Okta lifecycle states and provisioning behavior
This page explains how Okta models account states and how ChartHop settings determine which state a person lands in. Use it as a reference when troubleshooting why an account was created in a different state than expected.
This applies to our Okta 2-way sync, available for HRIS customers.
Okta lifecycle states
Okta has its own state model, separate from ChartHop. Here's what each state means, whether the person can sign in, and how it appears in Okta.
Okta state | What it means | Can the person sign in via SSO? | How it appears in Okta |
|---|---|---|---|
STAGED | Account created, but activation was never started. No email sent, no password set up. | No | INACTIVE |
PROVISIONED | Activation started. Okta sent an activation link to the person. Waiting for them to finish setting up their password. | Not yet | ACTIVE |
ACTIVE | Fully set up, activation complete. | Yes | ACTIVE |
INACTIVE | Deactivated, e.g., after a departure or before a rehire is reactivated. | No | INACTIVE |
Note: PROVISIONED maps to ACTIVE in ChartHop. ChartHop treats "activation started" the same as "active." The distinction between PROVISIONED and ACTIVE lives in Okta, not in ChartHop.
Provisioning behavior by scenario
The table below shows what Okta state results from each combination of person type and app settings. All scenarios are gated by the Sync new hires before start date setting — nothing runs until a person crosses that threshold.
Person type | Settings | Resulting Okta state | Email sent? |
|---|---|---|---|
New hire | Create Okta profiles for new hires = on Send email and activate upon creation = on | PROVISIONED → becomes ACTIVE once the person completes setup | Yes |
New hire | Create Okta profiles for new hires = on Send email and activate upon creation = off | STAGED — account sits here until manually activated | No |
New hire | Create Okta profiles for new hires = off | No account created | — |
Rehire (existing account is INACTIVE) | |||
Rehire | Re-activate Okta profiles for re-hires = on Send email and activate upon creation = on | INACTIVE → ACTIVE (or PROVISIONED if setup wasn't previously completed) | Yes — only if the person is assigned to Okta. Known limitation for preboarding. |
Rehire | Re-activate Okta profiles for re-hires = on Send email and activate upon creation = off | INACTIVE → ACTIVE, silently | No |
Rehire | Re-activate Okta profiles for re-hires = off | Stays INACTIVE | No |
Departure | |||
Departure | De-activate Okta profiles on departures = on | ACTIVE → INACTIVE | No |
Timing gate: Every scenario above only runs once the person crosses the Sync new hires before start date threshold. If an account isn't being created when expected, confirm the person is within that window.
