Veza review: lifecycle management on an access graph
ILM Reference editors · Editorial assessment · Last reviewed September 2026
Veza scores 69/100, third of eight, on the strength of its Access Graph: it maps effective permissions across 325+ integrations and reveals local, machine and service accounts even when they sit outside identity platforms. Lifecycle automation and reviews run on the same graph. Coverage depends on an integration or a custom connector existing for each system, and pricing is not published.
- Vendor
- Veza
- Category
- Access graph and governance
- Designation
- Best for entitlement-level visibility
- Lifecycle coverage score
- 69 / 100
- Rank
- 3 of 8
- Pricing
- Not published. Contact sales.
- Deployment
- SaaS (agentless integrations as described by Veza).
- Last reviewed
- September 2026
Scores are an editorial assessment of public vendor material. See Editorial method.
How does Veza score on each criterion?
Reveals accounts that exist outside identity platforms; custom systems connect through the Open Authorization API.
Detects dormant accounts and reveals local, machine and service accounts.
Birthright access, role-change and offboarding automation, including local accounts, with Dry Run and Safety Limits.
Access certification campaigns prioritized by risk, with effective permissions in plain terms.
Audit logging for lifecycle actions; no framework-specific evidence export described on the pages reviewed.
Integrates with Okta and HR sources and adds visibility beside existing IdP tooling.
No public pricing.
What does Veza do for identity lifecycle management?
Veza's Lifecycle Management provisions 'consistent birthright access' for new employees, contractors, vendors and guests, removes and adds access on role changes, and offboards 'automatically and thoroughly' including local accounts. It offers a Dry Run simulation before production changes and Safety Limits against large unintended changes. Sources include Workday, BambooHR, Okta, Oracle HCM and SAP HCM.
How does Veza handle orphan and local accounts?
Veza's access reviews page says it can 'accurately reveal all accounts with access, including local, machine, and service accounts, even if they exist outside your identity platforms', and whether an entitlement is actually used. The home page describes uncovering 'dormant accounts, excessive privileges, access drift'. This is why Veza scores 80 on orphan and local account discovery, second only to Orchid.
How does Veza handle disconnected applications?
Veza reaches systems through its integrations, and custom systems through the Open Authorization API (OAA). An application with no integration and no OAA connector stays outside the graph until someone builds one. That is a narrower claim than automatic discovery of unknown applications, which is why Veza scores 65 on disconnected-app coverage.
What are the watch-outs?
- Coverage follows integrations. Budget time for OAA connectors for in-house apps.
- No framework-specific audit evidence export described on the pages reviewed.
- No public pricing.
Who should shortlist Veza?
Security and IAM teams with large cloud, data and SaaS estates that need effective-permission visibility and dormant-account clean-up, and want lifecycle and reviews driven from the same data.
FAQ
Does Veza replace Okta or an IGA?
Veza integrates with Okta and HR sources and runs its own reviews and lifecycle automation. Some teams use it beside an IGA for visibility; others use its governance modules directly.
What is the Access Graph?
Veza's model of who can do what across integrated systems, expressed as effective permissions (create, read, update, delete).
Sources
Reviewed Sep 2026