← Back to all sparks
Z

Zluri

FINANCE
Velocity10.0

Zluri ships canvas workflows and a Segregation of Duties engine, moving from SaaS management into full IGA territory.

igasegregation-of-dutiesworkflow-automationaccess-governancesaas-managementcompliance
Current state
Zluri is in a concentrated feature-ship cycle, landing two significant enterprise compliance capabilities in one week: a visual canvas-based workflow builder (Workflows v2) that replaces a linear builder with node graphs, conditional branches, and dynamic variable support; and Segregation of Duties (SoD), a policy engine for detecting toxic access combinations with automated remediation via Playbooks. The August 30 cluster of three releases (source prioritization, instance management, activity-based status controls) built out the identity data layer these modules now operate against.
Where it's heading
The August 30 foundation releases — source prioritization, first-class instance/account entities, activity-based status thresholds — form a coherent identity model upgrade that makes Zluri's data precise enough to power compliance automation. Workflows v2 and SODs are the enforcement layer built on top. The trajectory is clear: Zluri is systematically working up the ITAM/IGA stack from discovery → governance → compliance automation, compressing a roadmap that traditionally spans separate products.
Prediction
Non-human identity (NHI) support, explicitly called out as the next step in the instance management release, is the next significant capability addition. Combined with SODs and account-level access reviews, Zluri is positioning directly against dedicated IGA tools in the SME/mid-market.

Recent moves

  1. 5d ago

    Workflows v2 - Canvas-based UI

    ⚡ SPARK

    Zluri replaces its workflow builder with a visual canvas: every step is a node, conditional logic appears as named branches, and variables flow dynamically between any action. Test-before-publish, drag-and-drop reordering, and step-level run inspection (inputs, outputs, retry) make complex playbooks auditable and debuggable in a way a list-based builder cannot. This is the execution layer that turns Zluri's identity governance data into enforceable automation.

    View source ↗
  2. 7d ago

    Allow Admins to cancel Access Requests

    Admins can now cancel pending access requests directly, with a reason field, without requiring the requester to withdraw. Cancelled and Withdrawn become distinct statuses with separate audit trails. Fills an operational gap that forced admins to contact requesters just to clean up stale or mistaken requests.

    View source ↗
  3. 7d ago

    Segregation of Duties (SODs)

    ⚡ SPARK

    Zluri's SoD module adds a full policy engine: Set A/Set B conflict pair definitions with risk levels, ongoing violation detection, configurable remediation (alert, manual review, or automated access removal via Playbooks), and exemptions with mandatory expiry dates. This is a new compliance capability category, not an extension of existing features — it addresses audit requirements that previously required dedicated IGA tools.

    View source ↗
  4. 17d ago

    Managing Activity and Status for App Users through a Source

    Activity-based user discovery gains configurable default status (active/inactive) and an inactivity threshold (days of no activity before auto-flip to inactive), configurable at org and app levels. Addresses a real data quality problem: users who went quiet were still counted as active, inflating adoption metrics and optimization counts.

    View source ↗
  5. 17d ago

    Manage Instances for your Applications and Accounts for your Identities

    Application instances (e.g., Azure AD-US, Azure AD-EU) and individual accounts become first-class entities with their own ownership, status, sources, and detail pages. Accounts are now identified by their source-unique identifier rather than email, surfacing username-only identities (GitHub) and multi-account-same-email patterns (Salesforce). Explicitly lays the groundwork for NHI support as the follow-on release.

    View source ↗
  6. 17d ago

    Source Prioritization for Application User and Account Status

    Source prioritization replaces single-source-per-app status resolution with configurable ranked groups: active in any source within a group wins, fallback proceeds to the next group if absent, org-level default with per-app overrides. Solves the fallback-when-trusted-source-is-silent problem that caused users to appear inactive when the direct integration had gaps but SSO showed activity.

    View source ↗