> ## Documentation Index
> Fetch the complete documentation index at: https://docs.accessowl.com/llms.txt
> Use this file to discover all available pages before exploring further.

# What's new

> New features, improvements and integrations shipped in AccessOwl.

<Update label="September 29, 2026" description="A more powerful API">
  ## Automate more with the AccessOwl API

  The AccessOwl API can now handle your whole user lifecycle. Create a user, set their manager and org details, and onboard them in a single call, then offboard them later without opening AccessOwl. You can also list access requests and revocations and deny or reject them, import an application's full access list in one go, and pull contract spend, renewal dates and policy approval paths into your own tools.

  If you've been waiting to connect AccessOwl to your HR, ticketing or finance workflows, now is a great time to start. The [API reference](/api-reference/introduction) has everything you need, and we'd love to hear what you build.

  ### New

  * **Google Workspace Super Admin requests.** You can now mark the Super Admin role as requestable if you want people to be able to ask for it.
  * **Bulk revoke.** Select several accesses on a user's Current Access tab and revoke them all at once.
  * **Shift+click range select.** Hold Shift to select every row between two clicks, for example to set business owners for many applications at once.
  * **GitHub repository access alerts.** If a GitHub sync can't see any repositories, your Slack admins get a notice explaining how to grant access, with a button that goes straight to the integration.
  * **New sync and provisioning integrations.** [Anthropic Console](/integrations/all/anthropic-console) and [HubSpot](/integrations/all/hubspot) are now available, both in beta.

  ### Improved

  * **Pre-selected single permissions.** When a resource has only one permission, it comes already ticked in your Slack access request.
  * **Directory sync feedback.** When you start a directory sync, the button now tells you when every run has finished or failed, so there's no need to check back later.
  * **Approver visibility.** Expand a single-step request in the App Hub to see who approves it.
</Update>

<Update label="September 14, 2026" description="Time-Based Access">
  ## Time-Based Access

  Some access shouldn't stick around. With [Time-Based Access](/guides/time-based-access/setup), you can grant access that expires automatically after a set period, so no one has to remember to clean it up later. It's perfect for sensitive resources like production databases, where someone needs in for a quick task but shouldn't keep standing access afterward. You can set the window as short as 30 minutes, keeping access tight without slowing your team down.

  Let us know about your use cases and what's missing to implement them. We're still making adjustments to this new feature.

  ### New

  * **Reconnect alerts.** When a Google, Microsoft, or GitHub integration stops authenticating, your Org Admins get a notice with a Reconnect button, so a broken connection never goes unnoticed.
  * **Any child resource required.** Mark a mandatory resource as satisfied by any one of its child resources, and access requests are checked against that.
  * **Filter applications by category.** Filter your applications overview by category to find what you need faster.

  ### Improved

  * **Permissions in revocation webhooks.** Revocation webhook events now include the exact permissions being revoked, so your deprovisioning automations can act on the specific permission rather than just the resource.
</Update>

<Update label="September 7, 2026" description="Access via IdP groups">
  ## Sync and provision apps via IdP groups

  You can now grant app access straight through your Google Workspace or Microsoft IdP groups, exactly what you need for SAML apps that get their users from the IdP. Each app keeps its own approval policies, and once a request is approved AccessOwl manages membership in the specific Google or Microsoft groups behind it. That means the apps you could only handle manually until now join the same request, approval, and review flow as everything else. See [Manage applications via Google or Entra ID groups](/integrations/idp-managed-apps) to set it up.

  ### New

  * **Directory source ranking.** When several directory integrations report the same user, you decide which source leads and which ones only fill in what it doesn't provide. See [Source Priority](/guides/users/source-priority).
  * **Managers see onboarding access.** When onboarding applies your Access Templates, the new user's manager gets a Slack message listing the applications being requested.
  * **Auth errors on the dashboard.** When an integration's OAuth authorization breaks, the error shows up on the dashboard so you can reconnect it right away.
  * **New provisioning integrations.** Drata, Excalidraw+, Orca Security, Pylon, Tactiq, Windmill.
  * **New sync integrations.** PandaDoc, PostHog.

  ### Improved

  * **Full approval chain on requests.** Your requests in the App Hub now show every approval step, who is on each one, and where the request stands.
  * **Better search matches.** In pickers, entries starting with what you typed are listed first, so the user or application you meant is at the top.
</Update>

<Update label="August 24, 2026" description="AccessOwl for Claude Tag">
  ## AccessOwl for Claude Tag

  IT admin tasks are now one-line Slack messages. Tag @Claude in Slack and AccessOwl takes it from there.

  * "Revoke all the tools that Jan Scott still has access to"
  * "Give Mike Carter a Salesforce seat with the Sales permission set"
  * "The access review flagged Ryan's access to Figma, revoke it"

  You send a message, Claude orchestrates, and AccessOwl executes. It takes a single connection between Claude Tag and AccessOwl, set up once with an AccessOwl API token. The [setup guide and example workflows](/guides/ai/claude-in-slack) walk you through it.

  More APIs are coming soon to support even more use cases, so tell us what you want to automate first with Claude Tag.

  ### New

  * **Maintenance messages.** When an integration is paused for maintenance you now see a "Sync paused" notice.
  * **GitHub accounts.** Unassign a user from an account identified by its GitHub handle, and spot unassigned GitHub accounts right in the dashboard's "Needs Attention" panel.
  * **Microsoft start dates.** The Microsoft integration now imports employee start dates, including future hires, so they can drive [Zero Touch Onboarding](/guides/onboarding-offboarding/zero-touch-onboarding).
  * **New provisioning integrations.** Certifier, Cledara, ClickHouse Cloud, Descript, Freshdesk, HockeyStack, Sembly, SendSafely, Storylane, Surfe.

  ### Improved

  * **Access reviews.** Reviewers are warned before leaving a review with unsubmitted decisions, and the submit button is prominent and full-size again.
  * **Spend breakdown.** The "Unmatched" total moved to the top of the cost breakdown table, so you see it without scrolling.
</Update>

<Update label="July 13, 2026" description="Request access on the web">
  ## Request access from the web

  Getting access just got simpler. You can now request access straight from the [App Hub](/guides/app-hub) on the web, with no more bouncing back to Slack to raise a request. Free from Slack's UI limits, the web experience is cleaner and easier to use, so finding the app you need and asking for access takes just a few clicks.

  ### New

  * **My requests on App Hub.** Track all your requests in the App Hub, see the status at a glance and know exactly who to reach out to when you need a hand.
  * **Duplicate Access Templates.** Copy an existing Access Template to spin up a new one in seconds instead of starting from scratch.
  * **Start onboarding now.** A new button on the User page lets you kick off onboarding directly, right when you need it.
  * **New provisioning integrations.** Certifier, Pleo.
  * **New sync integrations.** Claude AI, Claude Console, Clay, CoderPad, Vercel.

  ### Improved

  * **Grouped approval requests.** When several requests come in for the same app and person, approvers now get a single merged Slack message instead of many, for less noise and faster approvals.
  * **Faster approval tasks.** The Open Approval Tasks modal now has application and grantee filters, and opening it from an approval message pre-filters straight to that request.

  ### Changed

  * **Webhook field names.** Webhook payloads now use "Resource" (formerly "Object") and "Permission" (formerly "Entitlement"). The deprecated fields in Request and Revocation payloads will be removed on August 15, 2026, so migrate before then. See the [webhooks overview](/guides/webhooks/overview).
</Update>

<Update label="June 19, 2026" description="Public API">
  ## Build on AccessOwl with the new public API

  AccessOwl now has a public REST API, so you can drive access management programmatically from your own systems. This first version lets you manage applications, show current access, create access requests, and mark them as granted, all through the API.

  Paired with webhooks, it opens the door to a powerful pattern. Bring your own custom or in-house applications into AccessOwl, automate the request-and-grant flow end to end, and keep everything in sync without manual steps. The [API reference](/api-reference/introduction) has the details.

  This is just the first iteration, and we're already planning what comes next. Let us know what you want to build.

  ### New

  * **Cancel and skip in access reviews.** Cancel a pending review campaign, with a clear "Cancelled" status, and skip applications you don't need to act on, right from the review screen.
  * **Set license during onboarding.** When licenses aren't auto-assigned, set the license field directly during Google and Microsoft directory onboarding.
  * **Stuck requests at a glance.** A new dashboard alert panel highlights access requests that are stuck so you can act on them right away.
  * **Request status from the confirmation.** Request confirmations now include a button to jump straight to the request's status, including approvers, provisioning and denials.
  * **Microsoft Mail Security Groups.** These are now synced.
  * **New provisioning integrations.** Attio, CircleCI, Cloudsmith, ElevenLabs, EverFi, Float, Gamma, Light, Lovable, Magic Brief, Microsoft Ads, Office Ally, Omni Analytics, Reo.dev, Roam, Scribe, Teamtailor, TikTok Ads, WhosOff, Wispr Flow, ZoomInfo.
  * **New sync integrations.** Asana, ChartMogul, monday.com, Sentry, Slack (Enterprise Grid support).

  ### Improved

  * **Webhooks.** You're now alerted when a webhook delivery permanently fails so integration issues never go unnoticed, and payloads now include the application's tags for richer downstream automation.
  * **Grouped revocation messages.** When multiple users are affected, revocation messages are grouped by resource, which reduces noise in Slack.
</Update>

<Update label="April 16, 2026" description="Access Reviews">
  ## Access Reviews, reimagined

  [Access Reviews](/guides/access-reviews) now come with far more context, so reviewers can make confident decisions without chasing down information elsewhere. Every review can surface Department, Job Title, and Last Review Status alongside each access, and clearly flags whether an access originated from an approved request. Directories add another powerful signal. You can see at a glance whether a user is still part of a source like Google or your HRIS, because only people in those directories should still have access.

  Admins also get more flexible reviewer assignment, and can reassign per app and to a specific person.

  ### New

  * **Direct Reports in Zero Touch Onboarding.** A new "Direct Reports" attribute lets you write rules that grant access to managers only.
  * **Prefill the Zero Touch simulator from a user.** Pick a real user to auto-fill department, team, job title, and location so you can test templates with real-world data.
  * **Filter for integrations.** Application pages now filter by sync and provisioning integrations.
  * **Terminated users with access.** Remove access for terminated users in bulk instead of one at a time.

  ### Changed

  * **Onboarding in Slack retired.** Onboarding now lives fully in the web app, with richer features like support for multiple templates.
  * **Clearer terminology.** "Objects" is now "Resources" and "Roles/Permissions" is now "Permissions", which is just easier to understand.
</Update>

<Update label="March 10, 2026" description="Webhooks">
  ## Connect AccessOwl to anything with webhooks

  Make AccessOwl the trigger for the rest of your stack. With [webhooks](/guides/webhooks/overview), you can kick off actions in other systems whenever something happens in AccessOwl.

  For instance, send a security awareness training invite after onboarding is scheduled, or create and update tickets when access gets approved or granted. It's a powerful new way to automate follow-up work, reduce manual steps, and connect AccessOwl to the workflows you already run.

  ### New

  * **Deny with reason.** Users often need to know why a request was denied. Now you can enter a reason so the user is informed.
  * **"Is one of" operator in Zero Touch Onboarding.** Match multiple departments with one template, for example Department Is one of (Engineering, Data).
  * **Adjustable pagination.** Adjust how many rows are shown per page when you need to see more.
  * **Billing details.** See the next payment and credit card details, and update your payment details.
  * **New currency.** CAD.
  * **New provisioning integrations.** Office Ally, WhosOff, Light, Float, ZoomInfo.

  ### Improved

  * **Access import.** Importing access with multiple resources (for example role or tier) is now much easier. You can map columns in your file directly to resources.
  * **Google Workspace as HRIS.** Location can be passed as a custom schema field so it can be used in Zero Touch Onboarding.
  * **Access Templates.** Enable or disable auto-assignment directly from the overview page, and reach Auto Assign conditions more easily.
</Update>

<Update label="February 1, 2026" description="Zero Touch Onboarding">
  ## Zero Touch Onboarding

  With an HRIS integration, onboardings can now be fully automated. When a new hire is created in your HRIS, AccessOwl automatically pulls their start date, name, email, manager, and other attributes, and assigns the correct Access Template without needing manual input.

  If you've set up Access Templates with auto-assignment rules, the templates can be mapped based on attributes like department, team, job title, location, employment type, and more.

  Before, you added the new hire in your HRIS, then had to manually assign an Access Template in AccessOwl, and access was built by combining multiple Template Blocks. Now, you add the new hire in your HRIS and AccessOwl assigns one or multiple Access Templates automatically, mapped to your HRIS attributes.

  See [Zero Touch Onboarding](/guides/onboarding-offboarding/zero-touch-onboarding) to set it up. If you want help, or would like us to review your templates and HRIS mapping, reach out to your technical account manager.

  ### New

  * **Unarchive applications.** Archived applications can be unarchived, reinstating them as approved and requestable.
  * **Employment type on user details.** If provided, the user details page displays the employment type (for example full-time or contract).
  * **App Hub in one click.** Users can open the App Hub in Slack with a single click.
  * **New provisioning integrations.** Chargeflow, ClientSuccess, Coralogix, Dixa, Dremio, Dropbox Sign, Exa, GetAccept, Honeybadger, Lambda.ai, LaunchDarkly, MacPaw, Mobile Service Cloud, Momentum, MongoDB, NordLayer, Notabene, Outline, Plane, PlanetScale, Postmark, QuickBooks Online, Sana AI, Screen Studio, Shortwave, Sumsub, Tability, Vespa, Weights & Biases.

  ### Improved

  * **Fewer Slack messages.** Grant confirmation messages to grantees and requestors are aggregated, which is especially noticeable when multiple resources of an application are granted close together. Messages were also shortened.
  * **Google Workspace as HRIS.** When Google Workspace is used as HRIS, AccessOwl also syncs job title, employment type and department if set.

  ### Changed

  * **Template Blocks phased out.** Your existing Template Blocks turn into Access Templates with a "(Migrated Template Block)" suffix, and your former Access Templates become read-only. Instead of combining multiple Template Blocks into a single template, you can now assign multiple Access Templates to a single user.
</Update>

<Update label="January 13, 2026" description="App Hub">
  ## App Hub, all your apps in one place

  Get a complete overview of every app in your organization, including company apps you can request access to. Search and filter in seconds, see exactly what access you have, and instantly know who the app admin is. Every user can sign into AccessOwl and access the [App Hub](/guides/app-hub). Users without a specific role see only the App Hub, while others can reach it via a new icon in the admin dashboard's top bar.

  ### New

  * **Bulk offboarding.** Multiple users can be offboarded from the Users page.
  * **Employment type.** If your HRIS provides this data, it appears in the Users table and is available for filtering.
  * **Vendor certificates.** HITRUST CSF and GDPR were added.
  * **Semi-annual spend billing.** A semi-annual billing interval was added for spend.
  * **New provisioning integrations.** Adyen, KnowBe4, Clerk, Mintlify, Ashby, Vertice, Mailtrap.io, Axomo, Uber, Awesome Screenshot, CleanShot.

  ### Improved

  * **Scheduled offboarding Slack message.** It now includes the leaver's time zone to clarify when the offboarding will occur.
  * **Application export.** Added a category field.
  * **Sync integrations.** All regions are supported for Datadog and Amplitude.
</Update>
