Most people evaluating Veza file it under the wrong category before they’ve even seen what it does. ServiceNow’s acquisition landed it in the “identity governance” bucket by default, and that framing undersells what’s actually there. A handful of specific assumptions are worth correcting, because the real picture is more interesting than the shorthand.
It Doesn’t Replace Your IGA Tool, or Your PAM Tool
The instinct is to hear “identity security platform” and assume it competes with whatever runs identity governance today, SailPoint or Saviynt included. It doesn’t. An IGA tool runs the joiner-mover-leaver process: access requests, certifications, and it sees group membership before stopping there. A PAM tool like CyberArk or Delinea issues the credentials themselves, vaulting sessions and elevated access. It governs access, not what that access actually reaches. Veza surfaces what both of those processes miss: what an identity can actually do once every group, role, and policy resolves against a real resource. Complementary to both, a replacement for neither.
“Who Has Access” Was a Smaller Question Than It Seemed
Most tools can tell you what groups a user belongs to. That’s not the same as knowing what those groups actually let someone do once every role and inherited policy resolves against a specific resource. Veza’s Access Graph works through that chain explicitly: identity, to groups and roles and policies, to effective permissions, create, read, update, delete, on a specific resource. It runs that resolution across every identity worth tracking, human employees and contractors, but also service accounts, API keys, tokens, secrets, and AI agents, sourced straight from the identity provider and HR systems that already know which is which. Group membership was always a proxy. This is the actual answer.
It Surfaces Problems. It Doesn’t Fix Them.
That’s deliberate, not a gap. Veza hands its findings to a workflow engine, ServiceNow, Jira, whatever an organization already runs, rather than making changes itself. Keeping the finding and the fix in different places means the system doing the detecting isn’t also the system making unsupervised changes to access. That separation is a feature of how it’s designed to be trusted.
It’s Not a Cloud-Only Tool
Cloud, on-prem, SaaS, databases, file shares. Veza connects to more than 325 systems natively, plus an open API for anything else reachable over API or JDBC, and the on-prem coverage is stronger than what most IGA vendors sell as a cloud add-on. That matters more than it sounds like it should. A lot of the highest-risk access sprawl still lives in systems that never made it to the cloud.
It’s a Standalone Platform, Not a ServiceNow Plugin
ServiceNow acquired Veza and is integrating it, but it isn’t a module someone switches on inside an existing instance. It’s also not the same thing as Machine Identity Console, which governs service accounts inside a ServiceNow instance specifically. Veza governs the whole estate, ServiceNow included, and feeds what it finds into ServiceNow in a few distinct ways: remediation tickets through Flow Designer, agent inventory and risk inside AI Control Tower, asset and service context in the CMDB, and access risk inside IRM. Four separate connection points, not one plugin toggle.
It’s Not Just About People
Machine identities already outnumber human ones by a wide multiple, and every AI agent deployed is one more identity holding real permissions. Anyone standing up AI Control Tower and assuming agent identity is already handled should look again. AI Control Tower tracks which agents exist and what they cost to run. It doesn’t answer what they can actually reach, which is the question Veza’s Access Graph is built to answer.
It’s Not Just a Security Purchase
The fastest payback most teams find isn’t a security metric at all. It’s licensing: dormant accounts in Active Directory, Salesforce, and SAP that nobody has logged into in a year and everybody is still paying for.
The Bigger Miss: It’s an Identity Security Platform
Every one of these corrections points at the same misread. The instinct is to file Veza under governance, another feature that checks a compliance box. That undersells it. With more than 2,000 prebuilt queries running against a graph that resolves every identity down to its effective permissions, it’s a data platform for identity, one that happens to make governance possible rather than a governance feature that happens to hold some data. Organizations already standing up AI Control Tower are going to run into the access question sooner rather than later. Worth understanding the category correctly before that conversation happens.
Most organizations don’t find out what Veza would actually surface in their environment until after they’ve already bought it. If you want a preview first, get in touch with KeenStack and we’ll walk through what your own access graph would likely reveal.