Home / Companies / Veza / Blog / January 2026

January 2026 Summaries

7 posts from Veza

Filter
Month: Year:
Post Summaries Back to Blog
Veza's latest product update addresses the expanding identity risks associated with AI infrastructure and automation, extending visibility and control across cloud platforms. The release includes enhanced coverage for Google Cloud Vertex AI, improved lifecycle management with Azure AD integration, and streamlined access review workflows, enabling security teams to manage access and identity lifecycle operations more effectively. Key features include new APIs for access review exports and dynamic user filtering, support for OAuth2 in REST actions, and enhanced non-human identity (NHI) security through integrations with services like GitLab and Okta. The update also introduces better visualization tools for AWS IAM roles, expanded integration capabilities with platforms like CockroachDB Cloud and Databricks, and usability improvements across various interfaces, all aimed at reducing manual effort, improving auditability, and ensuring robust security measures in complex environments.
Jan 28, 2026 2,702 words in the original blog post.
Veza and ServiceNow have developed an integration that streamlines access requests by combining Veza’s Identity Authorization Platform with ServiceNow’s IT Service Management capabilities, creating a seamless workflow for automating access requests while maintaining governance standards. This integration allows users to request access to multiple resources through a familiar catalog interface in ServiceNow, and managers can approve requests with one click, ensuring automatic provisioning and a complete audit trail. The system is built on five key components: the ServiceNow Service Catalog Order Guide, a VezaAPI Script Include, business rules for managing approvals and workflow transitions, the Veza Platform as the source of truth for access profiles, and a Scheduled Catalog Sync to keep the ServiceNow catalog updated. The user journey from request to provisioning involves steps such as manager approval, optional IT review, admin approval for high-privilege access, and automatic provisioning, all designed to reduce manual intervention and speed up the process. The integration employs best practices like using ServiceNow’s native Order Guide feature to simplify the process, real-time API calls to Veza for up-to-date identity management, and a single approval business rule to avoid duplicates. Challenges such as duplicate approvals and variable access were overcome through strategic design decisions, and the implementation is designed to be maintainable and easily understandable for future developers. Overall, this integration enhances efficiency, reduces friction, ensures governance, and increases the agility and security of the organization’s access management process.
Jan 26, 2026 2,694 words in the original blog post.
Mergers, acquisitions, and divestitures present significant challenges in identity management, creating complexities and risks due to fragmented identity systems and unmanaged non-human identities. Traditional Identity Governance and Administration (IGA) tools struggle to provide the necessary visibility and management of identities across disparate systems, particularly during rapid organizational changes. Veza offers a solution by providing a unified view of identities through its Access Graph, enabling organizations to effectively manage human and non-human identities, automate onboarding and offboarding, and ensure compliance during these transitions. Veza's platform is designed to address the gaps left by legacy tools, offering permission-level visibility, fast integration, and comprehensive identity security across cloud and on-premise systems, thereby reducing risks and meeting regulatory requirements efficiently. By supporting the full lifecycle of M&A activities, Veza helps organizations maintain secure and manageable identity infrastructures, even amidst the complexity of merging or separating entities.
Jan 26, 2026 2,157 words in the original blog post.
Veza has been highlighted as a notable vendor in Forrester's latest report on Workforce Identity Security Platforms, emphasizing the growing importance of managing workforce identities in an increasingly complex enterprise environment. As identity security becomes the primary enterprise risk, these platforms offer a unified approach to governing and securing identities, crucially including not just employees but also contractors, partners, applications, and AI agents. The platforms integrate identity and access management capabilities with advanced analytics and AI-driven intelligence to provide comprehensive visibility and control over identity landscapes, addressing the explosion of identities due to cloud adoption and SaaS applications. Forrester's report guides organizations in selecting suitable platforms by clarifying necessary capabilities and highlighting vendor differentiation, with Veza recognized for its strengths in Identity Governance, Identity Security and Posture Management, and Machine and AI Identity Management. This recognition follows Veza's significant growth in 2025, marked by the launch of innovative products and being named a leader in multiple industry reports, highlighting its commitment to securing the full spectrum of identities and achieving least privilege at scale.
Jan 15, 2026 962 words in the original blog post.
In 2025, Veza Access Platform made significant advancements for its customers by introducing a range of new features and capabilities aimed at enhancing permission-level visibility and achieving least privilege across applications and systems. The platform expanded its integrations with over 325 out-of-the-box options, including major systems like AWS, Google, and Microsoft, thus facilitating faster onboarding without custom work. New generic integration methods and expanded attributes were introduced to enrich identity context and improve risk detection and remediation. User experience improvements included AI-powered queries, universal search, and a new design system for better usability. In identity governance, Veza launched Access AuthZ for automated access provisioning across various applications and introduced major improvements in risk-based reviews with new algorithms and auto-revocation features. Notifications and alerts were enhanced with Slack and Microsoft Teams integrations, while reporting capabilities were boosted with new Excel-based reports. The introduction of Just-in-Time access policies and cross-application Separation of Duties violation detection further strengthened security measures. Veza also addressed operationalization needs with updated risk engines, activity monitoring for BigQuery and Azure, and intelligent role engineering, while next-generation identity access for Non-Human Identities (NHI) and AI governance was redefined with new solutions and enhanced discovery and integration features.
Jan 11, 2026 1,568 words in the original blog post.
Veza's Risk 2.0 introduces an advanced approach to managing identity security by transforming risk signals into actionable outcomes with a focus on prioritization and operational efficiency. As organizations scale, the challenge shifts from visibility to effectively prioritizing and remediating high-priority risks across cloud, SaaS, and non-human identities. Risk 2.0 incorporates an updated risk scoring system and the introduction of the Veza Risk Framework and a New Risks Page, which serve as a unified dashboard for Identity Security Posture Management (ISPM). This framework categorizes identity risks into seven core Risk Profiles, allowing teams to consistently classify and prioritize risks by domain, rather than by tool or integration. The evolved risk scoring engine uses a logarithmic model to prevent score inflation and maintain meaningful differentiation between normal risk exposure and true outliers. These enhancements enable security teams to make informed decisions quickly, prioritize remediation efforts, and track risk posture trends over time, ultimately helping to reduce exposure and streamline compliance. The new features are available as Early Access for customers, with the risk scores having been generally available since November 2025.
Jan 07, 2026 1,624 words in the original blog post.
Identity management has evolved from being a background administrative function to a central element in enterprise risk, operational trust, and AI governance. The traditional approaches to identity security and governance are inadequate for modern needs, as the focus shifts from users and groups to permissions and entitlements, necessitating a new emphasis on securing and governing authorization at scale. Identity now serves as the enterprise control plane, with micro-certifications transforming trust units from users to permissions and promoting continuous justification over periodic reviews. As AI governance becomes more prevalent, it highlights existing issues like over-permissioning and fragmented visibility, prompting a need for systems that offer clear, real-time insights into access and exposure without requiring specialized expertise. This shift requires embracing graph architectures and relational contexts to define risk more accurately, with a focus on building trust incrementally through real products that deliver value.
Jan 06, 2026 722 words in the original blog post.