Veza

Veza is an identity security software company focused on helping enterprises understand, manage, and control access across hybrid, multi-cloud environments. Its platform is built to answer who can and should take what action on what data across SaaS applications, cloud infrastructure, data systems, on-prem applications, and AI environments. By centering identity on permissions and effective access, Veza gives organizations a clearer view of access risk than directory-centric tools alone.

At the core of the platform is the Access Graph, which maps relationships among human users, non-human identities, groups, roles, policies, resources, and AI agents. Veza uses that foundation to support identity security posture management, governance, lifecycle automation, and continuous least-privilege enforcement, helping organizations reduce excess access, improve audit readiness, and modernize identity operations across distributed enterprise estates.

Offerings, Capabilities, and Integrations

Veza combines access visibility, access intelligence, activity monitoring, access reviews, lifecycle automation, request and approval workflows, non-human identity governance, and AI agent governance on one platform. It is designed to correlate entitlements, usage, policies, and ownership across human, machine, third-party, and agentic identities so security and identity teams can investigate risk, enforce least privilege, and operationalize governance at scale.

Integration breadth is a major part of the offering. Veza provides 300+ agentless, read-only integrations and extends coverage through its Open Authorization API and REST APIs for custom applications and workflow automation. Its integrations span major enterprise ecosystems including AWS, Microsoft Azure, Google Cloud, Active Directory, Okta, Snowflake, Salesforce, Databricks, GitHub, Oracle, and OpenAI, allowing organizations to embed Veza into existing IAM, ITSM, SOAR, and ticketing environments rather than rebuilding their stack.

Products and Services

  • Access Graph: Core graph foundation that maps relationships between identities, groups, roles, policies, systems, data sources, and effective permissions in plain-language actions.
  • Access AI: Generative AI layer that adds natural-language search, access insights, and recommendations across the Veza platform.
  • Veza Access Agents: Purpose-built AI agents that automate identity security and access governance tasks such as conversational analysis, access search, and review assistance.
  • Access Visibility: Access discovery and query capabilities for visualizing granular permissions across enterprise systems, major cloud providers, applications, and data platforms.
  • Access Intelligence: Risk and posture analysis capabilities that detect privileged users, dormant permissions, policy violations, misconfigurations, and separation-of-duties issues using prebuilt queries, dashboards, and alerts.
  • Access Monitoring: Activity-based monitoring that shows what identities and roles have actually accessed, helping teams right-size permissions and remove unused access.
  • Access Reviews: Automated certification and review workflows for users, machines, and resources, with delegation, prioritization, and contextual review support.
  • Lifecycle Management: Provisioning and deprovisioning automation for joiner, mover, and leaver workflows, including birthright access, workflow orchestration, and change simulation.
  • NHI Security: Governance for non-human identities such as service accounts, keys, secrets, and workloads, with discovery, ownership assignment, and remediation support.
  • AI Agent Security: AI security posture and governance capabilities for discovering AI agents, understanding what data and systems they can access, mapping human ownership, and controlling agent risk.
  • Access Hub: Central workspace for managers and employees to view access, request access, approve changes, and participate in team-based governance workflows.
  • Access Requests: Self-service, policy-driven access request workflows with role recommendations, just-in-time access, and automated provisioning support.
  • Access AuthZ: Last-mile access automation that grants and revokes access across SaaS, cloud, legacy, and custom systems from a unified control layer.
  • Separation of Duties: Cross-platform SoD controls that identify toxic combinations, continuously monitor policy violations, and support reporting and remediation.

Target Customers

Veza is aimed at enterprise organizations with complex access environments spanning SaaS, cloud-native platforms, on-prem applications, data systems, and custom software. It is a fit for companies that need to enforce least privilege, improve audit readiness, modernize identity governance, or gain control over fast-growing non-human identity and AI agent sprawl across hybrid and multi-cloud estates.

Primary users include security teams, identity and IGA teams, compliance and audit functions, and data platform teams. Veza also supports business managers and application owners who participate in access approvals, reviews, and team-based governance. Its customer profile aligns especially well with regulated and data-intensive sectors such as financial services, insurance, hospitality, government, and technology.

Cloud Integrations and Marketplace

  • AWS Marketplace: Veza – Access Platform is available through AWS Marketplace and is supported by broad AWS integrations, including services such as AWS IAM, IAM Identity Center, S3, Lambda, Redshift, RDS, and Secrets Manager.
  • Azure Marketplace: Veza is listed in Azure Marketplace and integrates with Microsoft Azure services including Azure RBAC, Blob Storage, Data Lake, Azure SQL, Key Vault, and Microsoft Entra ID.
  • Google Cloud: Veza integrates with Google Cloud services including Google Cloud IAM, BigQuery, Cloud Storage, Cloud SQL, Compute Engine, Vertex AI, VPC, and Workload Identity Federation.

Key People

  • Tarun Thakur: Co-Founder & CEO
  • Kane Lightowler: President & COO
  • Robert Whitcher: Co-Founder & CPO
  • Dr. Maohua Lu: Co-Founder & CTO
  • Rich Dandliker: Chief Strategy Officer
  • Mike Towers: Chief Security & Trust Officer
  • Amy Veater: Head of People
  • Emmi Nguy: VP of Finance
  • Tom Barsi: Senior Vice President of Global Ecosystems and Alliances
  • Ismet Geri: Vice President of Sales, EMEA

Key Facts

  • Headquarters: Los Gatos, California, United States
  • Employees: Approximately 300
  • Annual Revenue: $63.4M
  • Parent Company: ServiceNow
  • Subsidiaries: None
  • Publicly Listed: Acquired by ServiceNow (NYSE: NOW) on March 2, 2026; Veza is not separately publicly listed.

Analyst Recognitions

  • Gartner: 2025 Gartner Market Guide for Identity Governance and Administration (IGA) – Representative Vendor.
  • Forrester: The Workforce Identity Security Platforms Landscape, Q4 2025 – Notable Vendor across Identity Governance, Identity Security and Posture Management (ISPM), and Machine and AI Identity Management.
veza

Enter a search