August 25th, 2026
New
Improved

A big three-week stretch: a full pass on access reviews, Luna picking up provisioning and policy work, five new integrations, and a new terminal sign-in flow.
Per-app reviews: A new Reviews tab lists one row per single-app review campaign — resource, frequency, progress, and due state at a glance — built for teams running lots of one-off reviews rather than a single big multi-app campaign.
Reviewer overrides: Route specific accounts (non-human identities, admin-level entitlements) to a different reviewer than the campaign default; the first matching rule wins.
Self-approval control: Approval steps now have an "Allow self-approval" switch so the person a request is for can be excluded from approving it themselves (off by default on new steps).
Self-review prevention: Reviewers can no longer be assigned to approve their own access. Conflicts are blocked at cycle creation with a clear message, or rerouted at runtime to the account holder's manager, the resource owner, or an org admin. Bulk decisions silently skip a reviewer's own accounts and note how many were excluded. Opt out per-cycle with "allow self-review."
Duplicate identities: Reviewers see one row per person instead of duplicates when someone holds more than one identity on a resource; campaign creation flags duplicates up front.
Exclude from a cycle: Exclude a review or a specific account from an in-progress cycle, with a required reason captured in the audit trail.
Escalation attribution: Decisions completed by an escalated reviewer now show an "Escalated" tag with a handoff tooltip, carried through to the evidence pack.
Data freshness: Review details show a "Data as of" date, source, and extraction date for imported access data.
Custom remediation routing: The "adjust entitlements" outcome can route to a dedicated flow configured on a resource's provisioning strategy instead of always creating an internal task.
Mid-cycle additions: Add resources to a review cycle that's already running, right from the cycle page — no need to wait for the next cycle. Luna can do this on request too.
Corrections toggle: Campaigns can now disable reviewer corrections entirely — useful for campaigns fed by integrations or controlled uploads.
Escalation tiers: Tiers can fire before the due date (e.g., "3 days before due"), each tier can carry its own custom message, and a new no-response tier action auto-closes undecided accounts on deadline and applies the campaign's configured remediation.
Evidence pack certificates now display your organization's logo.
Knows which admin sent each message in shared sessions, improving responses when multiple admins message Luna in one conversation.
Can read a resource's current access policy and apply bulk updates across many resources at once.
Can answer a reviewer's question directly when they flag an item instead of approving/denying, unblocking the review without an admin.
Confirmation cards now group related settings and show real dropdowns (e.g., seat type) instead of leaving them unset.
New "Setup new integration" playbook walks Luna through connecting and configuring an integration end to end.
After connecting a new integration, Luna checks if it supports account creation/removal and offers to build provisioning/deprovisioning flows, a provisioning strategy, managed access, and a catalog entry (new flows are created disabled for review).
New guided onboarding playbook for admins covering org settings, SSO, IP restrictions, notifications, and app connections.
Can create new custom employee fields on request (e.g., a cost centre), not just fill in existing ones.
Can update access review campaign settings and manage standing cover assignments from chat.
Can report the provisioning method assigned to each access catalog entry and flag entries with none configured.
New Memories section: explore what Luna knows about your org as a graph or filterable list (grouped by fact/episode/procedure/preference), with the ability to add or delete your own entries.
Provisioning strategies can name a flow that auto-creates a missing account when a request is approved, instead of failing with an identity error.
New "Create Resource" flow action creates a resource inside a connected integration (starting with Microsoft Entra security/M365 groups) — chainable straight into a grant-access step.
"Get resource access" now outputs both a resource's friendly display name and its full name in one flow.
New licence-availability gate step: branch flows based on whether a licence has free seats.
Alchemer users can now be created, disabled, or updated directly from flows.
Scheduled flow triggers can be pinned to a timezone with automatic daylight-saving handling.
Simployer One (HRIS) — new integration syncing your full employee roster for onboarding, offboarding, and provisioning.
Attio, Datadog, ngrok, Vercel, and Xero are now available to connect, alongside a new capabilities view in the setup wizard and integrations table showing what each integration can detect and action.
Google Workspace: custom member fields now appear in the field mapper and sync into Ploy (matching HiBob, Okta, Workday).
Google Drive: shared drives now show their organisational unit (name and path), captured automatically during scans.
Freshservice: flow ticket labels now sync as native tags; the Update ticket step supports setting closure fields.
Jira: can now connect via a service-account API token instead of OAuth for tighter least-privilege access.
Microsoft Entra (bring-your-own setup): scan-scope settings (users without mailboxes, guests, apps without a website) are now configurable, matching the Ploy-managed flow.
Dialpad is now available as an offboarding flow action.
Terminal sign-in approval: Employees can approve or deny Ploy CLI sign-in requests from the employee portal by entering the short code shown in their terminal, reviewing the origin address, client, and timestamp. Approved sessions stay valid up to 30 days.
Passkey elevation: Require a fresh passkey check before sensitive actions (offboarding, API key creation, security changes), with a configurable re-verification window. The elevation settings page lists which admins still need a passkey, and a key icon flags who already has one.
Choose which sections (Home, My Access, Reviews, Tasks, Catalog) appear in the employee portal — useful for a reviews-only rollout.
Assignment Configuration moved to its own Settings page, with a new Issues tab (offboarded assignees, incomplete configs) and a usage view showing where a configuration is referenced.
Standing reviewer swaps can carry an optional expiry date, so temporary reassignments (e.g., parental leave) end automatically.
Resource access records show a new Story timeline plus Field origins, surfacing which integration last confirmed each piece of data and when.
Notifications to Slack, Teams, and email (including from Luna) now render headings, lists, tables, and images properly instead of raw formatting characters.
Identity Inventory gained bulk actions to associate/remove employee links, matching the older Identities list.
Shift-click range selection now works across every dashboard table.
Saved private resource views show a "Private" badge, with an edit button for name, icon, colour, and visibility.
App Spend billing frequency now includes "Biannually" (every 6 months), with annual cost projections updating automatically.
Identity segments API's update endpoint is now full-replace (omitted fields are cleared); duplicate segment names return a clear conflict response.