August 27th, 2026
Improved

Luna can now help you build and generate flows for you automatically, simply describe what you want and watch Luna build it for you.

Luna has access to all the tools and learnings from the 1000s of flows weβve implemented at Ploy to ensure you get the most optimised outcome, tailored to your use case (as always). This is a beta feature so as always, weβd love to get any and all feedback you have.
August 27th, 2026

A wide release across access policies, integrations, flows, and the employee portal:
Access conditions: On-call status is now available as an access condition, automatically revoking break-glass access once a shift ends.
Active Access: You can now mark a stuck access row as deprovisioned, from the row menu or in bulk, without Ploy contacting the provider.
Redis Cloud: New integration for Redis Cloud, syncing team members and roles so you can review and revoke access alongside your other apps.
Flows: The "Update user in integration" action can now write to your organization's custom Google Workspace profile fields, picked from a live dropdown.
Luna: Steering chat on an in-progress agent run now accepts file attachments, and mentions in Luna chat now render as chips with a photo or app icon.
Employee portal: Time-limited access requests show clearer countdown text near expiry, and resources offered through multiple catalogs now show as already covered once requested.
August 25th, 2026
New
Improved

A big three-week stretch: a full pass on access reviews, Luna picking up provisioning and policy work, five new integrations, and a new terminal sign-in flow.
Per-app reviews: A new Reviews tab lists one row per single-app review campaign β resource, frequency, progress, and due state at a glance β built for teams running lots of one-off reviews rather than a single big multi-app campaign.
Reviewer overrides: Route specific accounts (non-human identities, admin-level entitlements) to a different reviewer than the campaign default; the first matching rule wins.
Self-approval control: Approval steps now have an "Allow self-approval" switch so the person a request is for can be excluded from approving it themselves (off by default on new steps).
Self-review prevention: Reviewers can no longer be assigned to approve their own access. Conflicts are blocked at cycle creation with a clear message, or rerouted at runtime to the account holder's manager, the resource owner, or an org admin. Bulk decisions silently skip a reviewer's own accounts and note how many were excluded. Opt out per-cycle with "allow self-review."
Duplicate identities: Reviewers see one row per person instead of duplicates when someone holds more than one identity on a resource; campaign creation flags duplicates up front.
Exclude from a cycle: Exclude a review or a specific account from an in-progress cycle, with a required reason captured in the audit trail.
Escalation attribution: Decisions completed by an escalated reviewer now show an "Escalated" tag with a handoff tooltip, carried through to the evidence pack.
Data freshness: Review details show a "Data as of" date, source, and extraction date for imported access data.
Custom remediation routing: The "adjust entitlements" outcome can route to a dedicated flow configured on a resource's provisioning strategy instead of always creating an internal task.
Mid-cycle additions: Add resources to a review cycle that's already running, right from the cycle page β no need to wait for the next cycle. Luna can do this on request too.
Corrections toggle: Campaigns can now disable reviewer corrections entirely β useful for campaigns fed by integrations or controlled uploads.
Escalation tiers: Tiers can fire before the due date (e.g., "3 days before due"), each tier can carry its own custom message, and a new no-response tier action auto-closes undecided accounts on deadline and applies the campaign's configured remediation.
Evidence pack certificates now display your organization's logo.
Knows which admin sent each message in shared sessions, improving responses when multiple admins message Luna in one conversation.
Can read a resource's current access policy and apply bulk updates across many resources at once.
Can answer a reviewer's question directly when they flag an item instead of approving/denying, unblocking the review without an admin.
Confirmation cards now group related settings and show real dropdowns (e.g., seat type) instead of leaving them unset.
New "Setup new integration" playbook walks Luna through connecting and configuring an integration end to end.
After connecting a new integration, Luna checks if it supports account creation/removal and offers to build provisioning/deprovisioning flows, a provisioning strategy, managed access, and a catalog entry (new flows are created disabled for review).
New guided onboarding playbook for admins covering org settings, SSO, IP restrictions, notifications, and app connections.
Can create new custom employee fields on request (e.g., a cost centre), not just fill in existing ones.
Can update access review campaign settings and manage standing cover assignments from chat.
Can report the provisioning method assigned to each access catalog entry and flag entries with none configured.
New Memories section: explore what Luna knows about your org as a graph or filterable list (grouped by fact/episode/procedure/preference), with the ability to add or delete your own entries.
Provisioning strategies can name a flow that auto-creates a missing account when a request is approved, instead of failing with an identity error.
New "Create Resource" flow action creates a resource inside a connected integration (starting with Microsoft Entra security/M365 groups) β chainable straight into a grant-access step.
"Get resource access" now outputs both a resource's friendly display name and its full name in one flow.
New licence-availability gate step: branch flows based on whether a licence has free seats.
Alchemer users can now be created, disabled, or updated directly from flows.
Scheduled flow triggers can be pinned to a timezone with automatic daylight-saving handling.
Simployer One (HRIS) β new integration syncing your full employee roster for onboarding, offboarding, and provisioning.
Attio, Datadog, ngrok, Vercel, and Xero are now available to connect, alongside a new capabilities view in the setup wizard and integrations table showing what each integration can detect and action.
Google Workspace: custom member fields now appear in the field mapper and sync into Ploy (matching HiBob, Okta, Workday).
Google Drive: shared drives now show their organisational unit (name and path), captured automatically during scans.
Freshservice: flow ticket labels now sync as native tags; the Update ticket step supports setting closure fields.
Jira: can now connect via a service-account API token instead of OAuth for tighter least-privilege access.
Microsoft Entra (bring-your-own setup): scan-scope settings (users without mailboxes, guests, apps without a website) are now configurable, matching the Ploy-managed flow.
Dialpad is now available as an offboarding flow action.
Terminal sign-in approval: Employees can approve or deny Ploy CLI sign-in requests from the employee portal by entering the short code shown in their terminal, reviewing the origin address, client, and timestamp. Approved sessions stay valid up to 30 days.
Passkey elevation: Require a fresh passkey check before sensitive actions (offboarding, API key creation, security changes), with a configurable re-verification window. The elevation settings page lists which admins still need a passkey, and a key icon flags who already has one.
Choose which sections (Home, My Access, Reviews, Tasks, Catalog) appear in the employee portal β useful for a reviews-only rollout.
Assignment Configuration moved to its own Settings page, with a new Issues tab (offboarded assignees, incomplete configs) and a usage view showing where a configuration is referenced.
Standing reviewer swaps can carry an optional expiry date, so temporary reassignments (e.g., parental leave) end automatically.
Resource access records show a new Story timeline plus Field origins, surfacing which integration last confirmed each piece of data and when.
Notifications to Slack, Teams, and email (including from Luna) now render headings, lists, tables, and images properly instead of raw formatting characters.
Identity Inventory gained bulk actions to associate/remove employee links, matching the older Identities list.
Shift-click range selection now works across every dashboard table.
Saved private resource views show a "Private" badge, with an edit button for name, icon, colour, and visibility.
App Spend billing frequency now includes "Biannually" (every 6 months), with annual cost projections updating automatically.
Identity segments API's update endpoint is now full-replace (omitted fields are cleared); duplicate segment names return a clear conflict response.
August 6th, 2026
New
Improved

Ploy now connects to Alchemer and ships improvements across employee profiles, access reviews, Segments, and Luna.
Alchemer: Ploy now scans your Alchemer account for users, teams, and licence seats and supports provisioning and deprovisioning directly from Ploy.
DocuSign: You can now provision and deprovision users directly from Ploy, and manage their group memberships. Invite someone by email (DocuSign sends them an activation link), close their account to revoke all access, or move them between groups, all without leaving Ploy.
Luna: Luna now has a separate read permission. Grant it to colleagues who need to browse and read existing chats without being able to start new sessions or send messages. The message composer stays hidden for read-only users.
Employee Resources: The Resources tab on an employee's profile now has a Dynamic membership filter. Use it to isolate groups where membership is controlled automatically by rules in Microsoft or Okta, or hide those groups to focus on manually-managed access.
Licence availability check: A new gate step in the flow builder lets you branch based on whether a specific licence has free seats. Choose a resource and one of its licences, set the direction (available or not), and the step passes current seat counts to downstream steps for end-to-end seat-rotation flows.
Range selection: Hold Shift and click a second row to select everything in between, across every table in the dashboard.
Saved resource views: Private saved views in Resources now show a "Private" badge. An edit button lets you update a view's name, icon, colour, or visibility at any time after saving.
August 3rd, 2026
New

Last week's release adds a full OneLogin integration, richer Luna responses and tools, and improvements across access reviews and the app catalog.
OneLogin: Ploy now integrates with OneLogin as a full IdP. Connect your tenant to pull in users, MFA enrollment and methods, roles, and app assignments, plus last sign-in activity. Open the Integrations page to get started.
Luna: Responses now render tables, cards, and structured blocks directly in the chat, at their natural position in the conversation, instead of inside collapsed thinking steps. The underlying model has also been upgraded for sharper, more reliable answers.
Access reviews: Reviewers in the employee portal now land on the full entitlements list by default when opening a review, with Luna's recommendations one click away via a tab at the top.
Agent actions: Luna agents can now suspend and restore user accounts at connected integrations as part of automated workflows, with confirmation required before each action and every suspension recorded in the audit trail.
Catalog search: The app catalog in the browser extension now matches underlying resources when searching, so "billing" surfaces the AWS tile via its Billing resource, with a hint showing what matched.
Assignment configs API: Reviewer routing rules can now be created, updated, and deleted via the public API, making them straightforward to manage from external tooling.
Escalation notifications: Escalation message wording can now be customised for access reviews. Open the escalation editor and choose "Customise the message" to edit the notification template that reaches reviewers at each stage and save it for reuse.
Access reviews: Reviewers in the employee portal now see department, job title, and last-active date columns switched on by default, so relevant context is visible without manually enabling columns.
Flows: You can now filter Microsoft and Entra accounts by guest status in flows, making it straightforward to target low-usage guest accounts for automated action.
Luna: Luna can now find failed or stalled access-request provisioning and retry it on demand, completing the full lifecycle from approval through to recovery.
App catalog: Employees browsing the app catalog now see a badge on any app they already have access to, preventing accidental duplicate requests.
Public API: New endpoints let you read and manage provisioning strategies and their folders via a dedicated API scope, and manage resource sources of truth per row via the API.
Luna: CSV imports, Luna can now preview what a CSV mapping will produce before you run it, showing which rows will import, merge, or be skipped and why. Ask Luna to load a saved import template or save the current mapping for reuse in later imports.
Luna: catalog management, Luna can now archive a catalog item so employees no longer see it in their access catalog, and permanently delete an access policy that is no longer needed.
Terraform and Public API improvements: You can now configure your core Ploy resources via Terraform. Contact your account rep to get access to the provider
Access catalogs in the API, Create, update, publish, and archive access catalogs and their items from Terraform or your own tooling, including visibility rules by department, group, or profile, and the access options offered within each item.
Resource access policies in the API, A resource's full access policy (approval stages, time limits, provisioning setup, and eligibility conditions) can now be defined and managed from infrastructure-as-code.
Organisation settings in the API, Internal email domains and IP restrictions for the admin dashboard and employee portal are now manageable via the API, making them part of your version-controlled configuration.
July 28th, 2026
New
Improved

Ploy now connects to Freshservice for ticketing, plus a range of other improvements.
Freshservice Ticketing integration: You can now integrate with Freshservice as your ticketing system, helping you manage access requests and other identity related issues in your native ITSM, or use it as a centralised backup for identity related work.
API key management: Existing keys can now be edited (rename or change permissions) without revoking them. Scope options are grouped by category in the picker.
Tags API: Create, update, and delete tags via the Ploy API using a key with tags permissions.
Access review scoping: Campaigns can now be scoped to access rows carrying a specific tag, not just tags on the employee or resource.
Luna: Luna can now draw on Ploy's accumulated knowledge about your environment when answering questions.
User importer: Human identities can now be imported using an external ID alone, without an email address.
Employee page: "Last Working Day" is now available as a column in the custom view picker.
Profiles in the public API: create, read, update, and delete profiles via the API, with the full filter definition included.
Resource and integration lookups: the resources endpoint now accepts exact-match filters by name, external ID, domain, and application status; new read-only endpoints for integrations and messaging channels are also available.
Jira knowledge source, service-account auth: when setting up Jira as a knowledge source, you can now choose between OAuth and a service-account API token scoped to specific projects, so Ploy can only read what that account can access.
Signup source on active access: the origin of a shadow-IT signup, captured by the browser extension, now stays visible after access moves to the active tab, so you can always trace how it started.
API docs: nested object schemas now expand inline, and the navigation panel scrolls independently of the content panes.
July 24th, 2026
New

A large set of updates shipped the last few days headlined by our changes to access reviews.
Multi-stage reviews: You can now have multiple stages of reviews, on all or a subset of entitlements allowing support for usecases such as βManagers revieiwing employee accessβ followed by an SME reviewing admin only roles
Escalation paths: Automatically re-assign reviews if users donβt complete in X days or notify their manager
Extension Requests: Users can request an extension if they need more time
Queries: Reviewers can also make queries, such as clarifying questions to your IT admins while completing reviews.
Bulk retry provisioning: Filter the access request list by status, select failed requests, and retry their provisioning in one action.
Tag management: Create, edit, and color-code tags from the Settings page. Assignment configurations can now be deleted directly from the configuration modal.
Tasks: Filter the unified Tasks list by app or resource.
User importer: Human accounts can now be imported using an Ext ID alone, without an email address.
Identities: Bulk convert human identities to non-human identities from the Inventory page.
July 22nd, 2026
New

You can now stream your Ploy audit log to an external SIEM, with Microsoft Sentinel as the first destination.
SIEM integrations: Connect from the new SIEM tab on the Integrations page. The wizard uses federated identity credentials so no client secrets are stored.
AI agent visibility: Ploy now tracks Copilot and Claude agents, so you can see which are active, who is using them, and what resources they reach on behalf of users.
HiBob: Mobile and work phone numbers now sync from HiBob for use in flows and automations.
Agent access view: The access-on-behalf-of panel on an agent page now groups entries by permission, with stacked member avatars replacing one row per individual account.
Employee portal: Employees outside an approved IP range now see a clear screen directing them to connect via VPN or contact IT, instead of a generic error.
July 21st, 2026
New

Four improvements shipped today covering security, automation, access management, and the Luna experience.
IP restrictions: You can now limit which networks can reach Ploy. In Settings > Authentication, configure separate IP allowlists for the admin dashboard and for the employee portal and browser extension. Leave a list empty for no restriction, and a warning flags if a saved range would lock you out of the dashboard.
Custom fields in flows: Custom employee fields now appear as audience filter options and as a flow trigger, so you can build flows that target or activate based on fields specific to your org, like a cost center or contract type.
Expiring Soon: The Managed Access > Expiring Soon page now has per-row Manage access and Deprovision access buttons, plus a bulk deprovision option when you select multiple entries, so you can act without opening the resource page first.
Luna and agent runs: The Luna indicator is now animated across the sidebar, chat, and agent pages, reflecting live state. On the agent runs page, task cards expand inline to show session detail, and the runs navigator is now called Active Runs.
July 20th, 2026
Improved

You can now see on-call status in employee profiles, delete Entra accounts and Exchange shared mailboxes from flows, and import users in update-only mode.
On-call status: Employee profiles now show whether someone is currently on call, pulled from your Grafana IRM or PagerDuty connection. A green badge marks an active shift; the row only appears for members on a rota. "Is on call" is also available as a filter when building segments.
Entra and Exchange deletion in flows: A new "Delete shared mailbox" step is available in the flow builder for removing Exchange shared mailboxes. The "Remove user from integration" step now also supports deleting an Entra account directly.
User import update-only mode: When importing users via CSV, you can turn on "Only update existing users" at the mapping step. Existing records are refreshed in place; rows that don't match anyone are skipped, nothing new is created, and the grant date and identity type become optional.
Google Workspace: The invite-external-user flow action now supports Google Workspace alongside the existing Microsoft support. Guests are automatically detected in scans and attributed to their real external email address.
Unmanaged accounts: You can now select multiple accounts on the Unmanaged tab and convert them to non-human identities in bulk, rather than one at a time.
Low usage detection: When previewing how many accounts a low-usage threshold would flag on a resource, you can now click "View accounts" to see the full list, each account's last activity date, and when access was first granted.