WEBVTT

NOTE Auto-generated from scripts/demo-video/ios-launch-scenes.ts.
NOTE Regenerate with: npx tsx scripts/demo-video/build-ios-launch-voiceover.ts

00:00:00.000 --> 00:00:04.824
This is Butterfly Security for iPhone and iPad, and it's on the App Store today.

00:00:04.824 --> 00:00:16.080
It's a companion to the Okta Admin Console, running on the Okta integration you install from the Okta Integration Network, and the work you used to need a laptop for now fits in your pocket.

00:00:16.080 --> 00:00:23.280
A resilience score out of a hundred with the factors behind it, the last backup, and the week's configuration drift.

00:00:23.280 --> 00:00:27.600
When you're away from your desk, you start by finding the person.

00:00:27.600 --> 00:00:30.829
Suspending someone spells out the consequence first.

00:00:30.829 --> 00:00:37.288
Every change clears two independent checks, and the server enforces both, not the app.

00:00:37.288 --> 00:00:41.440
The first is biometric, Face ID or your passcode.

00:00:41.440 --> 00:00:53.364
Only once that succeeds does the app attach a confirmation header, which the server checks before it parses the body or loads your session, so a replayed session can't even probe it.

00:00:53.364 --> 00:00:55.600
Deactivation wants the email typed exactly.

00:00:55.600 --> 00:01:00.240
Backup history carries status, age, resource counts, and size.

00:01:00.240 --> 00:01:02.011
The second check is capability.

00:01:02.011 --> 00:01:16.183
Every action declares the Okta scope it needs, the server compares that against what your integration actually granted, and a missing scope comes back as a structured refusal naming the scope and the fix, with no round trip to Okta.

00:01:16.183 --> 00:01:20.080
You see it as a lock badge on a disabled button.

00:01:20.080 --> 00:01:27.909
Network zones are the containment story, blocklist zones are marked, and you can activate one from your phone during an incident.

00:01:27.909 --> 00:01:38.720
Both gate decisions land in the audit log, refusals included, and reads are logged too, though reads aren't gated the same way, so a read only connection still works.

00:01:38.720 --> 00:01:44.015
Rate limits sit on top, thirty a minute for changes and sixty for reads.

00:01:44.015 --> 00:01:48.175
The system log gives you severity, event type, actor, and timing.

00:01:48.175 --> 00:01:51.200
Restore preview shows what a recovery would touch.

00:01:51.200 --> 00:02:02.589
Running the restore stays on the desktop on purpose, because a full restore can reach thousands of objects and its safety comes from reviewing the dry run diff on a real screen.

00:02:02.589 --> 00:02:08.640
The assistant answers from indexed runbooks and your own backed up configuration, and cites what it used.

00:02:08.640 --> 00:02:11.631
The executive brief is what you forward to leadership.

00:02:11.631 --> 00:02:20.603
Settings shows the scopes your connection granted, the same list the server checks against, and nothing sensitive stays on the device beyond the session in the keychain.

00:02:20.603 --> 00:02:25.920
It's a free download for iPhone and iPad, and it works with the thirty day trial.
