Identity resilience by ArboID

Back up your identity configuration. Recover in minutes, not days.

ArboVault snapshots your Okta tenant configuration, shows you exactly what drifted, and restores it to the same tenant or a different one when something goes wrong.

  • Users
  • Groups
  • Applications
  • Policies
  • Authenticators
ArboVault safe

Configuration categories captured in every snapshot.

What is ArboVault?

Your identity provider is the front door to every application your company runs, yet its configuration is rarely backed up. A misconfigured policy, a deleted group or a bad bulk change can lock out thousands of users. ArboVault gives identity teams the version history, drift detection and restore tooling they have always had for code and infrastructure.

Everything you need to recover

  • Snapshots

    Capture users, groups, applications, policies, network zones, authenticators and more into a versioned backup.

  • Compare and drift

    Diff any two snapshots, or a snapshot against the live tenant, to see what was added, removed or changed.

  • Selective restore

    Restore chosen objects to the same tenant or to another one, with a preview of every change before it runs.

  • Schedules

    Run backups automatically on a cadence so your latest known-good configuration is never stale.

  • Storage

    Keep backups in storage you control and export them for offline retention or Terraform workflows.

  • Audit log

    Every backup, comparison, restore and sign-in event is recorded so you can answer who did what, and when.

How it works

  1. 1

    Connect a tenant

    Add your Okta org URL and a read-scoped SSWS API token.

  2. 2

    Take a backup

    ArboVault snapshots the configuration and stores it as a versioned backup.

  3. 3

    Detect drift

    Compare snapshots over time and review exactly what changed.

  4. 4

    Restore with confidence

    Preview and apply a selective restore to recover fast.

Built to protect the keys to your kingdom

  • Two-factor authentication

    Every account must enrol an authenticator app before it can use the platform.

  • Progressive lockout

    Repeated failed sign-ins lock the account for longer each time, and the security team is alerted by email.

  • Organization isolation

    Users only see their own organization. Invitations never cross organization boundaries.

Ready to protect your identity configuration?

Access is by invitation. Sign in with the account your administrator created for you.

Sign in