ServiceNow’s planned acquisition of Veza marks its first serious entry into the IAM and IGA market. It transforms ServiceNow from an identity-adjacent platform into a credible identity security player by adding Veza’s AI-native access intelligence across human, machine, and AI identities. This shift directly affects vendors built on or tightly integrated with ServiceNow. While many of them retain strong governance depth, they now operate in a more competitive and rapidly evolving platform environment.
For the broader market, the implications go beyond product positioning. ServiceNow is reinforcing its role as a central control plane where identity, security, and workflows increasingly converge. For customers already invested in the platform, further consolidation of identity capabilities into ServiceNow becomes an attractive and logical next step.
Why this resonates with ITSM-centric IAM ambitions
Over the years, many organizations have shifted substantial IAM activities into ITSM. Access requests, manager approvals, joiner-mover-leaver processes, and even lightweight governance workflows often end up in ServiceNow because it is efficient, and already embedded in daily operations.
The value of dedicated IGA tools has been questioned more than once when similar workflows appear achievable within ServiceNow. For the decision makers, adding Veza’s identity intelligence into ServiceNow will feel like a natural extension of a platform they already trust and understand.
From an IGA perspective, expectations begin to shift
From an identity governance standpoint, the acquisition has the potential to reset expectations. Traditional IGA systems were designed for human-centric environments, built around periodic access reviews, static entitlements, and manual oversight. Modern systems are multi-cloud, highly dynamic, and increasingly dominated by machine identities and AI agents.
Veza’s access intelligence architecture continuously maps and analyzes permissions and offers a more real-time and contextual view of access. When combined with ServiceNow’s workflow engine, this points toward a next-generation IGA model that is more continuous, more automated, and more tightly integrated with operational processes.
Where workflows meet governance
ServiceNow’s great strength is workflows. They are structured, configurable, and efficient. Identity governance deals with policy conflicts, risk models, separation of duties, legacy systems, privilege sprawl, and complex on premises applications that need standardized workflows.
Veza adds a modern and powerful layer of access visibility, particularly in cloud and SaaS. A tightly integrated ServiceNow and Veza experience is undeniably attractive. Unified workflows enriched with identity context, governance of AI agents embedded into operations, and security signals flowing directly into incident and risk modules all form a strong narrative.
At the same time, this integration increases the gravitational pull of the platform. The closer identity governance moves to ITSM, the harder it becomes to separate the two.
What an ITSM plus IAM stack could mean for customer flexibility
Once identity governance becomes deeply embedded in ServiceNow, the option to switch ITSM vendors becomes far more complex. When ITSM and IGA converge too tightly, organizations inherit a dependency that stretches across service management, automation, governance and reporting. Tying identity governance to ITSM magnifies the cost and effort of any future move. Any future platform change becomes larger, riskier, and more expensive.
This matters in a market where ITSM pricing continues to rise. Consolidation can deliver efficiency and simplicity, but it inevitably trades flexibility for convenience. Organizations need to be deliberate about where they accept that trade-off.
A stronger identity story, with trade-offs
The acquisition gives ServiceNow a much stronger identity narrative by enriching vulnerability, incident and risk workflows with access context and enabling more confident governance of AI agents. This reinforces its role as the system where many customers want to centralize identity tasks.
At the same time, it exposes the tension between ITSM standardization and the complexity of identity governance. Veza strengthens visibility, but it does not eliminate the governance gap. Organizations that assume ServiceNow will now fully “do IAM” risk overlooking the hardest parts of identity. The challenge for organizations is understanding which identity problems can be addressed through automation and which still require the full capabilities of IGA.