Overview

The seeded lab, live in your browser.
The chain

Okta Active Directory TrueNAS + Proxmox


Try it: onboard someone, see their access in the explorer, then offboard them and watch the residual access go to zero.

Directory

Everyone in Okta, with the downstream access they resolve to.

Onboard

Provision a new hire across the whole stack in one action.
The provisioned account and its resolved access will appear here.

Offboard

Deprovision same-day — and verify zero residual access.

Deactivates in Okta, cascades to AD via SCIM, and re-resolves downstream access to confirm it is empty.

The verification result will appear here.

Devices

Managed laptop fleet — imaged per role on day one, flagged wipe & return at offboarding.

Onboarding readiness

Is each hire day-one ready? A live checklist across accounts, groups, laptop, MFA, SaaS, and training.

Access explorer

Resolve the full chain for any user, and test a single decision.
Test a decision

Access review

A quarterly-style entitlement report with anomaly flags.
Flags

Audit log

Append-only — every mutation and access decision in this session.

Access requests

Self-service requests → reviewer approves or denies. Approval grants the group through the normal Okta → AD path — all audited.
File a request

Break-glass admin

Just-in-time elevation into powerful groups — time-bound and self-expiring, so nobody carries standing admin.

Compliance

Training records that gate sensitive access. Toggle a training to see gated access unlock or auto-revoke.

SaaS & cost

Who has a seat in what — and what it costs. The source of truth for licence spend.

Cost analytics

SaaS spend by department against budget, vendor spend by category, and the savings from reclaiming orphaned seats.

Lab operations

Equipment, inventory, vendors, and facility safety — with the flags a reviewer wants.

Backup / DR health

Snapshot + replication status for every TrueNAS dataset and Proxmox VM, with stale-backup flags.

Network segmentation

VLANs, device placement, and a default-deny east-west policy — Wi-Fi / IoT segmentation and firewall rules.

Architecture

Identity flows down; decisions resolve back up.

Sign-in demo

Authenticate against the Okta layer and inspect the issued session token.

The auth result and token claims will appear here.