Skip to content

Veza

Identity security platform built around an authorization graph that maps who and what can actually access data and systems, beyond what IAM roles claim.

Visit Website ↗
77/100Meaningful Innovator

Overview

Veza, founded in 2020 and headquartered in Los Gatos, California, built its platform around what it calls the authorization graph — pulling raw permission and entitlement metadata from disparate systems (cloud IAM, data warehouses, SaaS apps, on-prem directories) and normalizing it into a single schema that shows actual effective access, not just the roles and groups an admin thinks are in place. That distinction matters because in most environments the nominal role structure and the real, computed effective permissions diverge significantly, especially in cloud IAM systems like AWS where policy inheritance is complex.

The company raised a $108 million Series D in April 2025 at an $808 million valuation, led by New Enterprise Associates with participation from Atlassian Ventures, Workday Ventures, and Snowflake Ventures — notably including strategic investment from companies whose own platforms are common Veza data sources — bringing total funding to $235 million.

Veza positions itself less as a replacement for identity governance tools like SailPoint and more as the authorization layer underneath them: a query-able graph of who can do what, used to power least-privilege enforcement, access reviews, and non-human identity governance across cloud, SaaS, and data infrastructure.

Innovation Matrix Assessment

Innovation Velocity 8/10

Expanded from cloud-entitlement visibility into full access-review, least-privilege automation, and non-human identity governance within roughly five years of founding.

Operational Value 8/10

Computing actual effective permissions rather than relying on nominal role assignments directly addresses a well-documented cause of over-privileged access that manual reviews routinely miss.

Market Momentum 7/10

An $808M valuation and strategic investment from Atlassian, Workday, and Snowflake — companies whose platforms are common data sources for Veza — is a strong momentum signal, though it remains a private, sub-scale company relative to incumbents.

Category Disruption 8/10

Modeling authorization as a queryable graph of effective permissions, rather than a static list of role assignments, is a structurally different approach to the access-visibility problem than traditional IGA.

Real-World Efficacy 6/10

Strong investor validation and named strategic partners, but independent, third-party efficacy evidence at large production scale is limited in public sources given the company's relative youth.

Enduring Relevance 9/10

As access sprawls across cloud, SaaS, data platforms, and non-human identities, a normalized authorization graph is likely to become more, not less, necessary.

Why CISOs Should Care

Veza answers the question access reviews are supposed to answer but usually can't — exactly what a given identity can actually do across cloud, data, and SaaS systems — replacing spreadsheet-based certification with a queryable graph.

What Makes It Different

Rather than governing static role assignments like traditional IGA tools, Veza computes and normalizes actual effective permissions across heterogeneous systems into one graph, closing the gap between assigned and real access.

The Matrix Verdict

77/100 — MEANINGFUL INNOVATOR

A structurally different, well-funded approach to a genuine and worsening problem — permission sprawl and effective-access blindness — with strong strategic investor validation. A strong Meaningful-to-Transformational Innovator among smaller category-creators.

Editorial Note: Claims vs. Verified Findings

Funding and investor details are independently corroborated (BusinessWire, Yahoo Finance); the technical claim of computing effective permissions is describable from Veza's own product documentation and is architecturally distinct, but independent third-party production benchmarks are limited.

Sources