August 6th, 2026
New
Improved

Ploy now connects to Alchemer and ships improvements across employee profiles, access reviews, Segments, and Luna.
Alchemer: Ploy now scans your Alchemer account for users, teams, and licence seats and supports provisioning and deprovisioning directly from Ploy.
DocuSign: You can now provision and deprovision users directly from Ploy, and manage their group memberships. Invite someone by email (DocuSign sends them an activation link), close their account to revoke all access, or move them between groups, all without leaving Ploy.
Luna: Luna now has a separate read permission. Grant it to colleagues who need to browse and read existing chats without being able to start new sessions or send messages. The message composer stays hidden for read-only users.
Employee Resources: The Resources tab on an employee's profile now has a Dynamic membership filter. Use it to isolate groups where membership is controlled automatically by rules in Microsoft or Okta, or hide those groups to focus on manually-managed access.
Licence availability check: A new gate step in the flow builder lets you branch based on whether a specific licence has free seats. Choose a resource and one of its licences, set the direction (available or not), and the step passes current seat counts to downstream steps for end-to-end seat-rotation flows.
Range selection: Hold Shift and click a second row to select everything in between, across every table in the dashboard.
Saved resource views: Private saved views in Resources now show a "Private" badge. An edit button lets you update a view's name, icon, colour, or visibility at any time after saving.
August 3rd, 2026
New

Last week's release adds a full OneLogin integration, richer Luna responses and tools, and improvements across access reviews and the app catalog.
OneLogin: Ploy now integrates with OneLogin as a full IdP. Connect your tenant to pull in users, MFA enrollment and methods, roles, and app assignments, plus last sign-in activity. Open the Integrations page to get started.
Luna: Responses now render tables, cards, and structured blocks directly in the chat, at their natural position in the conversation, instead of inside collapsed thinking steps. The underlying model has also been upgraded for sharper, more reliable answers.
Access reviews: Reviewers in the employee portal now land on the full entitlements list by default when opening a review, with Luna's recommendations one click away via a tab at the top.
Agent actions: Luna agents can now suspend and restore user accounts at connected integrations as part of automated workflows, with confirmation required before each action and every suspension recorded in the audit trail.
Catalog search: The app catalog in the browser extension now matches underlying resources when searching, so "billing" surfaces the AWS tile via its Billing resource, with a hint showing what matched.
Assignment configs API: Reviewer routing rules can now be created, updated, and deleted via the public API, making them straightforward to manage from external tooling.
Escalation notifications: Escalation message wording can now be customised for access reviews. Open the escalation editor and choose "Customise the message" to edit the notification template that reaches reviewers at each stage and save it for reuse.
Access reviews: Reviewers in the employee portal now see department, job title, and last-active date columns switched on by default, so relevant context is visible without manually enabling columns.
Flows: You can now filter Microsoft and Entra accounts by guest status in flows, making it straightforward to target low-usage guest accounts for automated action.
Luna: Luna can now find failed or stalled access-request provisioning and retry it on demand, completing the full lifecycle from approval through to recovery.
App catalog: Employees browsing the app catalog now see a badge on any app they already have access to, preventing accidental duplicate requests.
Public API: New endpoints let you read and manage provisioning strategies and their folders via a dedicated API scope, and manage resource sources of truth per row via the API.
Luna: CSV imports, Luna can now preview what a CSV mapping will produce before you run it, showing which rows will import, merge, or be skipped and why. Ask Luna to load a saved import template or save the current mapping for reuse in later imports.
Luna: catalog management, Luna can now archive a catalog item so employees no longer see it in their access catalog, and permanently delete an access policy that is no longer needed.
Terraform and Public API improvements: You can now configure your core Ploy resources via Terraform. Contact your account rep to get access to the provider
Access catalogs in the API, Create, update, publish, and archive access catalogs and their items from Terraform or your own tooling, including visibility rules by department, group, or profile, and the access options offered within each item.
Resource access policies in the API, A resource's full access policy (approval stages, time limits, provisioning setup, and eligibility conditions) can now be defined and managed from infrastructure-as-code.
Organisation settings in the API, Internal email domains and IP restrictions for the admin dashboard and employee portal are now manageable via the API, making them part of your version-controlled configuration.
July 28th, 2026
New
Improved

Ploy now connects to Freshservice for ticketing, plus a range of other improvements.
Freshservice Ticketing integration: You can now integrate with Freshservice as your ticketing system, helping you manage access requests and other identity related issues in your native ITSM, or use it as a centralised backup for identity related work.
API key management: Existing keys can now be edited (rename or change permissions) without revoking them. Scope options are grouped by category in the picker.
Tags API: Create, update, and delete tags via the Ploy API using a key with tags permissions.
Access review scoping: Campaigns can now be scoped to access rows carrying a specific tag, not just tags on the employee or resource.
Luna: Luna can now draw on Ploy's accumulated knowledge about your environment when answering questions.
User importer: Human identities can now be imported using an external ID alone, without an email address.
Employee page: "Last Working Day" is now available as a column in the custom view picker.
Profiles in the public API: create, read, update, and delete profiles via the API, with the full filter definition included.
Resource and integration lookups: the resources endpoint now accepts exact-match filters by name, external ID, domain, and application status; new read-only endpoints for integrations and messaging channels are also available.
Jira knowledge source, service-account auth: when setting up Jira as a knowledge source, you can now choose between OAuth and a service-account API token scoped to specific projects, so Ploy can only read what that account can access.
Signup source on active access: the origin of a shadow-IT signup, captured by the browser extension, now stays visible after access moves to the active tab, so you can always trace how it started.
API docs: nested object schemas now expand inline, and the navigation panel scrolls independently of the content panes.
July 24th, 2026
New

A large set of updates shipped the last few days headlined by our changes to access reviews.
Multi-stage reviews: You can now have multiple stages of reviews, on all or a subset of entitlements allowing support for usecases such as βManagers revieiwing employee accessβ followed by an SME reviewing admin only roles
Escalation paths: Automatically re-assign reviews if users donβt complete in X days or notify their manager
Extension Requests: Users can request an extension if they need more time
Queries: Reviewers can also make queries, such as clarifying questions to your IT admins while completing reviews.
Bulk retry provisioning: Filter the access request list by status, select failed requests, and retry their provisioning in one action.
Tag management: Create, edit, and color-code tags from the Settings page. Assignment configurations can now be deleted directly from the configuration modal.
Tasks: Filter the unified Tasks list by app or resource.
User importer: Human accounts can now be imported using an Ext ID alone, without an email address.
Identities: Bulk convert human identities to non-human identities from the Inventory page.
July 22nd, 2026
New

You can now stream your Ploy audit log to an external SIEM, with Microsoft Sentinel as the first destination.
SIEM integrations: Connect from the new SIEM tab on the Integrations page. The wizard uses federated identity credentials so no client secrets are stored.
AI agent visibility: Ploy now tracks Copilot and Claude agents, so you can see which are active, who is using them, and what resources they reach on behalf of users.
HiBob: Mobile and work phone numbers now sync from HiBob for use in flows and automations.
Agent access view: The access-on-behalf-of panel on an agent page now groups entries by permission, with stacked member avatars replacing one row per individual account.
Employee portal: Employees outside an approved IP range now see a clear screen directing them to connect via VPN or contact IT, instead of a generic error.
July 21st, 2026
New

Four improvements shipped today covering security, automation, access management, and the Luna experience.
IP restrictions: You can now limit which networks can reach Ploy. In Settings > Authentication, configure separate IP allowlists for the admin dashboard and for the employee portal and browser extension. Leave a list empty for no restriction, and a warning flags if a saved range would lock you out of the dashboard.
Custom fields in flows: Custom employee fields now appear as audience filter options and as a flow trigger, so you can build flows that target or activate based on fields specific to your org, like a cost center or contract type.
Expiring Soon: The Managed Access > Expiring Soon page now has per-row Manage access and Deprovision access buttons, plus a bulk deprovision option when you select multiple entries, so you can act without opening the resource page first.
Luna and agent runs: The Luna indicator is now animated across the sidebar, chat, and agent pages, reflecting live state. On the agent runs page, task cards expand inline to show session detail, and the runs navigator is now called Active Runs.
July 20th, 2026
Improved

You can now see on-call status in employee profiles, delete Entra accounts and Exchange shared mailboxes from flows, and import users in update-only mode.
On-call status: Employee profiles now show whether someone is currently on call, pulled from your Grafana IRM or PagerDuty connection. A green badge marks an active shift; the row only appears for members on a rota. "Is on call" is also available as a filter when building segments.
Entra and Exchange deletion in flows: A new "Delete shared mailbox" step is available in the flow builder for removing Exchange shared mailboxes. The "Remove user from integration" step now also supports deleting an Entra account directly.
User import update-only mode: When importing users via CSV, you can turn on "Only update existing users" at the mapping step. Existing records are refreshed in place; rows that don't match anyone are skipped, nothing new is created, and the grant date and identity type become optional.
Google Workspace: The invite-external-user flow action now supports Google Workspace alongside the existing Microsoft support. Guests are automatically detected in scans and attributed to their real external email address.
Unmanaged accounts: You can now select multiple accounts on the Unmanaged tab and convert them to non-human identities in bulk, rather than one at a time.
Low usage detection: When previewing how many accounts a low-usage threshold would flag on a resource, you can now click "View accounts" to see the full list, each account's last activity date, and when access was first granted.
July 16th, 2026

Users can now select which of their identity they are making the request for when making an access request as well as making requests on behalf of owned NHISs, alongside other improvements across the user importer, Google Drive, and the access catalog editor.
Access requests: Employees can pick which account or service account they own gets the grant, per resource. People with multiple accounts on the same integration, or who own service accounts, see a dropdown on each item in the request basket. Admins see "Requested by" and "Requested for" as separate rows in the request detail panel.
User importer: Both the column-mapping dropdown and the person-preview picker now have a type-to-filter search box. A new "Apply to more columns" option copies one column's mapping to several others at once, and a "Use column name as type" checkbox auto-fills the entitlement type from the mapped column name.
Google Drive: Shared drives now show the org unit they belong to as a resource attribute. Luna can filter drives by org unit when answering questions about specific areas of your Drive environment.
Access catalogs: The catalog editor now has a "View in portal" button that opens the catalog directly in the employee portal, so you can preview exactly what employees see.
On-call status: Employee profiles now show whether someone is currently on call, pulled from your Grafana IRM or PagerDuty connection. A green badge marks an active shift; the row only appears for members on a rota. "Is on call" is also available as a filter when building segments.
Entra and Exchange deletion in flows: A new "Delete shared mailbox" step is available in the flow builder for removing Exchange shared mailboxes. The "Remove user from integration" step now also supports deleting an Entra account directly.
July 14th, 2026
New
Improved

A lot has changed over the past couple of days here at Ploy. Letβs dive in.
AI agents: AI agents (Copilot Studio, custom GPTs, and others) now have dedicated resource pages in the admin dashboard. Each shows the platform the agent runs on, its direct app permissions, delegated access held on behalf of users, who is using it, and a visual access graph. To get access please contact your account manager
Microsoft own-app setup: When connecting Microsoft, you can now use your own Entra app registration instead of Ploy's managed app. A setup wizard covers capability selection, the app manifest, and the Azure configuration values, with a toggle to enable or disable all optional permissions at once.
Luna: Reports can now filter apps by tag dynamically, so querying for "procured" apps (or any other tag) always reflects the current tagged set rather than a stale list.
Edge on Mac: A deployment profile for Edge on Mac is now available, letting admins push the Ploy extension to managed Mac devices running Microsoft Edge.
Custom employee fields: Define custom fields for employee profiles from the Employee Fields settings page, pick from text, number, date, select, or yes/no types, and connect each to HiBob, Okta, or another integration so values sync automatically. Fields appear in a dedicated section on every employee profile.
Agent runs and success criteria: Agent detail pages now show a success scorecard for each defined criterion, a run history with declared outcomes and confidence level, and a full activity timeline. Non-human identities can also now submit access requests using dedicated API keys, which appear in the standard review queue.
Multi-file app fields: App custom fields can now hold multiple files, letting you attach several contracts or documents to a single field without overwriting previous uploads.
Integrations: BrowserStack service accounts now appear as non-human identities in Ploy. DigiCert now captures last-login dates for usage tracking. Microsoft enterprise app service principals now show the application permissions they hold. AWS classic IAM group memberships can now be provisioned directly.
Access policies: You can now delete an access policy directly from the resource detail view or the managed resources table. Ploy checks for active access reviews and open requests first and blocks deletion until those are resolved.
Flows: Yes/No confirmation steps now support a "No response" path. Set a timeout in minutes, hours, or days, and your flow continues automatically if the recipient never clicks Yes or No.
Microsoft guest accounts: Ploy now shows the sponsor for each Microsoft Entra B2B guest, the person in your organisation responsible for that account. Their name and email appear on the guest's identity record, and Luna can reach out to them when a guest account goes dormant.
Custom integration logos: When configuring a custom integration, you can now search Ploy's app logo library and pick a matching logo. It then appears consistently across cards, resource rows, and graphs.
July 8th, 2026
New

Ploy shipped two new capabilities today alongside several reliability fixes.
Jira sub-tasks: Using flows you can now create Jira sub-tasks
Luna file attachments: Employees chatting with Luna in the employee portal can now attach files alongside their messages. PDFs, spreadsheets, Word documents, images, and CSVs are all supported, up to 4.5 MB per file.
CSV entitlement sync: Update-only imports now replace a member's full set of entitlements rather than only appending new ones, so stale access is removed automatically on each re-run.