Status & Roadmap

Nova IAM changelog and release status

Nova IAM is under active development. This page shows the current version, the main changes in each release and the next milestones. The full plan is in the product roadmap. As of 4 Oct 2026.

Current version

Version
2026.08.2
Year.month.release scheme: second release in August 2026 · active development, pre-1.0
Latest release
August 2026
AI healthcheck per user
Standard integrations
13 + 1 beta
Including 5 target-system connectors: SAP, LDAP/AD, Entra ID, SCIM, Keycloak; SAP BTP in beta. Catalog with status per system →

Changelog

The two most recent releases are shown in full, older ones can be expanded. Full release notes on request for pilot customers.

2026.08.2 August 2026

AI healthcheck: find and fix governance deviations per user

Feature
  • One healthcheck run checks accounts, assignments, provisioning and reconciliation per user; the result is a list of findings with severity ratings
  • The AI summarises the findings in plain language: what deviates and why it is critical, such as unknown admin groups or directly assigned privileges outside role-based control
  • 19 checks in 4 groups, 11 of them with a suggested fix: reconciliation drift, i.e. backend roles unknown to Nova, is adopted or dismissed with a single click
  • The admin decides: the AI rates and proposes, every change remains a deliberate click
  • AI analysis can be toggled per run; the healthcheck itself also works without it
  • New year.month.release versioning scheme: this release is 2026.08.2 instead of v0.9.5.1
v0.9.5 August 2026

New frontend on Vue 3: themes, new layouts, full parity

Feature
  • The entire UI rebuilt on Vue 3 with TypeScript: typed components and clear module boundaries
  • A lean in-house UI component library instead of a heavy framework: consistent interaction patterns across all modules, forms and tables alike
  • Light and dark mode with theme switching; the UI follows your users’ environment
  • Redesigned views for the dashboard, role mining incl. chat, governance analysis and AI-agent management
  • Feature parity with the previous UI: everything from v0.9.4 is available in the new frontend
  • DE/EN localisation built into the new frontend from the start
  • Shipped as a static build: still no app-server cluster, deployment stays as lean as before
Older releases (9): v0.9.4 to v0.5.0
v0.9.4 August 2026

AI agents as a first-class identity type

Feature Security
  • AI agents as a fourth identity type next to natural, technical and test users: every agent carries a mandatory human owner with deputy, a business purpose, an expiry date and a review date
  • Ownership succession in the leaver process: when an owner leaves, their agents transfer to the deputy or manager; without a successor they are flagged as orphaned and audited. Expired agents are deactivated by the existing leave-date scan incl. backend deprovisioning
  • Keycloak: agents are provisioned as confidential service-account clients, with token-based machine login instead of passwords, per-client token lifetime and secret rotation from the UI; secrets are shown exactly once and never stored in Nova
  • Governance end to end: dedicated recertification scope for all agents, agent owner as a workflow approver type, access requests for agents restricted to owner, deputy or admin; SoD checks apply unchanged
  • Delegation chain: every assignment can record whom the agent acts on behalf of. On approved requests this is set automatically to the requester; visible in the assignments tab and the audit trail
  • Expiry monitoring and onboarding: warning for agents expiring within 14 days, a scheduled job flags overdue reviews; Keycloak/Entra imports can onboard existing agents typed with a default owner
  • Full localisation: complete DE/EN sweep across the entire UI and all backend error messages (700+ new translation keys)
v0.9.3 July 2026

Security hardening, deputy approvals & lifecycle expansion

Security Feature
  • Hardening along OWASP ASVS L2 following an internal code assessment (06/2026); external review pending. Measures: admin gates on all mutating routes and connectors, least-privilege database role and function blocklist for report SQL, consistent output escaping
  • Deputy rule with absence window: deputies approve alongside the absent approver, fully audited; new escalation job reminds on overdue approvals and escalates to admins
  • Rehire as its own lifecycle event: configurable between keeping prior access and a clean start that revokes all legacy assignments incl. backend deprovisioning
  • Active Directory: rule-based UPN and mail naming with live preview, configurable initial account state (disabled until activation) and forced password change at first logon
  • Operations: active ops alerting on failed background jobs (email/Teams, deduplicated) and auto-retry queue for failed provisioning runs with exponential backoff
  • Secrets: all system credentials incl. SCIM tokens consistently encrypted at rest; e2e test suite stabilized at 368 green tests
v0.9.2 June 2026

Access governance: recertification, TOTP & Keycloak

Feature Security
  • Keycloak connector: Keycloak as a full target system via the Admin REST API, covering create, change and revoke for users, groups and realm roles incl. password management; optional integration as an identity provider for Nova login
  • Recertification campaigns (access reviews): reviewer resolved per entry, risk flags per row (SoD conflict, over-privileged, orphan account), decisions are recorded in the audit log
  • TOTP two-factor authentication for administrative logins: native MFA plugin with self-service setup via QR code and one-time backup codes
  • SoD check at request time: segregation-of-duties analysis over existing plus requested roles already at submission, conflicts surfaced before approval (plugin)
  • Searchable self-service role catalog: full-text search over name and description, risk filters, card/table view and approval-stage display per role
  • Configuration export/import as a versioned JSON manifest (target systems without secrets, roles, business roles incl. members, SoD rules, workflows, settings) with a simulation mode on import
  • Directory rollback (point-in-time): every AD change made by Nova logged with before/after image and reversible per change
v0.9.1 March 2026

Connector refactoring & SAP OM integration

Feature Performance
  • Connector plugin system: each connector as its own package; SCIM connector added as generic module
  • SAP org management: chief-read direction corrected, is_chief persisted on sync
  • VDS dummy: updated_at stabilisation, LDIF multi-value parser extended
  • Job executor registry pattern for clean extensibility
v0.8.5 December 2025

Hardening, reporting polish & audit-trail fixes

Feature Fix
  • Free-SQL reports with read-only sandbox stabilised
  • Reporting performance optimised for large tables
  • Audit trail: edge cases in parallel sync jobs resolved
  • Org-tree search: person-based lookups, single-org-assignment enforcement
v0.8.0 September 2025

Reporting module & structured audit trail

Major Feature
  • Chat-based report generation with AI validation introduced
  • Structured audit log for identity operations: actor, timestamp, target and origin per entry
  • Compliance pack first published (initially 9 documents)
  • Role and permission model finalised
v0.7.0 June 2025

Reconciliation engine

Major Feature
  • Three-way reconciliation across Nova, SAP and LDAP/AD
  • AI pattern recognition for mass-mismatch detection with root-cause analysis
  • Action buttons “Pull to Nova”, “Remove from Backend”, “Create Review”
  • Foundation laid for later reporting and audit functionality
v0.6.0 March 2025

Data-model consolidation & first connectors

Major Feature
  • Canonical identity data model finalised
  • First production-ready connector implementations: SAP, LDAP/AD, Entra ID
  • Sync-job framework with retry and backoff logic
  • First internal end-to-end tests against reference systems
v0.5.0 December 2024

Architecture foundation

Major
  • Initial architecture and tech stack defined
  • Domain model for identities, accounts, entitlements drafted
  • First proof-of-concept implementation of local sync flows
  • Project initialisation and team setup

Roadmap

What we plan in the open. The order of quarters is a guideline, not a guarantee. Pilot customers have direct influence on prioritization. Anything from the quarter just ended that was not finished is marked as postponed.

Full product roadmap with capability map →

Q3 2026 · completed

Delivered

  • v0.9.3 to 2026.08.2 (July and August 2026): security hardening, AI agents as an identity type, new frontend, AI healthcheck per user
  • OIDC identity provider add-on (August 2026)

In development

Developed since September 2026, but not yet in release 2026.08.2. Ships with the next release.

  • Change journal also for SAP, SCIM and Keycloak
  • Admin chat: preview and confirmation before far-reaching actions

Q4 2026 · current

Version 1.0

  • Nova IAM 1.0 & long-term support model
  • External penetration test: date to follow
  • SAP risk analysis (IAG connector), SoD rule editor, SCIM profile for SAP IPS/IAS

Q1 2027

Enterprise maturity

  • SOC 2 Type 1: after ISO 27001, no fixed date
  • S/4HANA Cloud connector (SAP Cloud Identity Services)
  • High-availability deployment patterns documented
  • Nova Online: hosted edition in preparation

Postponed from Q3 2026

New date open

  • AI Reconciliation Agent, multi-tenant model, plugin marketplace (beta)
  • Nova on BTP; the Kyma deployment is in trial
  • ISO 27001 (ISMS): certification audit
  • OIDC SSO, SIEM forwarding (DORA)
  • Recurring recertification, bulk-change UI, granular admin roles: first partial results in the release or in development, details in the roadmap

Get updates directly

We send a short monthly status letter with release highlights, roadmap updates and compliance status.

Join the list