Join our Newsletter — 33% off our NHI Course

ServiceNow-Veza acquisition: what it means for identity teams

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: ServiceNow’s acquisition of Veza changes the evaluation for teams that used the platform’s access graph for cloud entitlement analysis and its newer IGA functions for lifecycle workflows, while early access features and roadmap control now sit inside a larger integration process, according to Zluri. The key issue is no longer feature parity alone, but whether identity governance can still be proven in production before organisational accountability is absorbed into a platform transition.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “What the ServiceNow-Veza Acquisition Means for Identity Teams (And Why Zluri Is Worth a Look)”.

Key questions

Q: What breaks when a newly added IGA feature has not been production hardened yet?

A: What breaks is confidence in the workflow, not just the checkbox.

Q: Why do acquisition-led identity platforms create governance risk?

A: Acquisition-led platforms can inherit different data models, audit semantics, and policy assumptions.

Q: How should security teams turn access reviews into real risk reduction?

A: Security teams should use access reviews to remove dormant access, orphaned accounts, and privileges that no longer match the work being performed.

Practitioner guidance

  • Separate entitlement analysis from lifecycle governance Map which business problems require access-graph visibility and which require joiner-mover-leaver execution, access reviews, or deprovisioning.
  • Test newly added IGA workflows under production conditions Simulate simultaneous role changes, delayed offboarding, large review sets, and multi-system write-back before treating a recently launched feature as operationally proven.
  • Verify closed-loop remediation across connected systems Confirm that review decisions and entitlement changes flow through to deprovisioning or permission removal without manual follow-up, especially for SaaS and custom applications.

Bottom line: The acquisition changes the decision from feature comparison to governance assurance, because roadmap control now sits inside a broader platform transition.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 2 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21346
 

Roadmap control becomes an identity governance issue the moment a specialist capability is absorbed into a larger platform. Once Veza sits inside ServiceNow, teams are no longer only evaluating entitlement intelligence, they are also inheriting another company’s integration priorities, support model, and release cadence. That changes the governance conversation from feature comparison to operational dependency. For identity teams, the practical conclusion is that platform ownership can alter the evidence standard for trust.

A few things that frame the scale:

A question worth separating out:

Q: What is the difference between access visibility and access enforcement?

A: Access visibility tells you what users can do, while access enforcement changes that state in the target systems. A graph can expose effective permissions without being able to remove them, and a governance workflow can revoke access without showing the full entitlement picture. Practitioners need both layers, but they solve different problems.

👉 Read our full editorial: ServiceNow-Veza acquisition shifts the identity tooling calculus


This post was modified 2 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.