correlating events in one user session.
transaction.idTransaction ID correlating multiple log entries for one action.

References #