- August 4, 2026
- Posted by: admin
- Category: Newsletter
This month in IAM
![]()
Innovation is not a destination. It is a discipline. At CyberSolve Innovation Labs, every month brings new ideas, experiments, product releases, and engineering breakthroughs that push the boundaries of Identity and Cybersecurity.
Meanwhile, the industry is moving fast.
Okta just shipped Agent Gateway, letting every AI agent tool call pass through a single identity-secured endpoint with credentials isolated from the agent itself. We shipped SPIFFE Workload Identity Registration in NeuroShield this same month.
Same conviction, built independently: AI agents need first-class identity governance.
In this edition:
- Applications like mainframe systems, that were previously complex to bring into your identity governance program, can now be automated without any custom connectors needed, using enhanced NeuroID.
- AI agents need identities too. We’ve added cryptographically verifiable agent identities w
- ith secure authentication, full traceability, and instant access revocation , powered by SPIFFE, in NeuroShield
- A redesigned application onboarding platform with a modern UI, new database, and faster bulk imports cuts IAM application onboarding time from 30–42 days to under a week – IdentityXpress
- Eliminate manual access review preparation with automated account correlation, configurable service account detection, and self-service data validation for application owners with enhanced NeuroID.
- A mid-size US healthcare organization is running fully automated access reviews across 28 disconnected applications. Extraction, correlation, evidence capture, remediation verification, all automated. Zero manual effort after initial setup, using NeuroID & IdentityXpress
WHAT WE BUILT THIS MONTH
NeuroID now automates mainframe applications

To learn more about NeuroID, click here – NeuroID
Mainframe systems are the hardest apps to bring into an IGA. They run on 3270 terminals, require specialized knowledge, and have zero modern APIs. Until now, every operation meant finding someone who knows PCOMM and the exact commands.
Not anymore.
The NeuroID Emulator shipped in July. It connects to mainframe applications like IBM RACF dynamically, no more hardcoded terminal sessions. Full entitlement support: Groups and Permissions. You give NeuroID an SOP for how a mainframe admin creates a user or assigns a permission. NeuroID learns the terminal sequence, generates a deterministic automation script, and runs it on every request. Same Learn, Execute, Verify pattern as web apps, just on a 3270 terminal instead of a browser.
This matters because mainframe apps are often the most critical and the least governed. At one customer, their mainframe was the only fully governed app in the entire environment, but its granular security model made IGA integration practically impossible. Audit evidence collection was entirely manual. NeuroID removes that bottleneck.
NeuroLink also shipped alongside the emulator. A new component that bridges NeuroID to native Windows desktop applications using Python-based automation. Thick-client ERPs, desktop admin tools, legacy apps with no web UI and no API. All now in scope. The SOP goes in, the automation comes out.
Your COBOL system on a 3270 terminal and the thick-client ERP nobody wanted to touch? Both just became automatable. No connectors. No API wrappers. Just an SOP and NeuroID.
Smarter pre-aggregation for User Access Reviews
To learn more about UAR, click here – NeuroID
Running a UAR on disconnected apps means pulling data from dozens of systems, correlating accounts to identities, flagging service accounts, resolving mismatches, and doing it all before the campaign even launches. Most teams do this with spreadsheets and manual screenshots. Every cycle starts from scratch.
The pre-aggregation workflow got significantly smarter this month.
Correlation logic now handles multiple authoritative sources with priority-based attribute ownership. When an app has no single unique identifier, NeuroID combines attributes automatically to create one. Rule-based fallback correlation for accounts that don’t match cleanly. Service account detection via configurable prefix, suffix, and contains patterns. Six account classification types with bulk operations.
The review page got a major upgrade. Account search. CSV download. Auto-complete for items that don’t need human review. App owners self-service resolve discrepancies through the NeuroID UI before anything reaches SailPoint.
Post-campaign, NeuroID checks whether remediations actually happened in the target application. If access was marked as revoked but the app still shows it active, NeuroID flags the discrepancy. No more taking anyone’s word for it.
The full UAR cycle now runs end-to-end: pre-aggregation, owner review, aggregation, certification, automated remediation, and post-campaign verification with a complete audit package. Currently running live at a US healthcare organization.
IdentityXpress: new UI, new database, faster onboarding
To learn more about IdentityXpress, click here – IdentityXpress

Database migrated from MySQL to PostgreSQL. Better scalability, cleaner architecture. The entire UI was redesigned: app onboarding, operational dashboard, and common modules all got a new Angular-based interface. The operational dashboard now shows automation distribution, mechanism breakdowns, and SOP version history at a glance.
Bulk onboarding got simpler. Upload a CSV of your app inventory. IDXP creates both NeuroID application entries and SailPoint ISC source configurations in one step. One import. Both systems ready.
Default vault (HashiCorp Vault) is now out-of-the-box. No manual secrets setup on first deployment. All email notifications standardized and moved to template-based content from the database.

Outcomes you can expect:
Traditional onboarding: ~42 days per app. With IDXP: ~6 days. 7x faster. 60%+ cost reduction per application. 90%+ onboarding artifacts auto-generated.
More from the Build Floor
-
SafeAccessCopilot: Application scaffolded and UI implemented. The first feature in development: entitlement enrichment using LLM. App owners answer structured questions about their entitlements (who uses it, what task it enables, SOX relevance, SOD conflicts). An LLM generates 3-4 business-friendly descriptions for each entitlement. Reviewers pick the best one. Clean, understandable entitlement data flows back into your IGA. No more concatenated spreadsheet descriptions that nobody can read. Questionnaire implementation in review, with export and IGA push coming in August.
-
SailPoint ISC connectors: Revoke and aggregation support fixes. Directly supports deployments running NeuroID alongside SailPoint. Delivered by Sarala Lakshmi.
-
Email notifications: All NeuroID email content standardized, moved from hardcoded to template-based. Worked on by Thwisha Kotian and Sarala Lakshmi.
-
Security: Penetration test: 17 of 18 findings mitigated. Host header manipulation review completed. Owned by Diksha Bhatti.
-
DevOps: Automated release notes via Jira Fix Versions. QA release status tracker. Docker image management in ECR.

ROADMAPWhat’s Next?
Where each solution accelerator is headed in August 2026 and beyond. Milestones that are shipped stay shipped. Everything here is what’s actively in progress or coming next.


