November 2025 Summaries
4 posts from Veza
Filter
Month:
Year:
Post Summaries
Back to Blog
Veza's closed-loop remediation system for access reviews ensures that decisions made during the review process translate into actionable outcomes, focusing on revocation, remediation, and reconciliation. The Veza platform automates the process where reviewer decisions trigger actions, ensuring that rejected access is promptly revoked and verified through mechanisms like Auto-Revocation and Auto-Validation. These features remove and validate rejected access, providing auditors with clear evidence of compliance. Veza Actions further enhance this by operationalizing reviewer decisions, enabling real-time enforcement across various systems through notifications, workflow integrations, and custom actions. Reconciliation ensures the accuracy of access data and aligns system states with reviewer decisions, which is crucial for audit readiness and compliance with standards like SOX and SOC. The system's closed-loop approach not only mitigates risks and reduces manual workloads but also strengthens the organization's compliance posture by providing reliable audit evidence and ensuring the integrity of user access reviews.
Nov 24, 2025
1,996 words in the original blog post.
Veza Access Reviews offer a robust framework for managing and validating access rights across an organization's applications, systems, and resources, focusing on maintaining least privilege and ensuring compliance with standards like SOX, GDPR, and HIPAA. The platform accommodates various user personas, each with distinct roles, such as access review program managers, assigned reviewers, coordinators, auditors, and application owners, who collectively contribute to the success of access review campaigns by ensuring that policies are turned into enforceable controls. Veza's access control model is two-dimensional, regulating both visibility and operational actions through user roles and permission-based controls, supplemented by features like Veza Groups for scalable management and the Limit Access list for flexible campaign scoping. These features enable organizations to efficiently enforce security and compliance requirements by providing granular, role-based access controls tailored to diverse organizational structures and needs.
Nov 17, 2025
2,183 words in the original blog post.
The text discusses the challenges and solutions related to managing access authorization in modern enterprises, emphasizing the limitations of traditional calendar-based access recertification campaigns, which often leave security gaps due to their infrequency and labor-intensive nature. It introduces on-demand access reviews, also known as micro-certifications, as a more dynamic and risk-based approach to access governance. These reviews are initiated by specific security incidents or user mobility events, allowing organizations to address access issues in real-time rather than waiting for the next scheduled review. The Veza platform facilitates this process by creating triggers for on-demand reviews through its Access Intelligence and Lifecycle Management tools, ensuring that access is evaluated precisely when necessary. By adopting this methodology, organizations can maintain a continuous and proactive approach to identity governance, moving away from compliance-driven strategies to more effective, risk-based management.
Nov 07, 2025
2,060 words in the original blog post.
Veza's September 2025 Product Update introduces significant advancements in Identity Security, focusing on non-human identity (NHI) security, AI Governance, and enhanced automation for Identity Governance and Administration (IGA) needs. The update includes improvements in lifecycle management, such as supporting secondary identity sources, SCIM for custom applications, and OAuth2 SCIM authentication, which bolster automation for user provisioning and deprovisioning. Operational usability is enhanced with Slackbot notifications for access reviews, predefined question sets for consistent decision documentation, and persistent reviewer settings. In terms of NHI security, the update enhances credential discovery capabilities, including Okta OAuth tokens, Azure Key Vault monitoring, and certificate-based authentication across multi-cloud environments. Risk intelligence is improved with advanced query management, enabling security teams to move efficiently from discovery to remediation. The update also highlights AI-driven enhancements, such as Access AI explanations for complex queries, enhanced query management UX, and monthly query export scheduling. Comprehensive improvements in access security, visibility, and query management are complemented by advanced graph controls and agentic user visualization, making it easier to manage both human and machine identities. Enhanced policy management features include improved access profiles usability, native attribute mapping, and support for custom IDP identity mapping, while integration support extends to platforms like Azure, AWS, GitLab, and Oracle, enhancing overall enterprise security and governance capabilities.
Nov 04, 2025
2,966 words in the original blog post.