Terraform Okta: Identity as Code
Okta config lives in Terraform now, not in clicks. Config drift is gone, changes get reviewed like code, and policy stays consistent across the tenant.
Senior Systems Engineer · Corporate Systems lead, Robinhood
Identity has been my whole career: who gets in, what they can touch, and how access ends when they leave. Ten years of that across fintech and healthcare. Lately the newest users on the network are not people, so the job now is making sure AI tools live by the same rules as everyone else: who, and what, can do what.

The identity, cloud, and collaboration stack the company runs on. The mandate: harden the foundation, make AI tooling adoptable, keep sprawl down.
Authentication flows in Okta: SAML, OAuth 2.0, OIDC, plus SCIM for downstream provisioning. The full user lifecycle: birthright access, joiners, movers, leavers, rehires, service accounts, and the edge cases SCIM can't reach.
Led the Okta Identity Governance rollout: access certification campaigns and policy-driven lifecycle controls. Audit responses across SOX controls, access reviews, and service accounts, working directly with external auditors. Identity changes ship through technical reviews I author.
The identity side of Claude Code, ChatGPT, Cursor, and Gemini Enterprise: rollout review, access controls, and MCP integration enablement across the SaaS stack. Agents get identities, scopes, and an audit trail. Service accounts authenticate through brokered credentials, checked out from the vault programmatically and returned, never held.
Terraform-managed IAM and project structure, so engineers move AI workloads from prototype to production without creating sprawl.
The surface where everyone works. Hardened, audited, and watched.
A decade of identity work, written the way this audience reads change. Every line is on the .
Okta config lives in Terraform now, not in clicks. Config drift is gone, changes get reviewed like code, and policy stays consistent across the tenant.
A paved road from local prototype to hosted service. Project factories, IAM bindings, and access controls all live in Terraform, so shipping an AI-assisted tool to production is a reviewed change, not a hand-built exception.
Tightening Google Workspace: access policies, DLP, third-party OAuth, audit coverage. The attack surface gets bigger every time someone installs a new AI tool, and that's the part I'm watching.