TL;DR: ServiceNow’s acquisition of Veza changes the evaluation for teams that used the platform’s access graph for cloud entitlement analysis and its newer IGA functions for lifecycle workflows, while early access features and roadmap control now sit inside a larger integration process, according to Zluri. The key issue is no longer feature parity alone, but whether identity governance can still be proven in production before organisational accountability is absorbed into a platform transition.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “What the ServiceNow-Veza Acquisition Means for Identity Teams (And Why Zluri Is Worth a Look)”.
Key questions
Q: What breaks when a newly added IGA feature has not been production hardened yet?
A: What breaks is confidence in the workflow, not just the checkbox.
Q: Why do acquisition-led identity platforms create governance risk?
A: Acquisition-led platforms can inherit different data models, audit semantics, and policy assumptions.
Q: How should security teams turn access reviews into real risk reduction?
A: Security teams should use access reviews to remove dormant access, orphaned accounts, and privileges that no longer match the work being performed.
Practitioner guidance
- Separate entitlement analysis from lifecycle governance Map which business problems require access-graph visibility and which require joiner-mover-leaver execution, access reviews, or deprovisioning.
- Test newly added IGA workflows under production conditions Simulate simultaneous role changes, delayed offboarding, large review sets, and multi-system write-back before treating a recently launched feature as operationally proven.
- Verify closed-loop remediation across connected systems Confirm that review decisions and entitlement changes flow through to deprovisioning or permission removal without manual follow-up, especially for SaaS and custom applications.
Bottom line: The acquisition changes the decision from feature comparison to governance assurance, because roadmap control now sits inside a broader platform transition.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Roadmap control becomes an identity governance issue the moment a specialist capability is absorbed into a larger platform. Once Veza sits inside ServiceNow, teams are no longer only evaluating entitlement intelligence, they are also inheriting another company’s integration priorities, support model, and release cadence. That changes the governance conversation from feature comparison to operational dependency. For identity teams, the practical conclusion is that platform ownership can alter the evidence standard for trust.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
Q: What is the difference between access visibility and access enforcement?
A: Access visibility tells you what users can do, while access enforcement changes that state in the target systems. A graph can expose effective permissions without being able to remove them, and a governance workflow can revoke access without showing the full entitlement picture. Practitioners need both layers, but they solve different problems.
👉 Read our full editorial: ServiceNow-Veza acquisition shifts the identity tooling calculus