Okta Workload Principal
| eventType | Description | Sample | Rule |
|---|---|---|---|
| workload_ | Workload principal has been activated. | N | N |
| workload_ | Activate an AI agent credential. | N | N |
| workload_ | Create an AI agent credential. | N | N |
| workload_ | Deactivate an AI agent credential. | N | N |
| workload_ | Delete an AI agent credential. | N | N |
| workload_ | Workload principal has been deactivated. | N | N |
| workload_ | Workload principal has been deleted. | N | N |
| workload_ | Workload Principal has been registered. | N | N |
| workload_ | Workload principal resource connection activation. | N | N |
| workload_ | Workload principal resource connection creation. | N | N |
| workload_ | Workload principal resource connection deactivation. | N | N |
| workload_ | Workload principal resource connection deletion. | N | N |
| workload_ | Workload principal resource connection update. | N | N |
| workload_ | Sign-on provider has been added to workload principal. | N | N |
| workload_ | Sign-on provider has been removed from workload principal. | N | N |
| workload_ | workload principal has been updated. | N | N |
| workload_ | Create a workload principal delegation link. | N | N |
| workload_ | Delete a workload principal delegation link. | N | N |
workload_principal.activate
#Description
Workload principal has been activated. This event can be used to track the activation of workload principals within the organization, including details about the agent and the user who performed the activation. When fired, this event contains information about the workload principal, such as its configuration, and the user who activated it.
References #
workload_principal.ai_agent.credential.activate
#Description
Activate an AI agent credential. This event can be used to track the activation of credentials for AI agents within the organization, including details about the credential and the user who performed the activation.
References #
workload_principal.ai_agent.credential.create
#Description
Create an AI agent credential. This event can be used to track the creation of credentials for AI agents within the organization, including details about the credential and the user who performed the creation.
References #
workload_principal.ai_agent.credential.deactivate
#Description
Deactivate an AI agent credential. This event can be used to track the deactivation of credentials for AI agents within the organization, including details about the credential and the user who performed the deactivation.
References #
workload_principal.ai_agent.credential.delete
#Description
Delete an AI agent credential. This event can be used to track the deletion of credentials for AI agents within the organization, including details about the credential and the user who performed the deletion.
References #
workload_principal.deactivate
#Description
Workload principal has been deactivated. This event can be used to track the deactivation of workload principals within the organization, including details about the agent and the user who performed the deactivation. When fired, this event contains information about the workload principal, such as its configuration, and the user who deactivated it.
References #
workload_principal.delete
#Description
Workload principal has been deleted. This event can be used to track the deletion of workload principals within the organization, including details about the agent and the user who performed the deletion. When fired, this event contains information about the workload principal, such as its configuration, and the user who deleted it.
References #
workload_principal.register
#Description
Workload Principal has been registered. This event can be used to track the registration of workload principals within the organization, including details about the user who registered it. When fired, this event contains information about the workload principal, such as its type, configuration, and the user who registered it.
References #
workload_principal.resource_connection.activate
#Description
Workload principal resource connection activation. This event can be used to track the activation of resource connections for workload principals within the organization, including details about the connection and the user who made the activation. When fired, this event contains information about the workload principal, the resource connection activated, and the user who performed the activation.
References #
workload_principal.resource_connection.create
#Description
Workload principal resource connection creation. This event can be used to track the creation of resource connections for workload principals within the organization, including details about the connection and the user who made the creation. When fired, this event contains information about the workload principal, the resource connection created, and the user who performed the creation.
References #
workload_principal.resource_connection.deactivate
#Description
Workload principal resource connection deactivation. This event can be used to track the deactivation of resource connections for workload principals within the organization, including details about the connection and the user who made the deactivation. When fired, this event contains information about the workload principal, the resource connection deactivated, and the user who performed the deactivation.
References #
workload_principal.resource_connection.delete
#Description
Workload principal resource connection deletion. This event can be used to track the deletion of resource connections for workload principals within the organization, including details about the connection and the user who made the deletion. When fired, this event contains information about the workload principal, the resource connection deleted, and the user who performed the deletion.
References #
workload_principal.resource_connection.update
#Description
Workload principal resource connection update. This event can be used to track updates made to resource connections for workload principals within the organization, including details about the changes and the user who made them. When fired, this event contains information about the workload principal, the resource connection updated, the changes made, and the user who performed the update.
References #
workload_principal.sign_on_provider.add
#Description
Sign-on provider has been added to workload principal. This event can be used to track the addition of sign-on providers to workload principals within the organization, including details about the provider and the user who made the addition. When fired, this event contains information about the workload principal, the sign-on provider added, and the user who performed the addition.
References #
workload_principal.sign_on_provider.remove
#Description
Sign-on provider has been removed from workload principal. This event can be used to track the removal of sign-on providers from workload principals within the organization, including details about the provider and the user who made the removal. When fired, this event contains information about the workload principal, the sign-on provider removed, and the user who performed the removal.
References #
workload_principal.update
#Description
workload principal has been updated. This event can be used to track updates made to workload principals within the organization, including details about the changes and the user who made them. When fired, this event contains information about the workload principal, such as its configuration changes, and the user who updated it.
References #
workload_principal.delegation_link.create
#Description
Create a workload principal delegation link. This event can be used to track the creation of delegation link for workload principals within the organization, including details about the source, target and the user who created it. When fired, this event contains information about the workload principal, the delegation link created, and the user who performed the creation.
References #
workload_principal.delegation_link.delete
#Description
Delete a workload principal delegation link. This event can be used to track the deletion of delegation link for workload principals within the organization, including details about the source, target and the user who deleted it. When fired, this event contains information about the delegation link deleted, and the user who performed the deletion.