Major Release Notes September 24, 2026

Prev Next

Clarity 1.9.0.0 is a major release. It introduces attribute-based access requests with routed approvals, a full non-human identity (NHI) governance layer, an AI-powered reconciliation agent, near-real-time delta syncs, and a new activity-logging foundation.

Several of the new capabilities are rolled out on an opt-in basis. Contact your Clarity account team to enable them for your tenant.

New Capabilities

Non-Human Identity Governance for Entra ID v2 and GitHub v2

Clarity now discovers, classifies, and governs service accounts, workload identities, and other non-human identities with the same rigor as human users.

  • Service users are classified into types (service principal, managed identity, application registration, workload identity, AI agent, and more) with rule-based auto-typing.

  • Credentials (secrets, certificates, keys) are tracked per service user, with expiry and rotation visibility.

  • Ownership is modeled explicitly: Clarity records who owns each non-human identity, whether discovered from the source system or assigned manually, and admins can manage owners directly from the service user page.

  • New Microsoft Entra ID (v2) and GitHub (v2) connector versions perform full NHI discovery, including ownership, entitlements, lifecycle signals, and write-back. Existing Entra and GitHub applications keep running unchanged on their current version.

AI-Assisted Agent to Link Unreconciled Service Users

A new AI-assisted agent links unreconciled service users to the correct Clarity identities, clearing reconciliation backlogs that previously required manual review.

  • Runs nightly and on demand from the Service Users list with new Reconcile and Reset Verdicts actions.

  • Unambiguous matches (such as exact email matches) are resolved deterministically before the agent is engaged, keeping results fast and predictable.

  • Each verdict records who or what made the match, a confidence score, and a plain-language rationale, all visible as new columns on the Service Users list.

  • Inactive identities are considered as match candidates so orphaned accounts are correctly identified rather than left unmatched.

Activity Logging

A new activity-logging foundation captures identity activity from connected systems and surfaces it inside Clarity.

  • Identities gain an Activity Logs tab showing recent activity across connected applications.

  • A nightly unused-access detection job identifies entitlements that have not been exercised, laying the groundwork for usage-based access reviews.

Attribute-Based Access Requests (ABAC) and Routed Approvals

End users can now request attribute-based access directly from the Access Hub. The Request Access page has been redesigned into User Access and ABAC Access tabs with a shared cart, so users can add profile-based and entitlement-based requests together and submit them in one pass.

  • Two new intake questionnaires, "Add Access" and "Create Profile", are provided out of the box and can be activated per tenant.

  • Dynamic Workflows gain a new Require Approval action with flexible approver routing: route to a specific identity, to the requester's owners, to tag owners, or to the owners of an ABAC attribute, with configurable quorum.

  • A live approver roster preview in the workflow builder shows exactly who will be asked to approve before the workflow is published.

  • Every approval decision is captured in an append-only decision ledger for a complete audit history.

  • Tags can now have designated owners, enabling tag-owner approval routing.

  • ABAC submissions appear on the identity's Submissions tab, and ABAC runs appear in LCM Execution Logs.

Enhancements & Connectors

Attribution Overrides

Attribute overrides that reference identity fields now resolve correctly in all contexts.

Dynamic Database Custom Username Generation

Added support for custom username generation and pushing attributes to Dynamic Database applications.

New Dynamic Workflow Option for New-User Email Config

Added a "Trigger AccountCreated workflow" option to new-user email configuration, so onboarding automation can fire as soon as an account is created.

Onboarding Attribute Restrictions

Dropdown attributes can now be restricted to existing values only, preventing free-text entries where a controlled list is required.

Provisioning Enhancements

  • Added a sliding-window incrementer for generated attribute values, giving finer control over uniqueness rules.

  • Added read-only provision and deprovision handling for non-joiner identities, so lifecycle actions are recorded without unintended changes.

  • Stranded provisioning rows are now retried automatically when a sync completes or an identity's trust level is upgraded, reducing manual intervention.

Microsoft Entra ID Connector Improvements

  • Added distribution-list provisioning through ClarityConnect scripts, with deferred outcomes tracked until the script completes.

  • New v2 connector version with full non-human identity discovery, ownership, credentials, and write-back.

  • Webhook-driven delta sync keeps Clarity in step with directory changes as they happen.

GitHub v2 Connector

The new GitHub connector version includes non-human identity discovery and connector versioning, so existing GitHub applications continue on v1 with no changes required.

ServiceNow Connector Pagination Reliability

Improved pagination reliability so large record sets sync completely and consistently.

Improved Connection Pooling for All OAuth Connectors

Improved connection pooling for all OAuth connectors so authenticated sessions are established before the first request, increasing sync reliability at scale.

Date of Release: September 24, 2026
Version: 1.9.0.0