auditclaw-idpIdentity provider compliance checks for auditclaw-grc. 8 read-only checks across Google Workspace (MFA, admin audit, inactive users, passwords) and Okta (MFA...
Install via ClawdBot CLI:
clawdbot install mailnike/auditclaw-idpGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://www.auditclaw.aiUses known external API (expected, informational)
googleapis.comAudited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
A SaaS company undergoing SOC2 Type II audit needs to demonstrate identity provider compliance. This skill automates evidence collection for Google Workspace and Okta, verifying MFA enforcement, password policies, and user activity to meet access control and security monitoring requirements.
A healthcare organization using Google Workspace or Okta must comply with HIPAA security rules. The skill checks for strong password policies, MFA on all accounts, and inactive user management to ensure protected health information (PHI) is accessed only by authorized, active personnel.
A financial institution subject to regulations like GLBA or FFIEC guidelines uses this skill to audit identity providers. It validates session timeouts, password strength, and admin account security to prevent unauthorized access and meet stringent financial compliance standards.
A large enterprise rolling out MFA across Google Workspace or Okta needs to verify enforcement. This skill scans all active users to ensure MFA enrollment, identifying non-compliant accounts for remediation and providing automated evidence of security posture improvement.
An organization seeking ISO 27001 certification uses the skill to gather evidence for identity management controls. It checks password policies, inactive user cleanup, and admin audit trails, automating documentation for Annex A controls related to access management and user accountability.
A consultancy offers ongoing compliance monitoring using this skill to automate evidence collection for clients. They integrate it into audit workflows, charging subscription fees for regular sweeps and reports that demonstrate adherence to SOC2, HIPAA, or ISO standards.
An MSSP bundles this skill into their security offerings to monitor client identity providers. They use it for proactive threat detection, such as identifying weak passwords or inactive accounts, and upsell remediation services based on findings.
Large enterprises adopt the skill internally to streamline audit processes. It reduces manual effort for IT and compliance teams, saving costs on external audits and enabling continuous monitoring, with value derived from operational efficiency and risk reduction.
💬 Integration Tip
Ensure auditclaw-grc is installed first and environment variables are set correctly for each provider; use the test-connection command to verify setup before running full sweeps.
Scored Apr 19, 2026
Self-hosted auth for TypeScript/Cloudflare Workers with social auth, 2FA, passkeys, organizations, RBAC, and 15+ plugins. Requires Drizzle ORM or Kysely for D1 (no direct adapter). Self-hosted alternative to Clerk/Auth.js. Use when: self-hosting auth on D1, building OAuth provider, multi-tenant SaaS, or troubleshooting D1 adapter errors, session caching, rate limits, Expo crashes, additionalFields bugs.
Clerk integration. Manage Users, Organizations. Use when the user wants to interact with Clerk data.
Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP outages), and component reference. Prevents 15 documented errors. Use when: API keys for users/orgs, Next.js 16 middleware filename, troubleshooting JWKS/CSRF/JWT/token-type-mismatch errors, webhook verification, user type inconsistencies, or testing with 424242 OTP.
OAuth for the agentic era. Consent-gating for ALL sensitive agent actions. 75+ data-driven threat definitions with auto-updates (like antivirus signatures)....
Configures Firebase Authentication — providers, security rules, custom claims, and React auth hooks
Manages consent with strict safety limits, prohibits profiling or coercion, limits crisis inference, and ensures autonomy without persistent tracking or pres...