Changelog

Follow new updates and improvements to Ploy.

July 24th, 2026

New

A large set of updates shipped the last few days headlined by our changes to access reviews.

Access reviews:

  • Multi-stage reviews: You can now have multiple stages of reviews, on all or a subset of entitlements allowing support for usecases such as β€˜Managers revieiwing employee access’ followed by an SME reviewing admin only roles

  • Escalation paths: Automatically re-assign reviews if users don’t complete in X days or notify their manager

  • Extension Requests: Users can request an extension if they need more time

  • Queries: Reviewers can also make queries, such as clarifying questions to your IT admins while completing reviews.

And a lot more

  • Bulk retry provisioning: Filter the access request list by status, select failed requests, and retry their provisioning in one action.

  • Tag management: Create, edit, and color-code tags from the Settings page. Assignment configurations can now be deleted directly from the configuration modal.

  • Tasks: Filter the unified Tasks list by app or resource.

  • User importer: Human accounts can now be imported using an Ext ID alone, without an email address.

  • Identities: Bulk convert human identities to non-human identities from the Inventory page.

July 22nd, 2026

New

You can now stream your Ploy audit log to an external SIEM, with Microsoft Sentinel as the first destination.

  • SIEM integrations: Connect from the new SIEM tab on the Integrations page. The wizard uses federated identity credentials so no client secrets are stored.

  • AI agent visibility: Ploy now tracks Copilot and Claude agents, so you can see which are active, who is using them, and what resources they reach on behalf of users.

  • HiBob: Mobile and work phone numbers now sync from HiBob for use in flows and automations.

  • Agent access view: The access-on-behalf-of panel on an agent page now groups entries by permission, with stacked member avatars replacing one row per individual account.

  • Employee portal: Employees outside an approved IP range now see a clear screen directing them to connect via VPN or contact IT, instead of a generic error.

July 21st, 2026

New

Four improvements shipped today covering security, automation, access management, and the Luna experience.

  • IP restrictions: You can now limit which networks can reach Ploy. In Settings > Authentication, configure separate IP allowlists for the admin dashboard and for the employee portal and browser extension. Leave a list empty for no restriction, and a warning flags if a saved range would lock you out of the dashboard.

  • Custom fields in flows: Custom employee fields now appear as audience filter options and as a flow trigger, so you can build flows that target or activate based on fields specific to your org, like a cost center or contract type.

  • Expiring Soon: The Managed Access > Expiring Soon page now has per-row Manage access and Deprovision access buttons, plus a bulk deprovision option when you select multiple entries, so you can act without opening the resource page first.

  • Luna and agent runs: The Luna indicator is now animated across the sidebar, chat, and agent pages, reflecting live state. On the agent runs page, task cards expand inline to show session detail, and the runs navigator is now called Active Runs.

July 20th, 2026

Improved

You can now see on-call status in employee profiles, delete Entra accounts and Exchange shared mailboxes from flows, and import users in update-only mode.

  • On-call status: Employee profiles now show whether someone is currently on call, pulled from your Grafana IRM or PagerDuty connection. A green badge marks an active shift; the row only appears for members on a rota. "Is on call" is also available as a filter when building segments.

  • Entra and Exchange deletion in flows: A new "Delete shared mailbox" step is available in the flow builder for removing Exchange shared mailboxes. The "Remove user from integration" step now also supports deleting an Entra account directly.

  • User import update-only mode: When importing users via CSV, you can turn on "Only update existing users" at the mapping step. Existing records are refreshed in place; rows that don't match anyone are skipped, nothing new is created, and the grant date and identity type become optional.

  • Google Workspace: The invite-external-user flow action now supports Google Workspace alongside the existing Microsoft support. Guests are automatically detected in scans and attributed to their real external email address.

  • Unmanaged accounts: You can now select multiple accounts on the Unmanaged tab and convert them to non-human identities in bulk, rather than one at a time.

  • Low usage detection: When previewing how many accounts a low-usage threshold would flag on a resource, you can now click "View accounts" to see the full list, each account's last activity date, and when access was first granted.

July 16th, 2026

Users can now select which of their identity they are making the request for when making an access request as well as making requests on behalf of owned NHISs, alongside other improvements across the user importer, Google Drive, and the access catalog editor.

  • Access requests: Employees can pick which account or service account they own gets the grant, per resource. People with multiple accounts on the same integration, or who own service accounts, see a dropdown on each item in the request basket. Admins see "Requested by" and "Requested for" as separate rows in the request detail panel.

  • User importer: Both the column-mapping dropdown and the person-preview picker now have a type-to-filter search box. A new "Apply to more columns" option copies one column's mapping to several others at once, and a "Use column name as type" checkbox auto-fills the entitlement type from the mapped column name.

  • Google Drive: Shared drives now show the org unit they belong to as a resource attribute. Luna can filter drives by org unit when answering questions about specific areas of your Drive environment.

  • Access catalogs: The catalog editor now has a "View in portal" button that opens the catalog directly in the employee portal, so you can preview exactly what employees see.

  • On-call status: Employee profiles now show whether someone is currently on call, pulled from your Grafana IRM or PagerDuty connection. A green badge marks an active shift; the row only appears for members on a rota. "Is on call" is also available as a filter when building segments.

  • Entra and Exchange deletion in flows: A new "Delete shared mailbox" step is available in the flow builder for removing Exchange shared mailboxes. The "Remove user from integration" step now also supports deleting an Entra account directly.

July 14th, 2026

New

Improved

A lot has changed over the past couple of days here at Ploy. Let’s dive in.

  • AI agents: AI agents (Copilot Studio, custom GPTs, and others) now have dedicated resource pages in the admin dashboard. Each shows the platform the agent runs on, its direct app permissions, delegated access held on behalf of users, who is using it, and a visual access graph. To get access please contact your account manager

  • Microsoft own-app setup: When connecting Microsoft, you can now use your own Entra app registration instead of Ploy's managed app. A setup wizard covers capability selection, the app manifest, and the Azure configuration values, with a toggle to enable or disable all optional permissions at once.

  • Luna: Reports can now filter apps by tag dynamically, so querying for "procured" apps (or any other tag) always reflects the current tagged set rather than a stale list.

  • Edge on Mac: A deployment profile for Edge on Mac is now available, letting admins push the Ploy extension to managed Mac devices running Microsoft Edge.

  • Custom employee fields: Define custom fields for employee profiles from the Employee Fields settings page, pick from text, number, date, select, or yes/no types, and connect each to HiBob, Okta, or another integration so values sync automatically. Fields appear in a dedicated section on every employee profile.

  • Agent runs and success criteria: Agent detail pages now show a success scorecard for each defined criterion, a run history with declared outcomes and confidence level, and a full activity timeline. Non-human identities can also now submit access requests using dedicated API keys, which appear in the standard review queue.

  • Multi-file app fields: App custom fields can now hold multiple files, letting you attach several contracts or documents to a single field without overwriting previous uploads.

  • Integrations: BrowserStack service accounts now appear as non-human identities in Ploy. DigiCert now captures last-login dates for usage tracking. Microsoft enterprise app service principals now show the application permissions they hold. AWS classic IAM group memberships can now be provisioned directly.

  • Access policies: You can now delete an access policy directly from the resource detail view or the managed resources table. Ploy checks for active access reviews and open requests first and blocks deletion until those are resolved.

  • Flows: Yes/No confirmation steps now support a "No response" path. Set a timeout in minutes, hours, or days, and your flow continues automatically if the recipient never clicks Yes or No.

  • Microsoft guest accounts: Ploy now shows the sponsor for each Microsoft Entra B2B guest, the person in your organisation responsible for that account. Their name and email appear on the guest's identity record, and Luna can reach out to them when a guest account goes dormant.

  • Custom integration logos: When configuring a custom integration, you can now search Ploy's app logo library and pick a matching logo. It then appears consistently across cards, resource rows, and graphs.

July 8th, 2026

New

Ploy shipped two new capabilities today alongside several reliability fixes.

  • Jira sub-tasks: Using flows you can now create Jira sub-tasks

  • Luna file attachments: Employees chatting with Luna in the employee portal can now attach files alongside their messages. PDFs, spreadsheets, Word documents, images, and CSVs are all supported, up to 4.5 MB per file.

  • CSV entitlement sync: Update-only imports now replace a member's full set of entitlements rather than only appending new ones, so stale access is removed automatically on each re-run.

July 7th, 2026

New

Improved

There’s been a lot shipped in Ploy over the last 7 days, let’s dive in ⬇️

  • Luna access requests: Requesting access for shorter windows, such as a few hours, now works correctly when chatting with Luna in Slack or Teams.

  • OneTrust: Login activity now flows into Ploy when the required permission is enabled in OneTrust, so you can see who is actively signing in alongside your full user directory.

  • Employee profile: The Resources tab now shows a Type column and lets you filter by resource type or integration, making it easier to review what kind of access an employee holds.

  • User importer: Ignore Rows now supports additional matching conditions, including "contains", "is one of", "is set", and "is not set", so you can filter rows without pre-processing your CSV.

  • Okta: Fixed a scan issue where the event log could stall on empty filtered time windows, causing outdated events to replay on every scan cycle.

  • Compliance segment templates: You can now create segments from pre-built compliance-framework templates. On the Segments page, choose "Create from compliance framework" to browse templates mapped to SOC 2, ISO 27001, CIS Controls, and more, with Google and Microsoft vendor packs included. Each card shows a live match count for your org. Select any number and bulk-create them in one click, or customize one before saving.

  • Claude.ai seat tracking: The Anthropic integration now shows a seat licence view: purchased vs active seats, cost per seat (defaulting to $20 if left blank), and a savings breakdown by usage tier. Set a minimum daily token threshold to define what counts as active for your org.

  • Access request notifications: The Managed Access "Notifications" tab (previously "Config") now surfaces opt-in notification types, including a new option to notify your team when a request is submitted.

  • New Relic: Ploy can now create and remove users and manage group membership in New Relic, making it a fully managed integration.

  • TestRail: Create and remove users, manage project access, and search your user base from Luna.

  • Confluent: Ploy can now invite users and search for existing users in Confluent.

  • GitLab: Bulk user search is now available across your configured groups and organisations.

  • Team member permissions: Granting access directly (outside of an approval policy) is now a separate, opt-in permission. Standard seats no longer have it by default; enable it per person in the permissions editor.

  • HiBob: Custom fields with human-readable names now sync into Ploy correctly.

  • Exchange: The setup wizard no longer requires you to grant Ploy the Exchange Administrator role. It now displays a PowerShell script you fill in with your Entra Object ID and copy straight to your terminal, giving Ploy only the permissions it actually needs.

  • Luna: You can now ask Luna to find identities by a specific MFA method, such as everyone who authenticates by SMS or passkey, rather than just checking whether MFA is on or off.

  • Low-usage trigger testing: The member field when testing a Low Usage flow trigger is now optional. Leave it blank and Ploy returns the full list of members who would trigger for that app, so you can validate the trigger at a glance without picking a specific person.

  • Saved CSV import mappings: You can now save a column-mapping configuration during a user import, name it, and reload it on future imports. Mappings are shared across your org, so any admin can reuse a setup someone else has already defined.

  • Employee status history: Hovering the Active, Inactive, or Onboarding badge on an employee's profile now shows a timeline of who or what changed that status and when.

  • Suggested alternatives: Blocked and unsanctioned apps can have alternatives set from the app details panel, pointing employees toward approved options.

  • Luna: Image attachments now preview correctly in chat. The composer and attachment tiles have a refreshed look, and trust level and usage stats now appear below the composer across all chat surfaces.

  • Report table widgets: Report table widgets now show up to 300 rows, up from 100.

  • Segments: Service accounts now display their account name in a segment's member list instead of showing the integration they were sourced from.

  • Custom connectors: You can now delete a connector from the custom integrations tab, which revokes its API keys and archives its linked integrations. The tab has also been redesigned with clearer health and status information at a glance.

  • Reports: Table widgets now include a download button to export the data as a CSV file.

July 1st, 2026

New

Access review campaigns now support a "Record decisions only" mode. Enable it in the campaign wizard to capture reviewer decisions without any automatic follow-up: no deprovisioning and no entitlement adjustment tasks. Templates display a badge so it is always clear which campaigns run in record-only mode.

  • New Relic: Ploy can now create and remove users and manage group membership in New Relic, making it a fully managed integration.

  • TestRail: Create and remove users, manage project access, and search your user base from Luna.

  • Confluent: Ploy can now invite users and search for existing users in Confluent.

  • GitLab: Bulk user search is now available across your configured groups and organisations.

  • Team member permissions: Granting access directly (outside of an approval policy) is now a separate, opt-in permission. Standard seats no longer have it by default; enable it per person in the permissions editor.

  • Audit log: Opening a log entry with a payload no longer crashes the page.

  • HiBob: Custom fields with human-readable names (such as team or pod fields) now sync into Ploy correctly.

  • Expiring access reminders: Employee notifications now list expiring grants in the correct chronological order.

June 30th, 2026

Improved

Two new integrations are live alongside richer Microsoft identity data and several bug fixes.

  • BrowserStack: Ploy now scans your BrowserStack organisation for users, their access roles (owner, admin, user), and license assignments.

  • DigiCert CertCentral: Ploy now scans your CertCentral account for users, app access, and access roles.

  • Microsoft identities: Identity detail pages now show last non-interactive sign-in separately from last active, a useful signal for service accounts that only authenticate silently. New filter options include on-premises sync status, service principal type, and SSO mode.

  • Access review exports: The CSV download now includes remediation type, status, due date, and completion date columns so you can track which deprovisioning and entitlement-change tasks remain outstanding after decisions are recorded.

  • Various Bug fixes