Release Highlights – Enhanced User Interface

- Modernized User Experience – A cleaner, more intuitive interface designed for ease of use.
- Simplified Navigation – Faster access to features, pages, and key information.

- Improved Productivity – Streamlined layouts help users complete tasks more efficiently.
- Enhanced Accessibility – Better visibility, readability, and usability across the platform.

- Personalized Experience – More flexibility to customize the interface to individual preferences.
- Familiar Functionality – Core workflows and business processes remain unchanged.
- Seamless Transition – Enjoy the benefits of a refreshed design without a learning curve.

1. User Access Reviews (UAR) Updates
1.1 “Revoke Immediately” Real-Time Access Deprovisioning
Feature Highlights
Campaign review screens now feature a dual-action revocation menu offering standard Revoke alongside a new Revoke Immediately capability at the entitlement level. When a reviewer confirms Revoke Immediately, SecurEnds instantly initiates an automated access removal request via the application’s configured fulfillment channel (direct connector, ticketing system, or email notification) without waiting for the campaign to conclude. Successfully processed immediate revokes are automatically locked as read-only and excluded from end-of-campaign batch deprovisioning routines to eliminate duplicate fulfillment tickets.

User Impact
Critical access risks, unauthorized privileges, and compromised accounts identified during reviews can be neutralized instantly. Reviewers no longer have to wait weeks for a certification cycle to close before high-risk access is revoked, dramatically shrinking exposure windows.
1.2 Manager Escalation & Reminder Notification Exclusions for Manual Reminders
Feature Highlights
Campaign notification settings now allow administrators to exclude specific managers and executives from receiving automated escalation emails and review reminders when their direct reports have overdue review items. This builds upon existing campaign launch exclusion lists to provide granular communication controls for escalation flows.
User Impact
Prevents executive inbox fatigue and unnecessary alert noise for senior leaders while allowing campaign administrators to maintain firm escalation tracking across operational management tiers.
1.3 Next Scheduled Launch Date on Campaign Scheduler List
Feature Highlights
The Campaign Scheduler dashboard now displays the Next Scheduled Launch Date as a primary column directly on the main scheduler view. Administrators no longer need to open individual campaign configuration settings to inspect upcoming execution dates.

User Impact
Eliminates administrative overhead and eliminates loading delays previously experienced when opening settings on large campaigns with extensive Active Directory group mappings, providing an immediate snapshot of upcoming certification cycles.
2. Access Requests & Lifecycle Management (AR / ILM)
2.1 Entitlement List View & Multi-Line Display in Manage Access
Feature Highlights
The entitlement selection interface in Manage Access and Access Templates has been updated to provide a toggle between the traditional Tile View and a structured List View. In List View, each entitlement is presented in a full-width row displaying its complete name with word-wrapping, description, entitlement type, and owner, alongside alphabetical (A–Z) sorting controls.

User Impact
Significantly enhances usability when selecting from applications with hundreds of similarly named or lengthy entitlements. Requesters can easily scan, sort, and select entitlements without truncation issues.
2.2 Manual Entitlement Creation
Feature Highlights
Application custodians and administrators can now manually add new entitlements directly from the Application → Entitlements interface. The feature includes strict duplicate validation (case-insensitive) and automatically detects if an entitlement exists in a purged state, giving admins the option to reactivate it immediately with full audit trail logging.

User Impact
Enables rapid onboarding of newly created roles or ad-hoc entitlements for immediate access requests without waiting for scheduled overnight imports or executing full application synchronizations.
2.3 Access Templates Updates
- Configurable “Requestable” Flag on Access Templates Access Template management now includes a configurable option: “Should this Access Template be requestable?” Setting this option to No conceals the template from the standard self-service Manage Access catalog while keeping it fully available for automated Birthright, Termination, and Scoping policies.

- Introduction of “Select All Entitlements” Option: Added a single-click “Select All Entitlements” option with individual deselection support when configuring Access Templates, with selected items pinned to the top of the list.

2.4 Automated Approval Workflows for Birthright & Termination Policies
Feature Highlights
Provisioning policies for Birthright Access and Termination Rules now include a dedicated Approval Workflow configuration. Administrators can specify whether policy-triggered assignments require standard approval routing or should be set to No approval flow (Auto-Approved). Auto-approved requests are immediately processed for fulfilment and stamped with Auto Approved audit status in request tracking.

User Impact
Accelerates day-one onboarding and enforces rapid offboarding security by removing manual approval bottlenecks for pre-approved standard access bundles and mandatory termination deprovisioning.
2.5 Visibility Policy Standard Attribute Support
Feature Highlights
Policy condition engines now natively evaluate core user profile attributes stored in primary database columns (such as Employee ID, Employee Type, and Access Status) in addition to custom JSON attributes.

User Impact
Simplifies the administration of scoping and visibility rules, drastically reducing policy setup time while enabling precise role- and attribute-based catalog filtering.
2.6 Full Catalog Visibility for Administrator Logins
Feature Highlights
When an administrator accesses the Manage Access module to submit requests on behalf of users, SecurEnds bypasses end-user scoping and visibility policy restrictions, displaying all configured applications and templates.
User Impact
Ensures system administrators have unrestricted oversight and the operational flexibility to provision any necessary application or entitlement across the organization without encountering artificial policy barriers.
2.7 Active Directory OU Selection & Default Provisioning Password
Feature Highlights
When configuring an Active Directory application with Access Requests enabled, a new OU Configuration section allows administrators to specify the default target Organizational Unit (OU) from a dropdown of available OUs and define an initial default account password for user provisioning.

User Impact
Streamlines automated AD account creation during access fulfillment, ensuring newly provisioned Active Directory accounts are created in the proper organizational structure with compliant temporary passwords.
2.8 Custom Application Branding for SFTP & Active Directory
Feature Highlights
Administrators can now upload custom logos and icon images when configuring SFTP and Active Directory applications, bringing parity with CSV and SaaS application branding options.
User Impact
Enhances user experience and visual recognition across the Manage Access self-service catalog, helping employees quickly identify corporate systems during access requests.
3. Connectors & Enterprise Integrations
3.1 AWS Connector Modern Authentication via IAM Roles
The AWS Connector has been upgraded to support authentication via AWS IAM Roles (AssumeRole) alongside traditional IAM user credentials.
3.2 Salesforce Connector Support for External Client Apps (ECAs)
The Salesforce Connector has been updated to integrate via Salesforce External Client Apps (ECAs) using OAuth 2.0 flows, aligning with Salesforce’s modern integration framework and phasing out legacy username-password authentication.
3.3 Lightweight Slack Messaging Integration
The Slack integration has been streamlined to focus exclusively on 1-on-1 direct user notifications. Legacy code dependencies for public channel broadcasting have been removed, drastically reducing the OAuth permissions and bot token scopes requested from workspace administrators.
4. System Administration, Audit & Compliance
4.1 Automated Notification for Terminated Employee Application Credentials
A new automated security notification has been introduced. When an SOR sync flags an identity as Terminated, SecurEnds automatically compiles, all associated application accounts that still show Active status for the terminated identity, across target systems and emails a CSV report (Active_Accounts_with_HR_Status_Terminated.csv) to administrators. Refer Configuration IS_EMAIL_TERMINATED_APP_CREDENTIAL_NOTIFICATION
4.2 Dedicated Ticketing System Logs & Separated IGA Auditing
Under Admin Console → Logs, a dedicated Ticketing System category has been established, cleanly separating logs into Campaigns and Access Requests (IGA). Access Request logs capture Request ID, Application Name, Action, Status, Log Message, and Timestamp for every ticket interaction.
4.3 Auditor Role Access to Export Downloads
Users assigned the Auditor role have been granted direct access to the Admin Console → Export Downloads menu to view and download asynchronous reporting exports they initiate.
4.4 Mappings for Inactive Definitions
The “SOR Fields Mapping” interface has been redesigned as Mappings for Inactive Definitions, with updated instructional tooltips clarifying how application status values map to Inactive/Terminated definitions.

4.4 Updates on JIRA Ticketing System
- Inline Jira Ticketing Settings: The Jira ticket label setting (JIRA_TICKET_LABEL) has been moved directly inside the Jira Ticketing Setup wizard, and the Manage Assign Details button has been promoted to a primary action on the Ticketing dashboard.

- JIRA Project Key for IGA There’s a new optional field, jira.IGA.projectKey, under Admin Console → Configuration → Ticketing System setup. Admins can use it to pick a dedicated Jira project for Access Request (IGA) tickets.
5. Non-Human Identity (NHI) & AI Agent Governance
5. 1 Azure AI Agents Connector for AI Foundry & Copilot Studio
Feature Highlights
SecurEnds introduces a specialized Azure AI Agents connector enabling organizations to centralize the discovery, governance, and auditing of AI agents deployed across both Azure AI Foundry and Microsoft Copilot Studio. The connector normalizes agent configurations into a standardized governance model, ingesting critical resource hierarchies, agent descriptions, publishing statuses, assigned tool definitions, knowledge sources, and external connection metadata.

User Impact
Security and Identity teams can close the visibility gap surrounding autonomous AI agents and Non-Human Identities (NHIs). Administrators gain comprehensive visibility into all deployed enterprise agents from a centralized dashboard, ensuring corporate compliance and governance standards are maintained across modern AI deployments.
5.2 Azure AI Foundry & Microsoft Copilot Studio Access Reviews
Feature Highlights
Access review campaigns now fully support AI agents discovered from Azure AI Foundry and Microsoft Copilot Studio. SecurEnds maps agent access permissions into structured entitlements (Agent Name / Role, such as HR Assistant / Consumer or Policy Bot / Editor) and identifies whether permissions are granted directly to a user or inherited via Microsoft Entra ID security groups. Reviewers can inspect assignment scopes (Agent-level, Project-level, or Environment-level) and agent capability context directly within the review interface.

User Impact
Reviewers are empowered with actionable context to evaluate AI agent access without needing administrative console access to Azure or Power Platform. This mitigates over-permissioned agent access, ensures clear least-privilege enforcement, and simplifies audit proof generation for enterprise AI tools.
5.3 Self-Service Access Requests for AI Agents
Feature Highlights
The Manage Access catalog has been expanded with a dedicated AI Agents category card. When the AI Agents module is enabled for a tenant, end users and managers can browse approved Azure AI and AWS AI agent applications, select required roles or access tiers, and submit self-service access requests following standard organizational approval and provisioning workflows.

User Impact
Employees can request necessary AI agent tooling through the familiar SecurEnds self-service portal, eliminating manual ticketing delays and shadow-IT provisioning while ensuring every access grant is tracked and authorized.
5.4 Interactive Visual Mindmaps for Applications, Entitlements & Templates
Feature Highlights
Visual Mindmap views have been upgraded across Applications, Entitlements, and Access Templates to align with the interactive graph visualization introduced for AI Agents. Users can interactively navigate relationships between identities, roles, parent-child groups, and assigned applications within an intuitive, graphical node layout.

User Impact
Administrators and compliance managers can quickly understand complex, multi-tiered entitlement structures and inheritance paths at a glance, significantly reducing the time required to diagnose permission sprawl or audit access architectures.