2023.3.27

Insights

  • Dashboard Reports now show increases or decreases over time, customizable by setting the Time Range to the past week or month. The current total results for each section are shown alongside the percent change and trend for the chosen time period.

Workflows

  • Reviewers can now quickly apply pre-configured filters to "Show Undecided Items" and "Only show Signed Off Items." These built-in options are now found under Filter > Saved Filters.

  • Alternate reviewer selection methods are now managed as a global option, defining assignment behavior when the deny list or self-review prevention blocks a requested reviewer.

  • When acting on multiple selected Certification items with Bulk Actions, Reviewers can now apply any action, whether or not the action applies to the selected rows. Any items the action cannot apply to are now skipped.

  • Workflow creators can now always add Fallback Reviewers, used when rules prevent the assignment of the original user, or when a manager does not exist for a certification result row.

  • Early Access: Workflow creators can now include or exclude indirect and nested relationships (such as roles assumed by other roles, or groups that are members of other groups) from certification results. When enabled, Show assumed entities is an option under Advanced Options > Relationship Options when the query source or destination entity type can be nested (such as Snowflake Group or AWS IAM Role).

Integrations

  • The AWS integration now supports Lambda Functions as Authorization Graph entities, enabling Search, Tags, Workflows, and Rules for:

    • AWS Users and Roles with the ability to create or edit Lambda functions.

    • AWS services and resources Lambda Functions can access.

    • AWS IAM roles assumed to access those services and resources.

  • AWS IAM Users with Lambda permissions and AWS IAM Roles with Lambda permissions are now provided in Saved Queries.

  • The required permissions for AWS are updated to enable listing Lambda functions and tags.

Bug Fixes

  • Attribute filters for Graph search are now correctly updated after applying changes.

  • Entity type names in certification details are now correctly formatted with spaces.

    • Fixed an issue where Over Provisioned Scores for users and groups appeared incorrectly for Snowflake integrations with audit log extraction disabled.

  • The Azure integration guide now correctly include the AuditLog.Read.All MS Graph permission, needed to collect last login dates.

    • Note that an Azure AD Premium P1/P2 license is also required to gather sign-in activity and custom security attributes for Azure AD users.

  • Fixed an issue where following external links to Veza Alerts did not correctly redirect users who weren't already signed in.

Last updated