NEWFreshservice is now a Ploy integrationSee what shipped

CHANGELOG

Everything we shipped

Every Ploy release, newest first.

  1. 2026
    IMPROVED

    Luna generated flows

    Luna can now help you build and generate flows for you automatically, simply describe what you want and watch Luna build it for you.

    Luna has access to all the tools and learnings from the 1000s of flows we’ve implemented at Ploy to ensure you get the most optimised outcome, tailored to your use case (as always). This is a beta feature so as always, we’d love to get any and all feedback you have.

  2. 2026

    On-call access conditions, Redis Cloud & more

    A wide release across access policies, integrations, flows, and the employee portal:

    • Access conditions: On-call status is now available as an access condition, automatically revoking break-glass access once a shift ends.

    • Active Access: You can now mark a stuck access row as deprovisioned, from the row menu or in bulk, without Ploy contacting the provider.

    • Redis Cloud: New integration for Redis Cloud, syncing team members and roles so you can review and revoke access alongside your other apps.

    • Flows: The "Update user in integration" action can now write to your organization's custom Google Workspace profile fields, picked from a live dropdown.

    • Luna: Steering chat on an in-progress agent run now accepts file attachments, and mentions in Luna chat now render as chips with a photo or app icon.

    • Employee portal: Time-limited access requests show clearer countdown text near expiry, and resources offered through multiple catalogs now show as already covered once requested.

  3. 2026
    NEWIMPROVED

    Mid August update

    A big three-week stretch: a full pass on access reviews, Luna picking up provisioning and policy work, five new integrations, and a new terminal sign-in flow.

    Access Reviews

    • Per-app reviews: A new Reviews tab lists one row per single-app review campaign — resource, frequency, progress, and due state at a glance — built for teams running lots of one-off reviews rather than a single big multi-app campaign.

    • Reviewer overrides: Route specific accounts (non-human identities, admin-level entitlements) to a different reviewer than the campaign default; the first matching rule wins.

    • Self-approval control: Approval steps now have an "Allow self-approval" switch so the person a request is for can be excluded from approving it themselves (off by default on new steps).

    • Self-review prevention: Reviewers can no longer be assigned to approve their own access. Conflicts are blocked at cycle creation with a clear message, or rerouted at runtime to the account holder's manager, the resource owner, or an org admin. Bulk decisions silently skip a reviewer's own accounts and note how many were excluded. Opt out per-cycle with "allow self-review."

    • Duplicate identities: Reviewers see one row per person instead of duplicates when someone holds more than one identity on a resource; campaign creation flags duplicates up front.

    • Exclude from a cycle: Exclude a review or a specific account from an in-progress cycle, with a required reason captured in the audit trail.

    • Escalation attribution: Decisions completed by an escalated reviewer now show an "Escalated" tag with a handoff tooltip, carried through to the evidence pack.

    • Data freshness: Review details show a "Data as of" date, source, and extraction date for imported access data.

    • Custom remediation routing: The "adjust entitlements" outcome can route to a dedicated flow configured on a resource's provisioning strategy instead of always creating an internal task.

    • Mid-cycle additions: Add resources to a review cycle that's already running, right from the cycle page — no need to wait for the next cycle. Luna can do this on request too.

    • Corrections toggle: Campaigns can now disable reviewer corrections entirely — useful for campaigns fed by integrations or controlled uploads.

    • Escalation tiers: Tiers can fire before the due date (e.g., "3 days before due"), each tier can carry its own custom message, and a new no-response tier action auto-closes undecided accounts on deadline and applies the campaign's configured remediation.

    • Evidence pack certificates now display your organization's logo.

    Luna

    • Knows which admin sent each message in shared sessions, improving responses when multiple admins message Luna in one conversation.

    • Can read a resource's current access policy and apply bulk updates across many resources at once.

    • Can answer a reviewer's question directly when they flag an item instead of approving/denying, unblocking the review without an admin.

    • Confirmation cards now group related settings and show real dropdowns (e.g., seat type) instead of leaving them unset.

    • New "Setup new integration" playbook walks Luna through connecting and configuring an integration end to end.

    • After connecting a new integration, Luna checks if it supports account creation/removal and offers to build provisioning/deprovisioning flows, a provisioning strategy, managed access, and a catalog entry (new flows are created disabled for review).

    • New guided onboarding playbook for admins covering org settings, SSO, IP restrictions, notifications, and app connections.

    • Can create new custom employee fields on request (e.g., a cost centre), not just fill in existing ones.

    • Can update access review campaign settings and manage standing cover assignments from chat.

    • Can report the provisioning method assigned to each access catalog entry and flag entries with none configured.

    • New Memories section: explore what Luna knows about your org as a graph or filterable list (grouped by fact/episode/procedure/preference), with the ability to add or delete your own entries.

    Provisioning & Flow Builder

    • Provisioning strategies can name a flow that auto-creates a missing account when a request is approved, instead of failing with an identity error.

    • New "Create Resource" flow action creates a resource inside a connected integration (starting with Microsoft Entra security/M365 groups) — chainable straight into a grant-access step.

    • "Get resource access" now outputs both a resource's friendly display name and its full name in one flow.

    • New licence-availability gate step: branch flows based on whether a licence has free seats.

    • Alchemer users can now be created, disabled, or updated directly from flows.

    • Scheduled flow triggers can be pinned to a timezone with automatic daylight-saving handling.

    Integrations

    • Simployer One (HRIS) — new integration syncing your full employee roster for onboarding, offboarding, and provisioning.

    • Attio, Datadog, ngrok, Vercel, and Xero are now available to connect, alongside a new capabilities view in the setup wizard and integrations table showing what each integration can detect and action.

    • Google Workspace: custom member fields now appear in the field mapper and sync into Ploy (matching HiBob, Okta, Workday).

    • Google Drive: shared drives now show their organisational unit (name and path), captured automatically during scans.

    • Freshservice: flow ticket labels now sync as native tags; the Update ticket step supports setting closure fields.

    • Jira: can now connect via a service-account API token instead of OAuth for tighter least-privilege access.

    • Microsoft Entra (bring-your-own setup): scan-scope settings (users without mailboxes, guests, apps without a website) are now configurable, matching the Ploy-managed flow.

    • Dialpad is now available as an offboarding flow action.

    Security & Access Control

    • Terminal sign-in approval: Employees can approve or deny Ploy CLI sign-in requests from the employee portal by entering the short code shown in their terminal, reviewing the origin address, client, and timestamp. Approved sessions stay valid up to 30 days.

    • Passkey elevation: Require a fresh passkey check before sensitive actions (offboarding, API key creation, security changes), with a configurable re-verification window. The elevation settings page lists which admins still need a passkey, and a key icon flags who already has one.

    Employee Portal & Admin UX

    • Choose which sections (Home, My Access, Reviews, Tasks, Catalog) appear in the employee portal — useful for a reviews-only rollout.

    • Assignment Configuration moved to its own Settings page, with a new Issues tab (offboarded assignees, incomplete configs) and a usage view showing where a configuration is referenced.

    • Standing reviewer swaps can carry an optional expiry date, so temporary reassignments (e.g., parental leave) end automatically.

    • Resource access records show a new Story timeline plus Field origins, surfacing which integration last confirmed each piece of data and when.

    • Notifications to Slack, Teams, and email (including from Luna) now render headings, lists, tables, and images properly instead of raw formatting characters.

    • Identity Inventory gained bulk actions to associate/remove employee links, matching the older Identities list.

    • Shift-click range selection now works across every dashboard table.

    • Saved private resource views show a "Private" badge, with an edit button for name, icon, colour, and visibility.

    Billing & API

    • App Spend billing frequency now includes "Biannually" (every 6 months), with annual cost projections updating automatically.

    • Identity segments API's update endpoint is now full-replace (omitted fields are cleared); duplicate segment names return a clear conflict response.

  4. 2026
    NEWIMPROVED

    Luna Memory

    Ploy now connects to Alchemer and ships improvements across employee profiles, access reviews, Segments, and Luna.

    • Alchemer: Ploy now scans your Alchemer account for users, teams, and licence seats and supports provisioning and deprovisioning directly from Ploy.

    • DocuSign: You can now provision and deprovision users directly from Ploy, and manage their group memberships. Invite someone by email (DocuSign sends them an activation link), close their account to revoke all access, or move them between groups, all without leaving Ploy.

    • Luna: Luna now has a separate read permission. Grant it to colleagues who need to browse and read existing chats without being able to start new sessions or send messages. The message composer stays hidden for read-only users.

    • Employee Resources: The Resources tab on an employee's profile now has a Dynamic membership filter. Use it to isolate groups where membership is controlled automatically by rules in Microsoft or Okta, or hide those groups to focus on manually-managed access.

    • Licence availability check: A new gate step in the flow builder lets you branch based on whether a specific licence has free seats. Choose a resource and one of its licences, set the direction (available or not), and the step passes current seat counts to downstream steps for end-to-end seat-rotation flows.

    • Range selection: Hold Shift and click a second row to select everything in between, across every table in the dashboard.

    • Saved resource views: Private saved views in Resources now show a "Private" badge. An edit button lets you update a view's name, icon, colour, or visibility at any time after saving.

  5. 2026
    NEW

    Terraform, OneLogin integration & Luna Tools

    Last week's release adds a full OneLogin integration, richer Luna responses and tools, and improvements across access reviews and the app catalog.

    • OneLogin: Ploy now integrates with OneLogin as a full IdP. Connect your tenant to pull in users, MFA enrollment and methods, roles, and app assignments, plus last sign-in activity. Open the Integrations page to get started.

    • Luna: Responses now render tables, cards, and structured blocks directly in the chat, at their natural position in the conversation, instead of inside collapsed thinking steps. The underlying model has also been upgraded for sharper, more reliable answers.

    • Access reviews: Reviewers in the employee portal now land on the full entitlements list by default when opening a review, with Luna's recommendations one click away via a tab at the top.

    • Agent actions: Luna agents can now suspend and restore user accounts at connected integrations as part of automated workflows, with confirmation required before each action and every suspension recorded in the audit trail.

    • Catalog search: The app catalog in the browser extension now matches underlying resources when searching, so "billing" surfaces the AWS tile via its Billing resource, with a hint showing what matched.

    • Assignment configs API: Reviewer routing rules can now be created, updated, and deleted via the public API, making them straightforward to manage from external tooling.

    • Escalation notifications: Escalation message wording can now be customised for access reviews. Open the escalation editor and choose "Customise the message" to edit the notification template that reaches reviewers at each stage and save it for reuse.

    • Access reviews: Reviewers in the employee portal now see department, job title, and last-active date columns switched on by default, so relevant context is visible without manually enabling columns.

    • Flows: You can now filter Microsoft and Entra accounts by guest status in flows, making it straightforward to target low-usage guest accounts for automated action.

    • Luna: Luna can now find failed or stalled access-request provisioning and retry it on demand, completing the full lifecycle from approval through to recovery.

    • App catalog: Employees browsing the app catalog now see a badge on any app they already have access to, preventing accidental duplicate requests.

    • Public API: New endpoints let you read and manage provisioning strategies and their folders via a dedicated API scope, and manage resource sources of truth per row via the API.

    • Luna: CSV imports, Luna can now preview what a CSV mapping will produce before you run it, showing which rows will import, merge, or be skipped and why. Ask Luna to load a saved import template or save the current mapping for reuse in later imports.

    • Luna: catalog management, Luna can now archive a catalog item so employees no longer see it in their access catalog, and permanently delete an access policy that is no longer needed.

    • Terraform and Public API improvements: You can now configure your core Ploy resources via Terraform. Contact your account rep to get access to the provider

      • Access catalogs in the API, Create, update, publish, and archive access catalogs and their items from Terraform or your own tooling, including visibility rules by department, group, or profile, and the access options offered within each item.

      • Resource access policies in the API, A resource's full access policy (approval stages, time limits, provisioning setup, and eligibility conditions) can now be defined and managed from infrastructure-as-code.

      • Organisation settings in the API, Internal email domains and IP restrictions for the admin dashboard and employee portal are now manageable via the API, making them part of your version-controlled configuration.

  6. 2026
    NEWIMPROVED

    Freshservice integration

    Ploy now connects to Freshservice for ticketing, plus a range of other improvements.

    • Freshservice Ticketing integration: You can now integrate with Freshservice as your ticketing system, helping you manage access requests and other identity related issues in your native ITSM, or use it as a centralised backup for identity related work.

    • API key management: Existing keys can now be edited (rename or change permissions) without revoking them. Scope options are grouped by category in the picker.

    • Tags API: Create, update, and delete tags via the Ploy API using a key with tags permissions.

    • Access review scoping: Campaigns can now be scoped to access rows carrying a specific tag, not just tags on the employee or resource.

    • Luna: Luna can now draw on Ploy's accumulated knowledge about your environment when answering questions.

    • User importer: Human identities can now be imported using an external ID alone, without an email address.

    • Employee page: "Last Working Day" is now available as a column in the custom view picker.

    • Profiles in the public API: create, read, update, and delete profiles via the API, with the full filter definition included.

    • Resource and integration lookups: the resources endpoint now accepts exact-match filters by name, external ID, domain, and application status; new read-only endpoints for integrations and messaging channels are also available.

    • Jira knowledge source, service-account auth: when setting up Jira as a knowledge source, you can now choose between OAuth and a service-account API token scoped to specific projects, so Ploy can only read what that account can access.

    • Signup source on active access: the origin of a shadow-IT signup, captured by the browser extension, now stays visible after access moves to the active tab, so you can always trace how it started.

    • API docs: nested object schemas now expand inline, and the navigation panel scrolls independently of the content panes.

  7. 2026
    NEW

    Access review updates & More

    A large set of updates shipped the last few days headlined by our changes to access reviews.

    Access reviews:

    • Multi-stage reviews: You can now have multiple stages of reviews, on all or a subset of entitlements allowing support for usecases such as ‘Managers revieiwing employee access’ followed by an SME reviewing admin only roles

    • Escalation paths: Automatically re-assign reviews if users don’t complete in X days or notify their manager

    • Extension Requests: Users can request an extension if they need more time

    • Queries: Reviewers can also make queries, such as clarifying questions to your IT admins while completing reviews.

    And a lot more

    • Bulk retry provisioning: Filter the access request list by status, select failed requests, and retry their provisioning in one action.

    • Tag management: Create, edit, and color-code tags from the Settings page. Assignment configurations can now be deleted directly from the configuration modal.

    • Tasks: Filter the unified Tasks list by app or resource.

    • User importer: Human accounts can now be imported using an Ext ID alone, without an email address.

    • Identities: Bulk convert human identities to non-human identities from the Inventory page.

  8. 2026
    NEW

    SIEM integrations, Microsoft AI agents & more

    You can now stream your Ploy audit log to an external SIEM, with Microsoft Sentinel as the first destination.

    • SIEM integrations: Connect from the new SIEM tab on the Integrations page. The wizard uses federated identity credentials so no client secrets are stored.

    • AI agent visibility: Ploy now tracks Copilot and Claude agents, so you can see which are active, who is using them, and what resources they reach on behalf of users.

    • HiBob: Mobile and work phone numbers now sync from HiBob for use in flows and automations.

    • Agent access view: The access-on-behalf-of panel on an agent page now groups entries by permission, with stacked member avatars replacing one row per individual account.

    • Employee portal: Employees outside an approved IP range now see a clear screen directing them to connect via VPN or contact IT, instead of a generic error.

  9. 2026
    NEW

    IP restrictions, custom employee fields in flows & more

    Four improvements shipped today covering security, automation, access management, and the Luna experience.

    • IP restrictions: You can now limit which networks can reach Ploy. In Settings > Authentication, configure separate IP allowlists for the admin dashboard and for the employee portal and browser extension. Leave a list empty for no restriction, and a warning flags if a saved range would lock you out of the dashboard.

    • Custom fields in flows: Custom employee fields now appear as audience filter options and as a flow trigger, so you can build flows that target or activate based on fields specific to your org, like a cost center or contract type.

    • Expiring Soon: The Managed Access > Expiring Soon page now has per-row Manage access and Deprovision access buttons, plus a bulk deprovision option when you select multiple entries, so you can act without opening the resource page first.

    • Luna and agent runs: The Luna indicator is now animated across the sidebar, chat, and agent pages, reflecting live state. On the agent runs page, task cards expand inline to show session detail, and the runs navigator is now called Active Runs.

  10. 2026
    IMPROVED

    On-call status, Google guest invitations & more

    You can now see on-call status in employee profiles, delete Entra accounts and Exchange shared mailboxes from flows, and import users in update-only mode.

    • On-call status: Employee profiles now show whether someone is currently on call, pulled from your Grafana IRM or PagerDuty connection. A green badge marks an active shift; the row only appears for members on a rota. "Is on call" is also available as a filter when building segments.

    • Entra and Exchange deletion in flows: A new "Delete shared mailbox" step is available in the flow builder for removing Exchange shared mailboxes. The "Remove user from integration" step now also supports deleting an Entra account directly.

    • User import update-only mode: When importing users via CSV, you can turn on "Only update existing users" at the mapping step. Existing records are refreshed in place; rows that don't match anyone are skipped, nothing new is created, and the grant date and identity type become optional.

    • Google Workspace: The invite-external-user flow action now supports Google Workspace alongside the existing Microsoft support. Guests are automatically detected in scans and attributed to their real external email address.

    • Unmanaged accounts: You can now select multiple accounts on the Unmanaged tab and convert them to non-human identities in bulk, rather than one at a time.

    • Low usage detection: When previewing how many accounts a low-usage threshold would flag on a resource, you can now click "View accounts" to see the full list, each account's last activity date, and when access was first granted.

  11. 2026

    Identity-aware access requests, user importer & more

    Users can now select which of their identity they are making the request for when making an access request as well as making requests on behalf of owned NHISs, alongside other improvements across the user importer, Google Drive, and the access catalog editor.

    • Access requests: Employees can pick which account or service account they own gets the grant, per resource. People with multiple accounts on the same integration, or who own service accounts, see a dropdown on each item in the request basket. Admins see "Requested by" and "Requested for" as separate rows in the request detail panel.

    • User importer: Both the column-mapping dropdown and the person-preview picker now have a type-to-filter search box. A new "Apply to more columns" option copies one column's mapping to several others at once, and a "Use column name as type" checkbox auto-fills the entitlement type from the mapped column name.

    • Google Drive: Shared drives now show the org unit they belong to as a resource attribute. Luna can filter drives by org unit when answering questions about specific areas of your Drive environment.

    • Access catalogs: The catalog editor now has a "View in portal" button that opens the catalog directly in the employee portal, so you can preview exactly what employees see.

    • On-call status: Employee profiles now show whether someone is currently on call, pulled from your Grafana IRM or PagerDuty connection. A green badge marks an active shift; the row only appears for members on a rota. "Is on call" is also available as a filter when building segments.

    • Entra and Exchange deletion in flows: A new "Delete shared mailbox" step is available in the flow builder for removing Exchange shared mailboxes. The "Remove user from integration" step now also supports deleting an Entra account directly.

  12. 2026
    NEWIMPROVED

    AI agent governance, Custom Employee fields and Luna agents v2

    A lot has changed over the past couple of days here at Ploy. Let’s dive in.

    • AI agents: AI agents (Copilot Studio, custom GPTs, and others) now have dedicated resource pages in the admin dashboard. Each shows the platform the agent runs on, its direct app permissions, delegated access held on behalf of users, who is using it, and a visual access graph. To get access please contact your account manager

    • Microsoft own-app setup: When connecting Microsoft, you can now use your own Entra app registration instead of Ploy's managed app. A setup wizard covers capability selection, the app manifest, and the Azure configuration values, with a toggle to enable or disable all optional permissions at once.

    • Luna: Reports can now filter apps by tag dynamically, so querying for "procured" apps (or any other tag) always reflects the current tagged set rather than a stale list.

    • Edge on Mac: A deployment profile for Edge on Mac is now available, letting admins push the Ploy extension to managed Mac devices running Microsoft Edge.

    • Custom employee fields: Define custom fields for employee profiles from the Employee Fields settings page, pick from text, number, date, select, or yes/no types, and connect each to HiBob, Okta, or another integration so values sync automatically. Fields appear in a dedicated section on every employee profile.

    • Agent runs and success criteria: Agent detail pages now show a success scorecard for each defined criterion, a run history with declared outcomes and confidence level, and a full activity timeline. Non-human identities can also now submit access requests using dedicated API keys, which appear in the standard review queue.

    • Multi-file app fields: App custom fields can now hold multiple files, letting you attach several contracts or documents to a single field without overwriting previous uploads.

    • Integrations: BrowserStack service accounts now appear as non-human identities in Ploy. DigiCert now captures last-login dates for usage tracking. Microsoft enterprise app service principals now show the application permissions they hold. AWS classic IAM group memberships can now be provisioned directly.

    • Access policies: You can now delete an access policy directly from the resource detail view or the managed resources table. Ploy checks for active access reviews and open requests first and blocks deletion until those are resolved.

    • Flows: Yes/No confirmation steps now support a "No response" path. Set a timeout in minutes, hours, or days, and your flow continues automatically if the recipient never clicks Yes or No.

    • Microsoft guest accounts: Ploy now shows the sponsor for each Microsoft Entra B2B guest, the person in your organisation responsible for that account. Their name and email appear on the guest's identity record, and Luna can reach out to them when a guest account goes dormant.

    • Custom integration logos: When configuring a custom integration, you can now search Ploy's app logo library and pick a matching logo. It then appears consistently across cards, resource rows, and graphs.

  13. 2026
    NEW

    Jira sub-tasks, Luna attachments & more

    Ploy shipped two new capabilities today alongside several reliability fixes.

    • Jira sub-tasks: Using flows you can now create Jira sub-tasks

    • Luna file attachments: Employees chatting with Luna in the employee portal can now attach files alongside their messages. PDFs, spreadsheets, Word documents, images, and CSVs are all supported, up to 4.5 MB per file.

    • CSV entitlement sync: Update-only imports now replace a member's full set of entitlements rather than only appending new ones, so stale access is removed automatically on each re-run.

  14. 2026
    NEWIMPROVED

    Last week at Ploy

    There’s been a lot shipped in Ploy over the last 7 days, let’s dive in ⬇️

    • Luna access requests: Requesting access for shorter windows, such as a few hours, now works correctly when chatting with Luna in Slack or Teams.

    • OneTrust: Login activity now flows into Ploy when the required permission is enabled in OneTrust, so you can see who is actively signing in alongside your full user directory.

    • Employee profile: The Resources tab now shows a Type column and lets you filter by resource type or integration, making it easier to review what kind of access an employee holds.

    • User importer: Ignore Rows now supports additional matching conditions, including "contains", "is one of", "is set", and "is not set", so you can filter rows without pre-processing your CSV.

    • Okta: Fixed a scan issue where the event log could stall on empty filtered time windows, causing outdated events to replay on every scan cycle.

    • Compliance segment templates: You can now create segments from pre-built compliance-framework templates. On the Segments page, choose "Create from compliance framework" to browse templates mapped to SOC 2, ISO 27001, CIS Controls, and more, with Google and Microsoft vendor packs included. Each card shows a live match count for your org. Select any number and bulk-create them in one click, or customize one before saving.

    • Claude.ai seat tracking: The Anthropic integration now shows a seat licence view: purchased vs active seats, cost per seat (defaulting to $20 if left blank), and a savings breakdown by usage tier. Set a minimum daily token threshold to define what counts as active for your org.

    • Access request notifications: The Managed Access "Notifications" tab (previously "Config") now surfaces opt-in notification types, including a new option to notify your team when a request is submitted.

    • New Relic: Ploy can now create and remove users and manage group membership in New Relic, making it a fully managed integration.

    • TestRail: Create and remove users, manage project access, and search your user base from Luna.

    • Confluent: Ploy can now invite users and search for existing users in Confluent.

    • GitLab: Bulk user search is now available across your configured groups and organisations.

    • Team member permissions: Granting access directly (outside of an approval policy) is now a separate, opt-in permission. Standard seats no longer have it by default; enable it per person in the permissions editor.

    • HiBob: Custom fields with human-readable names now sync into Ploy correctly.

    • Exchange: The setup wizard no longer requires you to grant Ploy the Exchange Administrator role. It now displays a PowerShell script you fill in with your Entra Object ID and copy straight to your terminal, giving Ploy only the permissions it actually needs.

    • Luna: You can now ask Luna to find identities by a specific MFA method, such as everyone who authenticates by SMS or passkey, rather than just checking whether MFA is on or off.

    • Low-usage trigger testing: The member field when testing a Low Usage flow trigger is now optional. Leave it blank and Ploy returns the full list of members who would trigger for that app, so you can validate the trigger at a glance without picking a specific person.

    • Saved CSV import mappings: You can now save a column-mapping configuration during a user import, name it, and reload it on future imports. Mappings are shared across your org, so any admin can reuse a setup someone else has already defined.

    • Employee status history: Hovering the Active, Inactive, or Onboarding badge on an employee's profile now shows a timeline of who or what changed that status and when.

    • Suggested alternatives: Blocked and unsanctioned apps can have alternatives set from the app details panel, pointing employees toward approved options.

    • Luna: Image attachments now preview correctly in chat. The composer and attachment tiles have a refreshed look, and trust level and usage stats now appear below the composer across all chat surfaces.

    • Report table widgets: Report table widgets now show up to 300 rows, up from 100.

    • Segments: Service accounts now display their account name in a segment's member list instead of showing the integration they were sourced from.

    • Custom connectors: You can now delete a connector from the custom integrations tab, which revokes its API keys and archives its linked integrations. The tab has also been redesigned with clearer health and status information at a glance.

    • Reports: Table widgets now include a download button to export the data as a CSV file.

  15. 2026
    NEW

    Decision-only access reviews, new provisioning & more

    Access review campaigns now support a "Record decisions only" mode. Enable it in the campaign wizard to capture reviewer decisions without any automatic follow-up: no deprovisioning and no entitlement adjustment tasks. Templates display a badge so it is always clear which campaigns run in record-only mode.

    • New Relic: Ploy can now create and remove users and manage group membership in New Relic, making it a fully managed integration.

    • TestRail: Create and remove users, manage project access, and search your user base from Luna.

    • Confluent: Ploy can now invite users and search for existing users in Confluent.

    • GitLab: Bulk user search is now available across your configured groups and organisations.

    • Team member permissions: Granting access directly (outside of an approval policy) is now a separate, opt-in permission. Standard seats no longer have it by default; enable it per person in the permissions editor.

    • Audit log: Opening a log entry with a payload no longer crashes the page.

    • HiBob: Custom fields with human-readable names (such as team or pod fields) now sync into Ploy correctly.

    • Expiring access reminders: Employee notifications now list expiring grants in the correct chronological order.

  16. 2026
    IMPROVED

    BrowserStack & DigiCert integrations & more

    Two new integrations are live alongside richer Microsoft identity data and several bug fixes.

    • BrowserStack: Ploy now scans your BrowserStack organisation for users, their access roles (owner, admin, user), and license assignments.

    • DigiCert CertCentral: Ploy now scans your CertCentral account for users, app access, and access roles.

    • Microsoft identities: Identity detail pages now show last non-interactive sign-in separately from last active, a useful signal for service accounts that only authenticate silently. New filter options include on-premises sync status, service principal type, and SSO mode.

    • Access review exports: The CSV download now includes remediation type, status, due date, and completion date columns so you can track which deprovisioning and entitlement-change tasks remain outstanding after decisions are recorded.

    • Various Bug fixes

  17. 2026
    IMPROVED

    Slack/Teams access requests

    Employees can now request access right from Slack and Teams, without breaking flow to go somewhere else. They ask Luna for what they need, pick how long they need it, and confirm, all in the chat tool they already have open. It makes the whole thing fast enough that people actually request the access they need instead of putting it off or borrowing someone else's, and they get pinged the moment each tool goes live. The same catalog and approvals you've configured power it underneath; the win is that getting access now takes a message instead of a context switch.

  18. 2026
    IMPROVED

    In-page Luna

    Luna now lives as a chat bubble inside the dashboard, available from any page. Open it on a resource, identity, app, or access review and Luna already knows what you're looking at — no need to paste IDs or re-state context. Ask "who owns this?", "summarise the last 30 days of activity", or "find anyone with similar access" and Luna will answer against the entity in view.

    You can drag-and-drop files directly into the composer too: screenshots, CSV exports, IdP reports, anything you'd previously have to describe. When Luna queues actions that need your sign-off, you can now bulk approve or deny them by tool type rather than clicking through each one.

    Click the Luna icon on any page to try it.

  19. 2026
    IMPROVED

    Luna Guardrails

    Guardrails are admin-authored rules that let Luna take action without a human-in-the-loop when conditions match, a more surgical alternative to broad "auto-approve" toggles. Every Luna tool now has four states: Allowed, Denied, Ask, and the new Guarded state, which only runs when your rule evaluates true.

    Rules can reference attributes on the entity Luna is acting on, for example, "auto-approve membership additions to low-risk groups, but always ask for production resources." Permissions inherit from parent agents and playbook configs, with overrides shown explicitly on each tool so you always know which rule fired.

    Configure under Settings → Luna → Guardrails.

  20. 2026
    IMPROVED

    Configurable Access Review Attestations

    You can now control exactly who signs off on an access review, what they're agreeing to, and how granular that sign-off is. Choose between three modes: let each reviewer self-attest their own work, require a separately designated person to countersign each account set, or have one person certify the entire review once every set is in. Set an org-wide default, then override it per campaign or per cycle so routine reviews stay light while quarterly compliance certifications can be stricter. Once a cycle starts, its settings are locked, so later changes to your defaults never affect a review already in flight.

    You can also tailor the statements each signer must confirm: edit the wording, add or remove statements, reorder them, and mark each as required or optional. Statements can include real values like the cycle name and resource name, captured at the moment the sign-off is recorded so the historical record shows exactly what was agreed.

  21. 2026

    Dynamic group detection

    Ploy now detects dynamic-membership groups from your IdPs, the ones whose membership is computed from a rule rather than maintained by hand, and labels them throughout the UI. The membership rule is shown alongside the group, so you can see exactly why a user is included.

    Luna can also see these rules and help you make changes/suggestions to better suit how your organisation manages their identities.

  22. 2026
    IMPROVED

    Source of Truth Suggestions

    Ploy now surfaces recommended source of truth configurations in a review queue, so you can set up cascade access relationships in bulk instead of configuring each app one at a time. When Ploy notices a group, license, or role granting access to an app that has no source of truth yet, or a connected integration whose domain matches an app, it adds a suggestion to the queue with sensible defaults already filled in.

    For each suggestion you see the target app, its existing sources, and the recommended source, along with a short explanation of why those defaults were chosen. For group, license, and role suggestions you can adjust the defaults before applying: whether the source is the authoritative identity, whether its identities take priority, whether removing someone there revokes their app access, and whether only active members count. Then choose to apply it alongside your existing sources, apply it and replace what's there (with a confirmation step, since that one is destructive), or dismiss it.

    Once you apply or dismiss a suggestion, Ploy won't surface that same pairing again. New pairings show up within a minute or two. To get started, open the new Source of Truth Suggestions tab on the Resources page, where a badge shows how many are waiting for review.

  23. 2026
    IMPROVED

    Time windows on access request policies

    Access request policies can now specify time windows users are able to make requests within, such as “only between 9-5”. Combined with conditions, you’re now able to craft complex logic around access policy approvals.

  24. 2026
    NEW

    Public API

    Ploy now has a public API allowing you to manage everything from user access to resource access policies programatically, including via IaC tools.

  25. 2026
    IMPROVED

    Claude and OpenAI NHI detection

    Ploy now scans Anthropic and OpenAI for API keys, service accounts, and other non-human credentials, and surfaces them in your NHI inventory. Each key shows up alongside the workspace or team it belongs to, when it was created, when it was last used, and what scopes it carries.

    This is a starting point for governing shadow AI usage - every API key your team has created sitting in .env files, terminal history, and contractors' laptops - without having to chase down individual developers. Combined with the rest of the NHI feature set, you can review and attest AI credentials the same way you handle any other access grant.

    To get started, integrate with either of the applications and then visit the non human identities page in your dashboard to see them.

  26. 2026
    NEW

    Self-hosted integrations

    We’ve now released the ability for anyone to build a integration with Ploy via our Custom connectors. This means tools, applications and databases that were impossible to integrate with before due to being on-prem or generally in-accessible from third party systems can now be integrated with Ploy and enjoy the full suite of Ploy features including user scanning and identity lifecycle management.

  27. 2026
    NEW

    3 new integrations: Calendly, monday.com, Kandji

    Three new connectors landed recently:

    • Calendly: pull Calendly user accounts and access into Ploy so scheduling tooling shows up alongside the rest of your SaaS.

    • monday.com: full coverage including users, accounts, and access.

    • Kandji: device management visibility, with a setup flow that surfaces device counts and ownership during onboarding.

    These join the eight integrations we launched in February and continue our push to cover every SaaS your team actually uses.

  28. 2026
    NEW

    License tracking

    You can now track what your SaaS access actually costs, right alongside who has it. Open the new Licenses tab on any app to record a license, cost per seat, billing cycle, currency, and the seats you've purchased, and Ploy uses the activity it already tracks to show how many of those seats are recently active, lightly used, or sitting idle.

    Each app's tab totals up purchased seats, annual cost, and potential savings, and you can flip any license card to see the exact low-usage accounts behind a wasted-spend figure. Licenses in different currencies roll up to your primary currency automatically, and you'll find new license modules across Reports, including total spend, your biggest savings opportunities, and licenses already at capacity.

    To get started, open any app and visit its Licenses tab.

  29. 2026
    NEW

    Agent and Non-Human Identity detection

    Agents and NHI service accounts, bots, API users, integration credentials, shared mailboxes: are now a first-class identity type in Ploy, alongside humans. Every NHI gets its own page, its own access review treatment, its own status workflow, and lives in a dedicated Non-Human Identities tab in the Identities view.

    You can convert existing human-classified identities to NHIs one at a time from a member page, or in bulk from the Identities list, and Ploy preserves the existing group memberships and access grants when it does. NHI-specific filters (provider, type, last seen, MFA status) make it possible to actually act on the long tail of service accounts that have accumulated over years.

    This is the foundation a lot of upcoming work builds on: your AI provider keys, scan tokens, integration credentials, and shared mailboxes are no longer mixed in with your humans.

  30. 2026
    IMPROVED

    New & extended integrations

    A batch of integration coverage upgrades over the last six weeks:

    • Miro — non-expiring tokens supported, and a new Full-license-holder scanner so you can review Miro spend alongside other paid SaaS.
    • Google Drive — shared-drive scans now include external collaborators, closing a long-standing visibility gap for over-shared drives.
    • Exchange — shared-mailbox status is now derived from accountDisabled rather than guessed, so review accuracy improves on mailbox-heavy tenants.
    • BambooHRmobile_phone is now ingested into Member records and exposed in flow outputs, letting you send SMS-based onboarding from a flow.
    • Microsoft — flows can now write Entra schema-extension (custom) fields via the UpdateUser action, so HR-system attributes can flow straight into your IdP.
  31. 2026
    IMPROVED

    New employee view

    We’ve completely redesigned the employee page in the admin dashboard and added a heap of new features, such as being able to update and lock certain user attributes as well as decide what is shown in the top bar at a glance.

  32. 2026
    IMPROVED

    Bulk request access in the employee portal

    Users are now able to bulk request access in the employee portal on behalf of themselves or other users, greatly reducing the amount of time taken for users to request access.

    This also comes with a brand new design and much more improved interface, allowing users to provide more granularity to their requests.

  33. 2026
    NEW

    SAML login into the Ploy dashboard

    You can now configure your Ploy workspace to use SAML authentication as it’s primary authentication strategy, allowing you to control and restrict access to Ploy based on resources in your IdP.

    To get started visit the settings page in the dashboard and configure your IdP.

  34. 2026
    IMPROVED

    Multi-stage Approvals

    Access policies can now require multiple stages of approvals before access to a resource is granted. For example requiring manager approval before the request is sent to the resource owner for final approval.

    With this new feature you'll be able to protect sensitive resources by requiring sign-off from multiple stakeholders before access is granted.

  35. 2026
    IMPROVED

    Analyse Access review evidence for discrepancies

    Luna can now analyse access reviews evidence like screenshots and CSV’s to automatically detect discrepancies between the uploaded evidence and what’s in Ploy ensuring you’re reviewers are using the most up to date information and your auditors are kept happy.

  36. 2026
    NEW

    8 New Integrations

    We've added 8 new integrations in the last 10 days: Zendesk, GitLab, Airtable, Miro, SIIT, Intercom, HubSpot, and Notion.

    Connect any of these and Ploy will automatically discover all user accounts across your team.

    • Zendesk

    • GitLab

    • Airtable

    • Miro

    • SIIT

    • Intercom

    • HubSpot

    • Notion

  37. 2026

    Profiles

    We’re really excited to release our Profiles feature which give you the ability to group users by any combination of attributes, not just their role. Instead of rigid RBAC rules like "Engineers get access to XYZ," you can now define precise conditions like "Active, full-time engineers with GitHub access and MFA enabled get access to XYZ."

    It's access management that actually reflects how your company works.

    To get started with profiles or to learn more about them, you can read our help docs here: 

    https://help.ploy.io/articles/profiles-dsfeg

  38. 2026
    IMPROVED

    Luna generated flows

    Using the brand new Luna Page and the new ‘Generate automation flow’ playbook, you can describe your desired workflow in natural language and have Luna automatically generate the flow for you.

    Disclaimer: This feature is very much in beta and Luna will most likely make mistakes. Verify every workflow Luna generates.

  39. 2026
    NEW

    Ploy API v1

    We’re excited to announce that we’ve released the first version of the Ploy api, allowing you to programmatically interact with Ploy. This is great for pulling data from Ploy automatically, or managing configurations via IaC tools like Terraform.

    This is currently in beta so if you’d like access don’t hesitate to reach out to the team.

  40. 2026

    Luna AI-Powered Access Catalogs

    Luna can now automatically generate access catalogs for you. Whether you're going through initial setup or managing catalogs day-to-day, Luna can create the catalog structure you need in seconds rather than hours. Catalogs allow you to define targeted sets of resources that employees can request access to.

    How it works

    You have two options:

    1. Let Luna take the wheel - Luna will analyse your historical access patterns and generate a complete suite of catalogs tailored to your organisation

    1. Request specific catalogs - Tell Luna exactly what you need and it will create catalogs to match

    Everything Luna creates starts in draft, so you have full control to review and refine before publishing.

    Regeneration with context

    Not quite right? You can regenerate your catalogs with additional context to guide Luna toward better results. This is particularly powerful for fine-tuning the output to match your specific needs. Note that regenerating will replace any AI-generated catalogs currently in draft.

    Fresh new look

    We've also refreshed the catalog list with a more vibrant design to make managing your catalogs a better experience.


    This is an early release - we'll be tuning Luna's catalog generation based on your feedback, so please experiment and let us know how it goes.

  41. 2026
    IMPROVED

    Microsoft Offboarding: Revoke Sign-ins, Remove MFA devices, Remove mobile devices

    We’ve added 3 new offboarding actions for Microsoft based identities in Ploy, Revoking sessions/sign-ins, Removing MFA devices and removing entra connected mobile devices.

    This is a great way to further secure you’re identities post offboarding. To get started with these create a flow using any of these actions

  42. 2026
    IMPROVED

    Slack automatic provisioning and deprovisioning

    For Slack Business+ and Enterprise Grid customers, Ploy can now automatically provision and deprovision users. When someone joins your company or changes role, their Slack access follows automatically. When they leave, it gets revoked. No more chasing IT tickets or finding out three months later that a former employee still has access to your channels.

    Enterprise Grid customers can also create single and multi-channel guests directly from Ploy, which is handy for managing contractors, vendors, or anyone else who needs limited access without a full account.

    Improved usage data

    We now pull in Slack session history alongside the existing metadata. This means you can:

    • See when someone last actually used Slack, not just when their account was created

    • Spot dormant accounts that might be worth reclaiming (or investigating)

    • Flag dangling access during reviews. If someone hasn't logged in for 90 days, that's probably worth a conversation

    This is especially useful for access reviews where you're trying to work out whether someone still needs access or if they've quietly moved on to a different team.

  43. 2026
    NEW

    What's New in Ploy

    The team at Ploy have hit the ground running in 2026 releasing a huge amount of features, updates and (long awaited) bug fixes to make managing access and identities in 2026 a breeze.

    Let’s dive in 👇

    New resources page

    The biggest change is our brand new resources page which puts everything right at your fingertips. On one page you now have a much more clear breakdown of each resource including any issues Luna’s found, active, removed and shadow access as well as any access requests and usage data we have.

    There’s also a heap of new actions you can take from re-granting access for removed users to quickly viewing and remediating users stuck in in-between states. Read more about it here.

    Sources of truth

    It’s now easier than ever to see the exact same list of users you see in an app or resource, reflected in Ploy. With sources of truth you define where Ploy gets it’s authoritative list of access for any given resource. This might be an integration, another resource (e.g. if it’s SAML/SCIM controlled) or the Browser extension.

    You can also automatically associate entitlements (more on this below) with each source of truth making it easier to know and manage not only who has access to a resource but also what they can do in that resource.

    Entitlements

    Entitlements in Ploy are now first class citizens, allowing you to easily review, manage and provision permissions, roles and other forms of access across any application and resource. We’ll automatically pull these in from integrations or via connected resources from sources of truth.

    Custom Reports

    A long overdue feature is the ability to create custom reports in Ploy allowing you to track (and manage) what’s important for you and your team. We have some prebuilt ones out of the box to help you get started but if none of these fit your needs, you can always create your own.

    App auto provisioning

    Previously with applications, you’d need to use a manual flow to auto provision access, or provision access through a connected resource (e.g. a SCIM group). Now you’re able to directly provision access straight from the application by selecting a resource to grant access to when access is requested.

    Integrations view

    We’ve also completely redesigned our integrations views making it easier to integration with new sources as well as manage existing integrations.

    We’ve also added the ability for you to trigger scans manually when you need to see data live after a change in a source system.

    New Integration features

    New integration

    We’ve just released a new HRIS integration - Personio. This will allow customers using Personio as their employee source of truth pull in all those details into Ploy.

    View docs for getting setup here.

    Expanded features

    • Github: You can now automatically grant and revoke users access to teams inside your Org. Great for JIT access to certain Github resources.

    • JIRA/Atlassian: Via our Flows feature, you’re now able to automatically invite users to your Atlassian organisation when they don’t yet have an account. Great for onboarding or access requests.

    • Microsoft: You’re now able to invite guest users to your Microsoft tenant and grant them access to any resource in Ploy and wrap access policies around their access. Great for preventing guest access lingering.

    And a whole heap of other things

    New

    • New: Bulk add tags to resources

    • New: Archive old integrations

    • New: 'Nudge Reviewers' button on admin access request view

    • New: Option to include/exclude shadow accounts from offboarding

    • New: Filter access by low usage (e.g. unused in the last 30/60/90 days)

    Improved

    • Improvement: It’s now more clear what access reviews are ready for approval and more obvious how to approve them

    • Improvement: When creating offboardings manually, the end date of the employee will automatically pull in when present

    • Improvement: Select fields with large lists will now show a preview instead of having to search to see results

    • Improvement: App filters on will now persist across refresh

    Bugs

    • Bug: Fixed issue where requesting access on behalf of users in a department would fail

    • Bug: Fixed bug where month placeholder on campaigns would put the month number instead of text

    • Bug: Can now chain multiple ‘wait for response’ survey responses and use all results in subsequent nodes

    • Bug: Fixed issue where unsuspending access would failing

    • Bug: Fixed new app column views not showing on save

    • Bug: Fixed annual cost edit not working in managed apps

    • Bug: Fixed editing campaign reviewer not applying

    • Bug: Fixed incorrect link for access review started notification

    • Bug: Fixed reminder saying review is overdue when it isn't

    • Bug: Fixed create new app reporting failure but succeeding

    • Bug: Fixed issue with merging employees

  44. 2025
    NEW

    🔐 Bulk Action Protection


    We've added a new safety feature to protect against any automated process making un-intended large-scale access changes e.g. from a misconfigured rule or a policy applied to the wrong resource.

    How it works:
    You set a threshold (for example, 10 or 15 users). If any automated process like the low usage checker or automatic access expiry would revoke access for more users than your threshold, Ploy will pause the action and send it to an approvals screen. An admin then needs to review and approve it before it goes through. By default this threshold is set to 15 and can be configured here.

    Rollback:
    If something slips through, you can undo bulk revocations and restore access. Think of it like ctrl+z for access management.

  45. 2025

    Tailscale Role manipulation

    You’re now able to wrap your Just-in-time access policies around Tailscale roles, giving users elevated break glass permissions to perform sensitive actions in a secure way. Setup the Tailscale integration to get started today.

  46. 2025

    Nudge reviewers

    Employees requesting access via the catalog are now able to Nudge reviewers as a reminder to review their access request, enabling employees to be in control of their requests and reducing IT workload. In coming updates, Luna will automatically keep on top of access requests

  47. 2025
    IMPROVED

    Requesting access on behalf of other users

    For a while we’ve had the ability to say -
    this user can request access on behalf of these other users

    Which is done by explicitly specifying each individual for which this can be done. This is useful, for example, when a manager wants to request access to a tool for themselves and a few people in their team.

    Now, for extra convenience, it can be done for everyone in the organisation, or by everyone in the same department in the organisation

  48. 2025

    Refreshed Integration Flow

    We’ve released a new integration flow that will make it easier to both setup and track the status of your integrations within Ploy. Now, when starting a new integration you’ll see approximately how long it should take to complete, exactly what permissions are required and how many steps will be needed to complete the integration.

    We’ve added an integrations catalogue which makes it easier to surface and search for the all integrations Ploy offers along with the purpose of the integration.

    We’ve also added additional information about the health and status of the integration, we’ve added the ability to see the last time an incremental scan was run on the integration and clear information about the current status, as well as who the integration was added by (from this point forward)

    We hope this makes it easier to integrate your applications with Ploy, if you have any feedback, please let us know!

  49. 2025

    Add / Remove Users from Atlassian Groups

    If you’ve integrated Atlassian with Ploy, you’re now able to add and remove Atlassian users to (or from) groups, directly from Ploy.

    You can automatically add / remove group access via flows during onboarding & offboarding:

    You can be confident that any changes made to groups from directly within Atlassian will be updated automatically in Ploy - we continuously synchronise them in the background.

  50. 2025

    Invite and Remove Users from your Github organisation

    If you’ve integrated Github with Ploy, you’ll now be able to add (invite) and remove users to and from your Github organisation, directly from within Ploy. We’ve also given Luna a huge level up to allow her to help identify and match Github identities to the right employees.

    To get started jump in to Luna and try the following prompt:

  51. 2025
    IMPROVED

    Revoke employee portal + extension sessions

    This feature helps increase the security of Ploy and your employees and helps us meet the security requirements of larger companies. You’re now able to instantly revoke all sessions across the employee portal and extension at the click of a button, great if you believe an employee device has been stolen, or compromised.

    To do this, visit: https://app.joinploy.com/settings/auth-sessions and click the big button at the top.

  52. 2025
    IMPROVED

    Non-human and multi identity access requests

    Employees are now able to request access for a specific identity they control, whether that be them having multiple identities in a single integration (e.g. user + admin account) or a non-human identity they manage.

    If the user now has access to multiple identities, associated with item they are trying to request access to, they will be presented with a dropdown to select the most identity they want this access request for.

  53. 2025
    IMPROVEDWORKFLOWS

    Salesforce Updates

    We’ve now added the ability to assign users Roles, Territories and callcenters via the Salesforce integration in Ploy. This can be done via Workflows or via assigning users access through the access catalog/admin dashboard.

  54. 2025
    NEW

    Jumpcloud Integration

    We’ve now got a new IdP integration in Ploy - Jumpcloud 🎉

    Integrating with Jumpcloud is extremely straightforward and allows you to pull in and manage all your Jumpcloud identities, applications and groups straight from Ploy.

    You can read our setup documentation here.

  55. 2025

    Activity Streams

    We’re excited to announce that from today you’ll start seeing much more in-depth contextual data about whats happening in real-time throughout your Ploy environment. You’ll find new detailed activity streams beginning on your overview page (if you have the activity stream module.)

    The new activity tab in the members individual view

    and soon you’ll start seeing more of these popping up throughout the dashboard to give you in-depth history for the area you’re in at a glance.

  56. 2025

    Restrict resource access in the Ploy Dashboard

    A much requested feature is finally here - the ability to limit what resources in the Ploy dashboard users can access, allowing you the ability to grant specific users the ability to manage the access and policy for a select few resources, rather then your entire real estate.

    To apply these permission visit the teams settings page and you can manage the allow and block lists for each user who has the member type.

  57. 2025

    Google Admin Role Grants

    Privilege access management just got better in Ploy with the ability to grant and revoke users access to admin roles within Google, allowing you to increase your security posture and reduce you’re breached identity blast radius.

    Roles can now be granted dynamically or Just-in-time (JIT) via the catalog. Visit the integrations page to add the newly required scopes to get started.

  58. 2025

    Export access requests

    You’re now able to export access requests, keeping your auditors happy. We’ve also now started tracking which conditions on the approval flow were met, allowing you to see exactly why this request was automatically approved.

  59. 2025

    ✨ Inactive user with assigned tasks

    Now when you have a user who’s departed the company but still has assigned tasks Luna will let you know and provide a quick-fix popup window that let’s you resolve the issue then and there, without having to dig around into different pages trying to find users who’ve left and still have tasks assigned to them.

  60. 2025
    NEW

    ✨Luna AI + Start page ✨

    We're super excited to release (in beta) our start/overview page alongside Luna, our Identity and governance AI agent. We believe these will help you get so much more value out of Ploy as well as transform the way you manage identities and access across your organisation.

    Luna:

    • Meet Luna, Ploy's new identity and governance AI agent

    • Luna has access to your entire Ploy instance, as well as any integrations you have connected.

    • Luna can help you achieve (almost) anything in Ploy from sending reminders, diagnosing flow issues, identifying security issues and investigating shadow IT.

    • It's still in beta and free to use during this period so would really appreciate throwing everything you can at it and rating conversations you've had using the thumbs up + down.

    • Luna, won't do anything that mutates/changes anything without your explicit approval (with audit-logging builtin)

    • We also have introduced playbooks, which you can think of as AI powered workflows and will soon allow you to create and customise your own playbooks as well.

    📊 Start/Overview page:

    • Along side Luna we've also released a brand new overview/start page that is fully customisable to help you get an overview of everything thats happening in your business access related

    • In addition to this we have a summary widget, which gives you a recent overview of everything happening in your ploy instance over the last 24 hours, great for staying on top of tasks and reviews and proactively identifying issues to ensure your access and governance estate is locked down

    • If there's a widget/chart/graph you think is missing - as always drop us a message and we'll push it out for you.

  61. 2025
    NEW

    Configure member portal login options

    You can now restrict what login options are available to members when logging into the member portal. You can do this in the portal settings

    https://app.joinploy.com/settings/portal-config

  62. 2025
    IMPROVED

    Company logo in emails

    Your company logo in the portal settings section will now automatically be included in all your emails sent to employees, helping increase confidence amongst your employees.

    If no logo is setup, it will fallback to the Ploy logo.

  63. 2025

    Ava sneak peak 👀

    We’ve just released a sneak peak of Ploy’s brand new agentic AI Ava. Think of Ava as having an extra employee on your team dedicated to ensuring every single identity is managed across your entire organisation, without having to lift a finger.

    Ava will be able to:

    • Automatically onboard and offboard users into the right tools and resources

    • Simplify access reviews and provide more detailed context to reviewers to help them make more informed decisions

    • Enforce company policies and remediate violations

    • Proactively suggest policies and access conditions to ensure your security evolves as your business does

    • Investigate and remediate misconfigurations across your integrations

    • Execute ‘playbooks’ or common pre-defined workflows your team currently spend hours per weeks on

    • ??? ← Your own ideas for Ava

    This release is just a sneak peak that help you diagnose errors in your flows, helping you understand what’s gone wrong and more importantly how to fix it. Ava has been hooked up to your integrations so can also easily query against your live data to solve common questions like “why can’t I add xyz@acme.co to group ABC”?

    While this is a beta release there a couple of limitations, most importantly requiring you to rate each conversation you have with Ava to ensure we have the feedback needed to make Ava the best identity AI assistant it can be. To get started with Ava, navigate to an error on flows and click the little ‘Investigate with Ava’ button:

    A note on security:

    We’ve spent a lot of time adding in guardrails and security features to ensure that Ava is protected against common attack vectors and ensuring it only has access to your data. Additionally nothing you send to or interact with Ava is ever used to train models or seen by model providers. All inference is provided by AWS Bedrock currently in the EU region.

  64. 2025
    IMPROVED

    Approve/reject requests from dashboard

    You can now approve or reject access requests directly from the dashboard, great for cases where the reviewer is un-responsive.

  65. 2025
    IMPROVEDWORKFLOWS

    Flows improvements

    You can you now manually trigger flows from within the flow page itself instead of having to execute it only from the list of flows.

    Speaking of list of flows, you’re now able to see the last time a flow was executed as well sort by the last execution column.

  66. 2025

    Identities on employees

    You can now see each employees associated identities on the employee page directly, without having to visit the identities page.

  67. 2025
    IMPROVED

    Flows execution tree

    A long awaited feature but you can now see the full execution tree for each flow execution including branching, and searching.

  68. 2025
    IMPROVED

    Configurable request access on behalf of

    Previously, employees would only be able to request access on behalf of employees they directly managed. With this release however your now able to manually assign and configure extra employees in which a person is able to request access on behalf of.

    To do this, simply visit the page of the employee who you want to allow to request access on behalf of someone else and in the left hand sidebar you will see the ability to configure who they can request access on behalf of.

  69. 2025
    NEW

    ✨ AI Powered Access requests

    We’re super excited to release AI insights for access requests, giving reviewers the context they need to make informed decisions about access requests, instead of just guessing based on incomplete data.

    Ploy pulls in as much relevent context as possible for this insights including but not limited to things like who has current access? what were the employees last requests like? is there anything anomalous about this request and more…

    Ploy uses AWS bedrock in the EU region to power this feature, meaning none of your data leaves our AWS environment or the EU region and none of your data is used to train the models or shared with model providers, see below from AWS’s faq for bedrock:

    With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers.

    If you’d like this enabled in your account, please reach out to Seb

  70. 2025
    NEW

    Recurring Campaigns

    Following up on last month's release of Access Review Campaigns, we've now introduced Recurring Campaign Templates.

    This allows you to set up a Campaign once, and have it automatically recur at a cadence. The dynamic nature of Campaigns means that it really is a set-and-forget experience!

    Some example use cases include:

    • Automating quarterly compliance reviews (e.g. for SOC2 or ISO27001)

    • Automating access review checks for recent leavers

    • Automating monthly Admin account reviews

  71. 2025
    IMPROVED

    Campaigns Improvements

    We’ve made a bunch of iterative improvements to our Access Review Campaigns:

    • Created optional notifications that can be sent at each stage of a Campaign

    • Created an optional feedback loop whereby marking a user as Not Required in an access review will automatically deprovision their access

    • Added the ability to create new Assignment Configs via the Campaign modal

  72. 2025
    FIXED

    Campaigns Bug Fixes

    We’ve fixed a bunch of bugs in our Access Review Campaigns feature:

    • Status field is now working correctly

    • Notifications are now sent to reviewers upon creating a Campaign

    • Filter is now displaying variable names correctly

    • Preview page now loads correctly

  73. 2025
    NEW

    Source of Truth Status

    We now pull in the status field from your source of truth so that you can reference it in Ploy.

  74. 2025
    IMPROVED

    Flows 'Get Members' Node

    You can now multi-select the employee status field in the 'Get Members' node.

  75. 2025
    FIXED

    Bug Fixes Update

    We’ve fixed a bunch of niggling bugs to improve the overall user experience:

    • Access Reviews: Fixed a bug where the user couldn't add roles to a member

    • Apps: Fixed a bug where usage data for Okta wasn't being pulled in correctly

    • Assignment Configuration: Fixed a bug where the fallback assignee was not working

    • Flows: Fixed a bug where Offboarding 'Start on End Date' toggle was not working

    • Google Integration: Fixed a bug where nested Google Org Units were not pulling in

    • Task Reminder Messages: Fixed a bug where users were getting sent the message incorrectly

  76. 2025
    IMPROVED

    IdP Integration Improvements

    Okta Integration

    • You can now add & remove users from Okta IdP Apps

    • You can now create users in Okta

    • You can now update any user attribute field in Okta

    • We now pull in Usage data for the Okta app itself

    Google Workspace Integration

    • We can now pull in Google Org Units as a resource

  77. 2025
    NEW

    Deleting Flow Nodes ❗

    Sometimes it's the little things...

    We've finally built the ability to delete a node in Flows without it deleting the rest of the flow!

    We can't tell you how good this one feels!

  78. 2025
    IMPROVED

    Managed Apps Page Improvements

    We have 5 improvements to the Managed Apps page:

    1. You now have a count of the total number of Managed Apps at the top of the page

    2. You can now filter the page on any column you want

    3. You can now sort the page by the Owner column

    4. The ‘warning’ sign on the Owner column now indicates a missing or terminated employee

    5. You can now export the managed apps page

  79. 2025
    IMPROVED

    Flows - Filter on Resource Access

    You can now filter by whether members do/don’t have access to specific resources. This can either be done via the Get Members node (as above), or via the Multi Filter (As below).

  80. 2025
    NEW

    Access Review Campaigns

    Introducing Access Review Campaigns!

    Rather than conducting access reviews on a per app basis, you can now conduct access review campaigns on your entire estate, applying any filters you wish.

    Example use cases include:

    • Creating a campaign to review access on any resources tagged with 'soc2'

    • Creating a campaign to review access to any resources granted since 1st Jan

    • Creating a campaign to review access on any accounts with MFA Disabled

    Campaigns can also be set to recur at a cadence, so all you have to do is create them once!

  81. 2025
    NEW

    Jira Integration

    We now have the concept of tickets in Ploy which can optionally be two-way synced with Jira. Tickets will sync in real-time so can either be managed in Jira, or directly through Ploy.

    For now, tickets can only be created via Flows. But coming soon will be the ability to create tickets for access approval & provisioning.

  82. 2025
    IMPROVED

    New Offboarding Page 📴

    The Offboarding page has been completely revamped to make it simpler and more intuitive than ever before.

    You can now quickly find key information at a glance towards the top, and more easily track all the actions that need completing towards the bottom.

  83. 2025
    NEW

    Offboarding Flow - Send Admin Tasks in Advance

    When a Tool Admin is leaving the company, it’s important that they transfer their Admin rights to another team member before leaving.

    We now have the ability to send these Admin Rights Transfer tasks ahead of time, and without triggering the rest of the offboarding. An example flow might be:

    • Two weeks before the end date → Send the admin rights tasks

    • At 5pm on the last day → Start the rest of the Offboarding

  84. 2025
    NEW

    Flows - 'Wait Until' Node

    We’ve added in the ability to pause a flow until a specific time of the day. An example use case could be as follows:

    • Send a user a question or a survey

    • Wait until 4pm

    • If no response → Follow up

  85. 2025
    IMPROVED

    New Employee Portal

    We've completely revamped the employee-facing portal; adding in a sidebar and improving the UI of each constituent page.

    We’ve also introduced a homepage which offers a seamless way to:

    • view your current access

    • extend access that’s expiring soon

    • view any outstanding tasks

    • view available access catalogs

    Making it a one-stop-shop for your employees.

    Bonus: We've also (finally!) included a link to the Employee Portal in our Admin Console.

  86. 2025
    NEW

    Access Conditions 🚦

    For the first time, you can now set conditions that must always be True for a user to maintain access to a resource. Access will be automatically be Suspended if a user no longer meets the conditions, and can optionally be automatically reinstated if the conditions are met again.

    For example, is access to a resource team-dependent? Does it require MFA to be enabled? Do you have location-based access written into your client contracts?

    Access Conditions now give you a whole new lever to manage access in a seamless yet dynamic manner.

  87. 2025
    NEW

    Easily Re-request Access

    If you find yourself wanting to request access to a resource that you’ve recently lost access to, you can now easily do this by clicking the ‘Re-request access’ button in the deprovisioning message.

    This helps ensure that enforcing least privilege access is as frictionless a process as possible.

  88. 2025
    NEW

    Delete a Task

    You can now delete Tasks if you so wish. This is useful to ensure you don’t get reminders for tasks that are not going to get actioned.

  89. 2025
    NEW

    Delete an Access Review

    You can now delete access reviews. Doing so will delete all its constituent data though which means it won’t be auditable.

  90. 2025
    NEW

    Access Expiring Notification

    For employees that are due to lose access to resources within the next 24 hours, we will now send them a message at 10am UTC to notify them.

    This is to help ensure that employees are informed and maintain business continuity.

  91. 2025
    NEW

    Task Reminder Messages

    To help with stakeholders completing any outstanding tasks, we now send a reminder message every day at 10am UTC to anyone with tasks that need actioning.

    This can optionally be turned off in Settings.

  92. 2025
    NEW

    Message Batching

    To avoid users getting spammed with messages (e.g. if multiple resources are deprovisioned at the same time), we will now batch messages together into one overarching message.

  93. 2025
    NEW

    Welcome Message to employees

    To help with the rollout with Ploy across your company, we’ve also now added the ability for employees to receive a fully customisable welcome message that will be sent out before they receive any other messages. This is a great way to introduce the product, explain any new processes and send them a link to the new employee access portal.

    You can configure these settings by visiting: https://app.joinploy.com/settings/messages

  94. 2025
    IMPROVED

    Quality of life improvements

    We’ve released 3 new quality of life improvements to today to make using Ploy just a little bit nicer 😀

    Custom task title and description on flow created offboardings

    Fallback assignee for flow create offboardings

    You’re now also able to assign a fallback assignee in offboarding so that if an application is missing an owner or the owner is no longer active, the task will be assigned to a fallback to be completed.

    Access review names & deletion

    You’re now also able to give your access reviews a name as well as delete test or draft access reviews to keep your audit history clean 🧼

  95. 2025
    NEW

    Import users into apps & resources via CSV

    We’ve now added the ability to import users via CSV into apps and resources, ensuring that Ploy becomes your single source of truth. It’s as simple as selecting a CSV with all your users and mapping the columns to the fields in Ploy.

  96. 2025
    IMPROVED

    Launch URL's & Custom names

    You’re now able to add ‘Launch URLs’ to your managed access via their access policy making it easier for employees to know where to go after access has been granted. An example of a Slack message is visible below.

    You are also now able to change the name that’s shown to users when access is granted to be different from the resource that’s granting access (e.g. it’s a group granting access, but it’s Miro that access is granted to).

  97. 2025
    WORKFLOWS

    'Has access to' filter + UI/UX improvements

    We’ve added a new filter option to member/employee filtering in Ploy as well as greatly improved the UI / UX to make it easier to select the right reference.

    ‘Has access to’ and ‘doesn’t have access to’

    There are 2 new filter operations if you select a member reference in the multifilter node in workflows. This let’s you combine queries such as ‘does not have access to X’ and ‘is in department Y’ → ‘Add to group Z’.

    Improved selection UI

    One complaint we commonly got with the reference selector (e.g. picking a field/reference from a previous node in the workflow) was that it was hard to tell which field it was referencing and when, leading to multiple instances of referencing the wrong node/variable. We’ve greatly improved this UI/UX and turned it into a multi level dropdown selector where you start from the node you want to reference and work your way down to the field.

  98. 2025
    IMPROVED

    Auto-revoke violating access

    Access Policies on resources now have the ability to automatically revoke access if it’s detected that the granted access violated the approval policy.

    Why do we think this is cool?:

    Now regardless of where your access is granted for a resource, whether that be via your Ploy access request portal, directly inside an integration or even through another third party, if it violates your approval policy, Ploy will automatically revoke that access.

    How do I enable this?:

    Head to any resource in Ploy and either setup or add a new access policy and select ‘Revoke’ as the auto-enroll policy failure action:

    Then just ensure you have at least one condition in your approval policy that rejects and you’re good to go!

  99. 2025
    IMPROVEDACCESS REVIEWS

    Notes on access reviews & multiple roles

    You’re now able to add individual notes to each row in an access review, allowing you to capture particular nuances that might not otherwise be obvious. They’re also included in our CSV export meaning no back and forth clarification with auditors.

    Multiple roles

    You’re now also not limited to assigning a single role per account with access review, allowing you to capture those more complex permission structures present in some applications.

  100. 2025
    IMPROVED

    Access Review notifications

    You’re now able to receive notifications for any important event related to an access review lifecycle to ensure you’re remaining up to date and compliant across you’re access reviews.