Integrations
Integration Studio is now generally available
Integration Studio has moved from preview to general availability - no longer off by default, and no need to reach out to enable it. Connect any app with a documented API without waiting on an engineering cycle: an AI research agent reads the API, drafts a connector manifest, and hands it to you to review and connect.See Integration Studio for how it works.Governance
Custom access requests
Not every access request runs through your governance program - an internal tool, an app you haven’t integrated, a one-off action nobody built a workflow for. Custom Access Requests close that gap: define the form, choose the webhook that provisions and revokes access, and it runs through the same approval and audit trail as everything else.Governance
Approval chains
Not every access decision needs the same scrutiny. Approval Chains let you define the right review process for each request - one sign-off, or a chain through a manager, data owner, and security lead - with approvals that are manual, auto-approved by policy, or AI-assisted.NHI
A 360-degree view of NHI governance
See lifecycle, credential, access footprint, and impersonation data for any non-human identity in one place, instead of piecing it together across separate systems. Privilege levels, scopes, and permissions are visible alongside it, so exposure and impact are clear at a glance.NHI
NHI credential expiry workflow
Catch NHI credentials before they expire, so the integrations and automations that depend on them don’t break. Owners are notified with enough runway to rotate the credential, and if nothing happens the alert escalates to a manager or admin - so an expiring credential never slips through unnoticed.API
The Oleria API is live for customers
The API Reference is live, covering the full identity and access graph instead of a single endpoint. It documents the core resource types (accounts, employees, departments, roles, non-human identities, and more) along with the relationships between them, plus the TrustFusion query engine and Downloads.- Non-human identities are a first-class resource - list and read them the same way as any other identity type, not as a separate bolt-on.
- Every object and relationship endpoint documents its scope requirements directly, so you can request access with the right permissions the first time.
- The OpenAPI spec backing this reference stays in sync with the platform automatically, so the docs won’t drift from what the API actually returns.
Governance
Just-in-time access requests
Standing access is a standing risk. Access Requests grants access the moment it’s approved and automatically revokes it when the request expires, so access no longer lingers after the need is gone. Every request is fully audited.See Access Requests for how it works.Governance
Access bundle presets
Deciding how to group employees and what access each group needs is the hard part of an access bundle. Presets do it for you - ready-made bundles built from employee attributes like department, title, and manager, so you can roll out least-privilege access on day one without starting from a blank page.See access bundle presets for how it works.Posture
Shadow IT detection workflow
Unsanctioned SaaS applications are now caught the moment they show up. IT owners get routed visibility - including an auto-created ticket - so unmanaged apps get a decision instead of quietly becoming part of the stack.See Application Hygiene and the Detect and report Shadow IT workflow for how it works.NHI
NHI ownership workflow
Every non-human identity now gets a clear, accountable human owner, established in a fraction of the time it used to take. Oleria suggests the most likely owner automatically, with human confirmation always required before it’s final.See NHI ownership assignment for how it works.Integrations
New integrations: GCP Secret Manager, DocuSign, and more
Several integrations shipped or expanded this quarter:- Google Cloud Platform integrations now discover Secret Manager secrets as non-human identities and analyze their access graphs, without ever reading secret values.
- DocuSign moved from generic SCIM coverage to its own dedicated integration, governed under the same workflows and policies as every other connected system.
- Atlassian Cloud and Slack now support governance actions (not just read-only visibility) where the connected app’s permissions allow it.
- GreytHR and Cursor joined the application catalog.
- SCIM 2.0 provisioning for Oleria workspace users themselves - connect your identity provider to provision workspace users, map groups to roles, and deprovision access automatically as your directory changes.
NHI
AI Gateway (preview)
AI agents are starting to take real actions across your environment, which means they need the same access controls people do. AI Gateway brokers what an agent can do at the moment it acts, enforcing least privilege for non-human identities in real time instead of trusting standing credentials. Available as a preview - off by default, reach out to enable it.Integrations
Integration Studio (preview)
Point an AI research agent at an app’s API documentation and it ships a governance-grade connector the same day, with you approving every step. These connectors write back, not just read, so you can remove access from day one, and a validator outside the AI checks every draft. Available as a preview - off by default, reach out to enable it.See Integration Studio for how it works.Governance
Access reviews on Active Directory groups
Nested AD groups hide who can actually reach what. Access reviews now run directly on your AD groups, the same way they already do for your IdP groups, with peer signals surfaced to guide each reviewer’s call.See Access reviews for how it works.Governance
Access bundles with adaptive recommendations
New joiners are now provisioned automatically from your HR system. Instead of building an access list per hire, Oleria recommends a tailored bundle based on comparable peers, and the recommendation sharpens as roles shift - so joiners get least-privilege access from their first login, in minutes rather than weeks.See access bundles with adaptive recommendations for how it works.API
Oleria MCP for external AI clients
The identity intelligence you already rely on now plugs directly into the AI clients your team uses every day - Claude, ChatGPT, Cursor, and any copilot built on the open MCP spec. It’s read-only, authenticates through your existing IdP, and inherits the full access graph underneath.See Oleria MCP for how to connect it.Integrations
Slack integration
Slack is one of the most active and most overlooked surfaces in an identity security program. Oleria’s Slack integration pairs access data with real usage signals, so over-privileged accounts, dormant users, and behavioral anomalies surface automatically without manual work.See the Slack integration for setup details.Posture
Shadow IT visibility in Governance
Application Hygiene gives visibility into shadow IT applications - the unsanctioned apps users access outside your approved software catalog. Your security team can see which applications are used without IT oversight, assess their risk, and act before they become a vulnerability. No additional configuration required.See Application Hygiene for how it works.NHI
NHI Posture Overview
An instant read on the health and risk exposure of every non-human identity in your environment, across service principals, AI agents, PATs, service accounts, and more - surfacing ownership gaps, dormancy, and high-privilege access. Pin and personalize your most-used views, with pre-built options for excessive privileges, broad scope, token credentials, dormant NHIs, AI agent inventory, and unowned identities.Posture
MFA authority and identity provider visibility
Access Inventory now shows the identity provider used to authenticate each account and the MFA authority enforcing MFA for it, across both SSO and local accounts. Access Inventory also now shows which individuals are designated as owners for each group, so accountability during access reviews is clear and no group is left without an owner.See Using Access Inventory for the full list of fields.API
Copilot is now conversational
Ask follow-up questions, refine your queries, and dig deeper - Copilot remembers the context of your conversation so you don’t have to repeat yourself. Powered by the new Oleria MCP, Copilot can answer questions across your entire environment: who has access to what, how they’re using it, and what risks to prioritize.See Oleria AI for sample prompts.Integrations
Generic SCIM integration, GCP, Nudge, and Microsoft Teams
- Generic SCIM integration unlocks identity visibility and governance for any application that supports the SCIM standard, no custom connector required - including Atlassian, Databricks, Intercom, Informatica, Datadog, Zscaler, and over 100 more.
- Google Cloud Platform is now supported, extending identity governance to GCP IAM roles and GCS bucket permissions.
- Nudge joined the application catalog.
- Microsoft Teams integration brings governance notifications - pending access reviews and identity lifecycle updates - directly into Teams.
Governance
Customizable columns and smarter integration search
- Every Access Inventory and Governance page now supports customizable columns - choose the fields that matter to your workflow, hide the rest, and arrange them to fit how your team reviews access data.
- The Integrations page now supports searching by application name and filtering by category (cloud platforms, custom applications, HR systems, identity providers, on-premises applications, and SaaS applications) across the Connected, Available, and Coming Soon tabs.

