## TL;DR
This error means Okta never assigned the app to the user, so it stops before ever talking to the app. Check the app's Assignments in Okta Admin: if neither the user nor one of their groups is assigned, that is the whole problem. Assign them (directly or via group), have them sign out and back in, and the tile opens.

## The error
```text
You do not have access to this application.
```

## Steps
1. Confirm the user can reach the Okta dashboard and open other tiles. Expected: the dashboard loads and other apps work. This proves identity is fine and the block is app-level.
2. In Okta Admin go to Applications > the app > Assignments. Check the user or one of their groups is assigned. Expected: an assignment row exists. No assignment produces this error every time.
3. Check the app's sign-on policy and group rules: an app-level policy can deny even assigned users. Expected: the policy evaluates the user as allowed.
4. If assignment is via group, verify the user is actually in the group. Nested groups and rule-based groups can lag or mis-evaluate. Expected: the user is listed in the group membership.
5. Have the user sign out of Okta completely and sign back in, then launch the tile. Expected: the app opens without the error. Cached sessions can hold a stale deny for a few minutes.

## Use this when
- The exact "You do not have access to this application" message appears on an Okta app tile
- One user is denied while colleagues open the same app fine
- The error started after an app reconfiguration or re-import

## Not for this skill when
- SSO succeeded and the app itself shows an access-denied page (the app's own authorization, not Okta)
- The user cant sign into Okta at all (identity problem, not assignment)
- The app tile is missing entirely (different issue: the app may not be assigned or visible)

## Compatibility
- Okta Identity Engine and Classic Engine
- Applies to SAML, OIDC, and SWA app integrations

## Variants
### Everyone in one department gets this, other departments are fine
A group assignment got scoped to the wrong group. Check which group the working departments share and fix the assignment.
### Error appears right after an app reconfiguration
Re-importing or re-saving an app can drop assignments. Re-apply them and retest.

## Why it happens
Okta checks assignment before it ever talks to the app. If no assignment matches the user, directly or through a group, it stops with this error. Group-based assignment with a broken rule, an expired membership, or an app policy that denies is the usual chain.

## Edge cases
- Assignments changed by an automated lifecycle rule: check the rule history before assuming a manual error.
- Deprovisioned-then-rehired users: old assignments may be gone and need re-adding.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_VfLuTVQviMhAKmGDLRpoYg
