July 14th, 2026
New
Improved

A lot has changed over the past couple of days here at Ploy. Letβs dive in.
AI agents: AI agents (Copilot Studio, custom GPTs, and others) now have dedicated resource pages in the admin dashboard. Each shows the platform the agent runs on, its direct app permissions, delegated access held on behalf of users, who is using it, and a visual access graph. To get access please contact your account manager
Microsoft own-app setup: When connecting Microsoft, you can now use your own Entra app registration instead of Ploy's managed app. A setup wizard covers capability selection, the app manifest, and the Azure configuration values, with a toggle to enable or disable all optional permissions at once.
Luna: Reports can now filter apps by tag dynamically, so querying for "procured" apps (or any other tag) always reflects the current tagged set rather than a stale list.
Edge on Mac: A deployment profile for Edge on Mac is now available, letting admins push the Ploy extension to managed Mac devices running Microsoft Edge.
Custom employee fields: Define custom fields for employee profiles from the Employee Fields settings page, pick from text, number, date, select, or yes/no types, and connect each to HiBob, Okta, or another integration so values sync automatically. Fields appear in a dedicated section on every employee profile.
Agent runs and success criteria: Agent detail pages now show a success scorecard for each defined criterion, a run history with declared outcomes and confidence level, and a full activity timeline. Non-human identities can also now submit access requests using dedicated API keys, which appear in the standard review queue.
Multi-file app fields: App custom fields can now hold multiple files, letting you attach several contracts or documents to a single field without overwriting previous uploads.
Integrations: BrowserStack service accounts now appear as non-human identities in Ploy. DigiCert now captures last-login dates for usage tracking. Microsoft enterprise app service principals now show the application permissions they hold. AWS classic IAM group memberships can now be provisioned directly.
Access policies: You can now delete an access policy directly from the resource detail view or the managed resources table. Ploy checks for active access reviews and open requests first and blocks deletion until those are resolved.
Flows: Yes/No confirmation steps now support a "No response" path. Set a timeout in minutes, hours, or days, and your flow continues automatically if the recipient never clicks Yes or No.
Microsoft guest accounts: Ploy now shows the sponsor for each Microsoft Entra B2B guest, the person in your organisation responsible for that account. Their name and email appear on the guest's identity record, and Luna can reach out to them when a guest account goes dormant.
Custom integration logos: When configuring a custom integration, you can now search Ploy's app logo library and pick a matching logo. It then appears consistently across cards, resource rows, and graphs.
July 8th, 2026
New

Ploy shipped two new capabilities today alongside several reliability fixes.
Jira sub-tasks: Using flows you can now create Jira sub-tasks
Luna file attachments: Employees chatting with Luna in the employee portal can now attach files alongside their messages. PDFs, spreadsheets, Word documents, images, and CSVs are all supported, up to 4.5 MB per file.
CSV entitlement sync: Update-only imports now replace a member's full set of entitlements rather than only appending new ones, so stale access is removed automatically on each re-run.
July 7th, 2026
New
Improved

Thereβs been a lot shipped in Ploy over the last 7 days, letβs dive in β¬οΈ
Luna access requests: Requesting access for shorter windows, such as a few hours, now works correctly when chatting with Luna in Slack or Teams.
OneTrust: Login activity now flows into Ploy when the required permission is enabled in OneTrust, so you can see who is actively signing in alongside your full user directory.
Employee profile: The Resources tab now shows a Type column and lets you filter by resource type or integration, making it easier to review what kind of access an employee holds.
User importer: Ignore Rows now supports additional matching conditions, including "contains", "is one of", "is set", and "is not set", so you can filter rows without pre-processing your CSV.
Okta: Fixed a scan issue where the event log could stall on empty filtered time windows, causing outdated events to replay on every scan cycle.
Compliance segment templates: You can now create segments from pre-built compliance-framework templates. On the Segments page, choose "Create from compliance framework" to browse templates mapped to SOC 2, ISO 27001, CIS Controls, and more, with Google and Microsoft vendor packs included. Each card shows a live match count for your org. Select any number and bulk-create them in one click, or customize one before saving.
Claude.ai seat tracking: The Anthropic integration now shows a seat licence view: purchased vs active seats, cost per seat (defaulting to $20 if left blank), and a savings breakdown by usage tier. Set a minimum daily token threshold to define what counts as active for your org.
Access request notifications: The Managed Access "Notifications" tab (previously "Config") now surfaces opt-in notification types, including a new option to notify your team when a request is submitted.
New Relic: Ploy can now create and remove users and manage group membership in New Relic, making it a fully managed integration.
TestRail: Create and remove users, manage project access, and search your user base from Luna.
Confluent: Ploy can now invite users and search for existing users in Confluent.
GitLab: Bulk user search is now available across your configured groups and organisations.
Team member permissions: Granting access directly (outside of an approval policy) is now a separate, opt-in permission. Standard seats no longer have it by default; enable it per person in the permissions editor.
HiBob: Custom fields with human-readable names now sync into Ploy correctly.
Exchange: The setup wizard no longer requires you to grant Ploy the Exchange Administrator role. It now displays a PowerShell script you fill in with your Entra Object ID and copy straight to your terminal, giving Ploy only the permissions it actually needs.
Luna: You can now ask Luna to find identities by a specific MFA method, such as everyone who authenticates by SMS or passkey, rather than just checking whether MFA is on or off.
Low-usage trigger testing: The member field when testing a Low Usage flow trigger is now optional. Leave it blank and Ploy returns the full list of members who would trigger for that app, so you can validate the trigger at a glance without picking a specific person.
Saved CSV import mappings: You can now save a column-mapping configuration during a user import, name it, and reload it on future imports. Mappings are shared across your org, so any admin can reuse a setup someone else has already defined.
Employee status history: Hovering the Active, Inactive, or Onboarding badge on an employee's profile now shows a timeline of who or what changed that status and when.
Suggested alternatives: Blocked and unsanctioned apps can have alternatives set from the app details panel, pointing employees toward approved options.
Luna: Image attachments now preview correctly in chat. The composer and attachment tiles have a refreshed look, and trust level and usage stats now appear below the composer across all chat surfaces.
Report table widgets: Report table widgets now show up to 300 rows, up from 100.
Segments: Service accounts now display their account name in a segment's member list instead of showing the integration they were sourced from.
Custom connectors: You can now delete a connector from the custom integrations tab, which revokes its API keys and archives its linked integrations. The tab has also been redesigned with clearer health and status information at a glance.
Reports: Table widgets now include a download button to export the data as a CSV file.
July 1st, 2026
New

Access review campaigns now support a "Record decisions only" mode. Enable it in the campaign wizard to capture reviewer decisions without any automatic follow-up: no deprovisioning and no entitlement adjustment tasks. Templates display a badge so it is always clear which campaigns run in record-only mode.
New Relic: Ploy can now create and remove users and manage group membership in New Relic, making it a fully managed integration.
TestRail: Create and remove users, manage project access, and search your user base from Luna.
Confluent: Ploy can now invite users and search for existing users in Confluent.
GitLab: Bulk user search is now available across your configured groups and organisations.
Team member permissions: Granting access directly (outside of an approval policy) is now a separate, opt-in permission. Standard seats no longer have it by default; enable it per person in the permissions editor.
Audit log: Opening a log entry with a payload no longer crashes the page.
HiBob: Custom fields with human-readable names (such as team or pod fields) now sync into Ploy correctly.
Expiring access reminders: Employee notifications now list expiring grants in the correct chronological order.
June 30th, 2026
Improved

Two new integrations are live alongside richer Microsoft identity data and several bug fixes.
BrowserStack: Ploy now scans your BrowserStack organisation for users, their access roles (owner, admin, user), and license assignments.
DigiCert CertCentral: Ploy now scans your CertCentral account for users, app access, and access roles.
Microsoft identities: Identity detail pages now show last non-interactive sign-in separately from last active, a useful signal for service accounts that only authenticate silently. New filter options include on-premises sync status, service principal type, and SSO mode.
Access review exports: The CSV download now includes remediation type, status, due date, and completion date columns so you can track which deprovisioning and entitlement-change tasks remain outstanding after decisions are recorded.
Various Bug fixes
June 26th, 2026
Improved

Employees can now request access right from Slack and Teams, without breaking flow to go somewhere else. They ask Luna for what they need, pick how long they need it, and confirm, all in the chat tool they already have open. It makes the whole thing fast enough that people actually request the access they need instead of putting it off or borrowing someone else's, and they get pinged the moment each tool goes live. The same catalog and approvals you've configured power it underneath; the win is that getting access now takes a message instead of a context switch.
June 17th, 2026
Improved

Luna now lives as a chat bubble inside the dashboard, available from any page. Open it on a resource, identity, app, or access review and Luna already knows what you're looking at β no need to paste IDs or re-state context. Ask "who owns this?", "summarise the last 30 days of activity", or "find anyone with similar access" and Luna will answer against the entity in view.
You can drag-and-drop files directly into the composer too: screenshots, CSV exports, IdP reports, anything you'd previously have to describe. When Luna queues actions that need your sign-off, you can now bulk approve or deny them by tool type rather than clicking through each one.
Click the Luna icon on any page to try it.
June 17th, 2026
Improved

Guardrails are admin-authored rules that let Luna take action without a human-in-the-loop when conditions match, a more surgical alternative to broad "auto-approve" toggles. Every Luna tool now has four states: Allowed, Denied, Ask, and the new Guarded state, which only runs when your rule evaluates true.
Rules can reference attributes on the entity Luna is acting on, for example, "auto-approve membership additions to low-risk groups, but always ask for production resources." Permissions inherit from parent agents and playbook configs, with overrides shown explicitly on each tool so you always know which rule fired.
Configure under Settings β Luna β Guardrails.
June 10th, 2026
Improved

You can now control exactly who signs off on an access review, what they're agreeing to, and how granular that sign-off is. Choose between three modes: let each reviewer self-attest their own work, require a separately designated person to countersign each account set, or have one person certify the entire review once every set is in. Set an org-wide default, then override it per campaign or per cycle so routine reviews stay light while quarterly compliance certifications can be stricter. Once a cycle starts, its settings are locked, so later changes to your defaults never affect a review already in flight.
You can also tailor the statements each signer must confirm: edit the wording, add or remove statements, reorder them, and mark each as required or optional. Statements can include real values like the cycle name and resource name, captured at the moment the sign-off is recorded so the historical record shows exactly what was agreed.
June 10th, 2026

Ploy now detects dynamic-membership groups from your IdPs, the ones whose membership is computed from a rule rather than maintained by hand, and labels them throughout the UI. The membership rule is shown alongside the group, so you can see exactly why a user is included.
Luna can also see these rules and help you make changes/suggestions to better suit how your organisation manages their identities.