August 25th, 2026

New

Improved

Mid August update

A big three-week stretch: a full pass on access reviews, Luna picking up provisioning and policy work, five new integrations, and a new terminal sign-in flow.

Access Reviews

  • Per-app reviews: A new Reviews tab lists one row per single-app review campaign — resource, frequency, progress, and due state at a glance — built for teams running lots of one-off reviews rather than a single big multi-app campaign.

  • Reviewer overrides: Route specific accounts (non-human identities, admin-level entitlements) to a different reviewer than the campaign default; the first matching rule wins.

  • Self-approval control: Approval steps now have an "Allow self-approval" switch so the person a request is for can be excluded from approving it themselves (off by default on new steps).

  • Self-review prevention: Reviewers can no longer be assigned to approve their own access. Conflicts are blocked at cycle creation with a clear message, or rerouted at runtime to the account holder's manager, the resource owner, or an org admin. Bulk decisions silently skip a reviewer's own accounts and note how many were excluded. Opt out per-cycle with "allow self-review."

  • Duplicate identities: Reviewers see one row per person instead of duplicates when someone holds more than one identity on a resource; campaign creation flags duplicates up front.

  • Exclude from a cycle: Exclude a review or a specific account from an in-progress cycle, with a required reason captured in the audit trail.

  • Escalation attribution: Decisions completed by an escalated reviewer now show an "Escalated" tag with a handoff tooltip, carried through to the evidence pack.

  • Data freshness: Review details show a "Data as of" date, source, and extraction date for imported access data.

  • Custom remediation routing: The "adjust entitlements" outcome can route to a dedicated flow configured on a resource's provisioning strategy instead of always creating an internal task.

  • Mid-cycle additions: Add resources to a review cycle that's already running, right from the cycle page — no need to wait for the next cycle. Luna can do this on request too.

  • Corrections toggle: Campaigns can now disable reviewer corrections entirely — useful for campaigns fed by integrations or controlled uploads.

  • Escalation tiers: Tiers can fire before the due date (e.g., "3 days before due"), each tier can carry its own custom message, and a new no-response tier action auto-closes undecided accounts on deadline and applies the campaign's configured remediation.

  • Evidence pack certificates now display your organization's logo.

Luna

  • Knows which admin sent each message in shared sessions, improving responses when multiple admins message Luna in one conversation.

  • Can read a resource's current access policy and apply bulk updates across many resources at once.

  • Can answer a reviewer's question directly when they flag an item instead of approving/denying, unblocking the review without an admin.

  • Confirmation cards now group related settings and show real dropdowns (e.g., seat type) instead of leaving them unset.

  • New "Setup new integration" playbook walks Luna through connecting and configuring an integration end to end.

  • After connecting a new integration, Luna checks if it supports account creation/removal and offers to build provisioning/deprovisioning flows, a provisioning strategy, managed access, and a catalog entry (new flows are created disabled for review).

  • New guided onboarding playbook for admins covering org settings, SSO, IP restrictions, notifications, and app connections.

  • Can create new custom employee fields on request (e.g., a cost centre), not just fill in existing ones.

  • Can update access review campaign settings and manage standing cover assignments from chat.

  • Can report the provisioning method assigned to each access catalog entry and flag entries with none configured.

  • New Memories section: explore what Luna knows about your org as a graph or filterable list (grouped by fact/episode/procedure/preference), with the ability to add or delete your own entries.

Provisioning & Flow Builder

  • Provisioning strategies can name a flow that auto-creates a missing account when a request is approved, instead of failing with an identity error.

  • New "Create Resource" flow action creates a resource inside a connected integration (starting with Microsoft Entra security/M365 groups) — chainable straight into a grant-access step.

  • "Get resource access" now outputs both a resource's friendly display name and its full name in one flow.

  • New licence-availability gate step: branch flows based on whether a licence has free seats.

  • Alchemer users can now be created, disabled, or updated directly from flows.

  • Scheduled flow triggers can be pinned to a timezone with automatic daylight-saving handling.

Integrations

  • Simployer One (HRIS) — new integration syncing your full employee roster for onboarding, offboarding, and provisioning.

  • Attio, Datadog, ngrok, Vercel, and Xero are now available to connect, alongside a new capabilities view in the setup wizard and integrations table showing what each integration can detect and action.

  • Google Workspace: custom member fields now appear in the field mapper and sync into Ploy (matching HiBob, Okta, Workday).

  • Google Drive: shared drives now show their organisational unit (name and path), captured automatically during scans.

  • Freshservice: flow ticket labels now sync as native tags; the Update ticket step supports setting closure fields.

  • Jira: can now connect via a service-account API token instead of OAuth for tighter least-privilege access.

  • Microsoft Entra (bring-your-own setup): scan-scope settings (users without mailboxes, guests, apps without a website) are now configurable, matching the Ploy-managed flow.

  • Dialpad is now available as an offboarding flow action.

Security & Access Control

  • Terminal sign-in approval: Employees can approve or deny Ploy CLI sign-in requests from the employee portal by entering the short code shown in their terminal, reviewing the origin address, client, and timestamp. Approved sessions stay valid up to 30 days.

  • Passkey elevation: Require a fresh passkey check before sensitive actions (offboarding, API key creation, security changes), with a configurable re-verification window. The elevation settings page lists which admins still need a passkey, and a key icon flags who already has one.

Employee Portal & Admin UX

  • Choose which sections (Home, My Access, Reviews, Tasks, Catalog) appear in the employee portal — useful for a reviews-only rollout.

  • Assignment Configuration moved to its own Settings page, with a new Issues tab (offboarded assignees, incomplete configs) and a usage view showing where a configuration is referenced.

  • Standing reviewer swaps can carry an optional expiry date, so temporary reassignments (e.g., parental leave) end automatically.

  • Resource access records show a new Story timeline plus Field origins, surfacing which integration last confirmed each piece of data and when.

  • Notifications to Slack, Teams, and email (including from Luna) now render headings, lists, tables, and images properly instead of raw formatting characters.

  • Identity Inventory gained bulk actions to associate/remove employee links, matching the older Identities list.

  • Shift-click range selection now works across every dashboard table.

  • Saved private resource views show a "Private" badge, with an edit button for name, icon, colour, and visibility.

Billing & API

  • App Spend billing frequency now includes "Biannually" (every 6 months), with annual cost projections updating automatically.

  • Identity segments API's update endpoint is now full-replace (omitted fields are cleared); duplicate segment names return a clear conflict response.