Release notes
Nova is developed continuously. This page summarises the visible changes per month, newest first. Features from add-ons are marked as such; add-ons are switched off after installation and are enabled under “Administration” → “Plugins”. Limits that matter for a rollout are listed under Known limitations.
September 2026
- Handbook: The first edition of this handbook is published, in German and English.
- Admin chat: The Nova AI chat can carry out almost all functions of the user interface. Actions with far-reaching effects, such as deleting, are first shown as a preview and only carried out after confirmation in the next message. Answers can be downloaded as PDF, Excel, CSV, Markdown or text.
- Outbox: A new tab under “Monitoring” shows outgoing notifications with their status; sending can be set to “Active”, “Paused” or “Off”.
- Mapping: Attributes of source and target systems can also be mapped using expressions – concatenation, if-then rules, text functions – with an AI suggestion and a preview against a sample identity.
- HR import: Nova classifies every person the same way in all views: joiner, mover, update, leaver or unchanged.
- SAP: One SAP role can be granted to or revoked from many accounts at once. Passwords that Nova generates for new SAP accounts follow SAP's fixed rules on length and leading characters. Fixed: after a reconciliation, SAP composite roles appear as a direct assignment instead of a business role.
- Generic LDAP: Locking and unlocking use the directory's password policy; the password and group memberships are kept.
- Change journal: In addition to LDAP and Entra ID, the change journal now also records writes to SAP, SCIM and Keycloak.
- Role mining and Migration Workbench: All proposals of a layer can be accepted together, and applied mining runs can be deleted. On request, the Migration Workbench transfers only selected object types, and its final report lists the records that were not transferred.
August 2026
- New user interface: The new user interface is now the default; the previous one is still available under
/olduifor the time being. - Dashboard: Everyone can adjust the size, order and visibility of the tiles. A new tile shows the share of the entitlement catalogue that is contained in business roles.
- Role mining: Nova proposes business roles derived from direct assignments, arranged in layers from the base role to special functions. Proposals are reviewed, calculated in a trial run and only then applied. See Role mining.
- Attribute history: In an identity's “Changelog”, Nova shows for each attribute which value applied from when to when, and where it came from.
- User interface: Connection errors of target systems are visible directly on the system; an identity's assignment overview is grouped by system. Several themes are available, and Nova can be installed as a web app.
- AI settings: The timeout and the maximum length of AI answers can be configured.
- Add-on OIDC Identity Provider: Other applications can use sign-in to Nova via OpenID Connect (“Login with Nova”).
July 2026
- Keycloak: New connector; groups serve as entitlements. See Keycloak.
- Recertification: Campaigns with a worklist for reviewers and a completion step in which Nova removes denied entitlements on request; the result is available as CSV. See Recertification.
- Segregation of duties: SoD rules between roles and business roles. When an access request is made, Nova warns about conflicts; depending on the setting, Nova blocks the request instead or requires an additional review step. As an add-on, Nova also checks against the rule set of SAP GRC Access Control. See Segregation of duties (SoD).
- Approvals: Deputy rule for absent approvers; the job “Approval Escalation” sends reminders about overdue steps and escalates to the administrators. See Approval workflows.
- Lifecycle: A daily job runs the leaver routine once the leave date has passed. For rehires, administrators decide whether earlier entitlements are kept. See Joiners, movers, leavers.
- AI agents: AI agents are identities of their own, with a responsible person, a purpose and a review date. See AI agents as identities.
- Operations: Nova regularly checks that the target systems can be reached, retries failed provisioning runs automatically and notifies the administrators when a background job fails. See Monitoring and jobs.
- Traceability: Writes to LDAP and Entra ID appear in the “Provisioning Log”; administrators can undo them one by one. The filtered audit log can be exported as CSV or JSON.
- Validity: For target systems without validity dates of their own, Nova holds back future-dated assignments and pushes them on their start date.
- Add-on Native MFA (TOTP): a second factor with single-use backup codes for signing in with a password.
June 2026
- Notifications: Nova sends messages by email, for example about access requests and failed provisioning. With the Microsoft Teams add-on, access requests can also be approved in Teams.
- Joiner, mover and leaver routines: Custom steps are created in an editor – with conditions, calculated values and a preview of what each step does in Nova and in the target systems.
- Signing in to Nova: Password history, optional password expiry and a lockout after repeated failed attempts; Nova logs sign-in events such as failed attempts and lockouts.
- Governance analysis: Nova assesses a requirements questionnaire – partly by checking the current data, partly with AI – and presents the result as a scorecard.
- Migration Workbench: Exports from legacy systems can be read in any format. The AI writes a parser for them, a trial run shows in advance what would be transferred, and transfers can be rolled back.
- Fixed: The HR import no longer creates duplicate identities for one person.