← Back to all sparks
Z

Zluri

FINANCE
Velocity10.0

Zluri launches SoD compliance module and a visual canvas workflow builder — entering IGA territory

access-managementigasod-complianceworkflow-automationsaas-management
◆Current state
Zluri shipped two major capability expansions in September 2026: a full Segregation of Duties (SoD) compliance module — with policy library, ongoing violation detection, exemptions, and integration into both access request approvals (predictive violations) and access review certifications — and Workflows v2, a visual canvas-based workflow builder with drag-and-drop branching, inline action testing, and dynamic variables across all playbook types. Both are in early access or beta.
◆Where it's heading
The SoD launch followed rapidly by its extension into two separate access workflows (requests and reviews) shows deliberate, staged rollout of a compliance audit layer that spans the full access lifecycle. Workflows v2 canvas is the infrastructure that makes complex, compliance-driven automations practical. Together these move Zluri from SaaS management and basic access provisioning into Identity Governance and Administration (IGA) territory — competing with tools like Saviynt and SailPoint at the mid-market.
◆Prediction
SoD will expand to formal exception workflows with policy owner routing, and non-human identity (NHI) support is explicitly flagged as next in the instances/accounts release. Workflows v2 will move from beta to GA once the canvas builder stabilizes; Zluri needs it as the backbone of the new SoD automation paths.

◆Recent moves

  1. 3d ago

    SoD Violation Insights in Access Reviews

    SoD violation insights are now surfaced inside access review certifications as filterable insight chips, with severity ratings, entitlement-pair detail, and recommended actions (Modify to break the conflict, Approve for exempted violations). This extends the SoD module launched the previous week into the certification workflow — making compliance data visible at the moment a reviewer decides, not separately in the policy module.

    View source ↗
  2. 16d ago

    Workflows v2 - Canvas-based UI

    ⚡ SPARK

    Workflows v2 replaces the previous linear step model with a visual canvas builder: drag-and-drop nodes, named conditional branches, dynamic variables, inline action testing, and a live run graph with retry and manual task fallback. The redesign applies to all playbook types including the new SoD and access review workflows, making it the infrastructure backbone for Zluri's compliance automation ambitions.

    View source ↗
  3. 17d ago

    SoD Violation Insights in Access Requests

    SoD violation insights are now predicted at the access request stage — before access is granted — showing approvers which specific entitlement conflicts would be created, with severity ratings and policy detail. Together with the review certification integration, this closes the loop: SoD violations are now visible at the moment access is requested, while it's live, and when it's reviewed.

    View source ↗
  4. 17d ago

    Allow Admins to cancel Access Requests

    Admins can now cancel access requests directly from the request list, removing the need to ask the requester to withdraw. Adds a Cancelled/Withdrawn distinction for audit purposes. A small but useful operational improvement for access request administration.

    View source ↗
  5. 18d ago

    Segregation of Duties (SODs)

    ⚡ SPARK

    The Segregation of Duties module launches in early access — a policy library for defining toxic access combinations (Set A vs. Set B across roles, permissions, and groups), ongoing violation detection with configurable handling (alert, review, or automated removal via Playbooks), and time-bounded exemptions that automatically reopen. This is Zluri's foundational move into compliance-layer access governance.

    View source ↗
  6. 27d ago

    Managing Activity and Status for App Users through a Source

    Adds configurable inactivity thresholds and default status settings for users discovered via activity signals — enabling rules like 'mark inactive after 30 days with no SSO events.' Addresses inflated active-user counts caused by users who stopped using an app but remained marked active indefinitely.

    View source ↗