drop okta system log json · parse authn + admin + policy events
flags impersonation · policy.rule.change · mfa fatigue (push deny→allow) · tor/proxy · admin/policy auth correlation
heuristic screener · extends okta-log-analyzer patterns with deeper policy + admin correlation · export schema varies · not definitive proof