Status & Roadmap

Nova IAM changelog and release status

Nova IAM is under active development. This page shows the current version, the main changes in each release and the next milestones. As of 6 Oct 2026.

We send a short monthly status letter with release highlights, roadmap updates and compliance status.

Current version

Version
2026.10.1
Year.month.release scheme: first release in October 2026 · active development, pre-1.0
Latest release
October 2026
Migration Workbench and change journal
Standard integrations
13 + 1 beta
Including 5 target-system connectors: SAP, LDAP/AD, Entra ID, SCIM, Keycloak; SAP BTP in beta.
Catalog with status per system

Release history

Changelog

The two most recent releases are shown in full, older ones can be expanded. Full release notes on request for pilot customers.

2026.08.2August 2026

AI healthcheck: find and fix governance deviations per user

Feature

  • One healthcheck run checks accounts, assignments, provisioning and reconciliation per user; the result is a list of findings with severity ratings
  • The AI summarises the findings in plain language: what deviates and why it is critical, such as unknown admin groups or directly assigned privileges outside role-based control
  • 19 checks in 4 groups, 11 of them with a suggested fix: reconciliation drift, i.e. backend roles unknown to Nova, is adopted or dismissed with a single click
  • The admin decides: the AI rates and proposes, every change remains a deliberate click
  • AI analysis can be toggled per run; the healthcheck itself also works without it
  • New year.month.release versioning scheme: this release is 2026.08.2 instead of v0.9.5.1
Older releases (10): v0.9.5 to v0.5.0

v0.9.5August 2026

New frontend on Vue 3: themes, new layouts, full parity

Feature

  • The entire UI rebuilt on Vue 3 with TypeScript: typed components and clear module boundaries
  • A lean in-house UI component library instead of a heavy framework: consistent interaction patterns across all modules, forms and tables alike
  • Light and dark mode with theme switching; the UI follows your users’ environment
  • Redesigned views for the dashboard, role mining incl. chat, governance analysis and AI-agent management
  • Feature parity with the previous UI: everything from v0.9.4 is available in the new frontend
  • DE/EN localisation built into the new frontend from the start
  • Shipped as a static build: still no app-server cluster, deployment stays as lean as before

v0.9.4August 2026

AI agents as a first-class identity type

FeatureSecurity

  • AI agents as a fourth identity type next to natural, technical and test users: every agent carries a mandatory human owner with deputy, a business purpose, an expiry date and a review date
  • Ownership succession in the leaver process: when an owner leaves, their agents transfer to the deputy or manager; without a successor they are flagged as orphaned and audited. Expired agents are deactivated by the existing leave-date scan incl. backend deprovisioning
  • Keycloak: agents are provisioned as confidential service-account clients, with token-based machine login instead of passwords, per-client token lifetime and secret rotation from the UI; secrets are shown exactly once and never stored in Nova
  • Governance end to end: dedicated recertification scope for all agents, agent owner as a workflow approver type, access requests for agents restricted to owner, deputy or admin; SoD checks apply unchanged
  • Delegation chain: every assignment can record whom the agent acts on behalf of. On approved requests this is set automatically to the requester; visible in the assignments tab and the audit trail
  • Expiry monitoring and onboarding: warning for agents expiring within 14 days, a scheduled job flags overdue reviews; Keycloak/Entra imports can onboard existing agents typed with a default owner
  • Full localisation: complete DE/EN sweep across the entire UI and all backend error messages (700+ new translation keys)

v0.9.3July 2026

Security hardening, deputy approvals & lifecycle expansion

SecurityFeature

  • Hardening along OWASP ASVS L2 following an internal code assessment (06/2026); external review pending. Measures: admin gates on all mutating routes and connectors, least-privilege database role and function blocklist for report SQL, consistent output escaping
  • Deputy rule with absence window: deputies approve alongside the absent approver, fully audited; new escalation job reminds on overdue approvals and escalates to admins
  • Rehire as its own lifecycle event: configurable between keeping prior access and a clean start that revokes all legacy assignments incl. backend deprovisioning
  • Active Directory: rule-based UPN and mail naming with live preview, configurable initial account state (disabled until activation) and forced password change at first logon
  • Operations: active ops alerting on failed background jobs (email/Teams, deduplicated) and auto-retry queue for failed provisioning runs with exponential backoff
  • Secrets: all system credentials incl. SCIM tokens consistently encrypted at rest; e2e test suite stabilized at 368 green tests

v0.9.2June 2026

Access governance: recertification, TOTP & Keycloak

FeatureSecurity

  • Keycloak connector: Keycloak as a full target system via the Admin REST API, covering create, change and revoke for users, groups and realm roles incl. password management; optional integration as an identity provider for Nova login
  • Recertification campaigns (access reviews): reviewer resolved per entry, risk flags per row (SoD conflict, over-privileged, orphan account), decisions are recorded in the audit log
  • TOTP two-factor authentication for administrative logins: native MFA plugin with self-service setup via QR code and one-time backup codes
  • SoD check at request time: segregation-of-duties analysis over existing plus requested roles already at submission, conflicts surfaced before approval (plugin)
  • Searchable self-service role catalog: full-text search over name and description, risk filters, card/table view and approval-stage display per role
  • Configuration export/import as a versioned JSON manifest (target systems without secrets, roles, business roles incl. members, SoD rules, workflows, settings) with a simulation mode on import
  • Directory rollback (point-in-time): every AD change made by Nova logged with before/after image and reversible per change

v0.9.1March 2026

Connector refactoring & SAP OM integration

FeaturePerformance

  • Connector plugin system: each connector as its own package; SCIM connector added as generic module
  • SAP org management: chief-read direction corrected, is_chief persisted on sync
  • VDS dummy: updated_at stabilisation, LDIF multi-value parser extended
  • Job executor registry pattern for clean extensibility

v0.8.5December 2025

Hardening, reporting polish & audit-trail fixes

FeatureFix

  • Free-SQL reports with read-only sandbox stabilised
  • Reporting performance optimised for large tables
  • Audit trail: edge cases in parallel sync jobs resolved
  • Org-tree search: person-based lookups, single-org-assignment enforcement

v0.8.0September 2025

Reporting module & structured audit trail

MajorFeature

  • Chat-based report generation with AI validation introduced
  • Structured audit log for identity operations: actor, timestamp, target and origin per entry
  • Compliance pack first published (initially 9 documents)
  • Role and permission model finalised

v0.7.0June 2025

Reconciliation engine

MajorFeature

  • Three-way reconciliation across Nova, SAP and LDAP/AD
  • AI pattern recognition for mass-mismatch detection with root-cause analysis
  • Action buttons “Pull to Nova”, “Remove from Backend”, “Create Review”
  • Foundation laid for later reporting and audit functionality

v0.6.0March 2025

Data-model consolidation & first connectors

MajorFeature

  • Canonical identity data model finalised
  • First production-ready connector implementations: SAP, LDAP/AD, Entra ID
  • Sync-job framework with retry and backoff logic
  • First internal end-to-end tests against reference systems

v0.5.0December 2024

Architecture foundation

Major

  • Initial architecture and tech stack defined
  • Domain model for identities, accounts, entitlements drafted
  • First proof-of-concept implementation of local sync flows
  • Project initialisation and team setup

Next milestones

Roadmap

What we plan in the open. The order of quarters is a guideline, not a guarantee. Pilot customers have direct influence on prioritization. Anything from the quarter just ended that was not finished is marked as postponed.

Q3 2026 completed

Delivered

  • v0.9.3 to 2026.08.2 (July and August 2026): security hardening, AI agents as an identity type, new frontend, AI healthcheck per user
  • OIDC identity provider add-on (August 2026)
  • Built during the quarter, shipped in October 2026 with release 2026.10.1: expanded Migration Workbench, admin chat with preview and confirmation, change journal for all connectors

Q4 2026 current

Version 1.0

  • Nova IAM 1.0 & long-term support model
  • External penetration test: date to follow
  • SAP risk analysis (IAG connector), SoD rule editor, SCIM profile for SAP IPS/IAS

Q1 2027 planned

Enterprise maturity

  • SOC 2 Type 1: after ISO 27001, no fixed date
  • S/4HANA Cloud connector (SAP Cloud Identity Services)
  • High-availability deployment patterns documented
  • Nova Online: hosted edition in preparation

From Q3 2026 postponed

New date open

  • AI Reconciliation Agent, multi-tenant model, plugin marketplace (beta)
  • Nova on BTP; the Kyma deployment is in trial
  • ISO 27001 (ISMS): certification audit
  • OIDC SSO, SIEM forwarding (DORA)
  • Recurring recertification, bulk-change UI, granular admin roles: first partial results in the current release, details in the roadmap

Next step

Ask your questions live on the system.

30 minutes via video call on the demo system: you name your use cases, we show the relevant functions.

Request a demo

What happens next

  1. ReplyWe usually get back to you on the same working day and agree a date with you.
  2. PreparationWe prepare the demo around the topics you name.
  3. 30 minutes via video callLive on the demo system with fictitious data: you ask, we show the relevant views.