Veza vs Sonrai Security: Decide Access Graph vs Cloud Permissions
Choose Veza when you need an authorization Access Graph for people and non-human identities across apps, data systems, and cloud, now on the ServiceNow path. Choose Sonrai when the weekly job is cloud least privilege: unused permissions, toxic combinations, and org-level guardrails through the Cloud Permissions Firewall.
Committees often buy “an identity graph” twice and still miss Monday. One invoice maps who can take what action on SaaS objects, Snowflake tables, and service accounts. The other invoice was supposed to strip unused cloud privilege and block toxic permission chains with org policies. Paying for both without naming the queue is the expensive mistake: two dashboards, one unresolved access-review backlog, and standing AdminAccess that never got an SCP deny.
Between these two the centers differ. Veza productizes an authorization Access Graph for people and non-human identities across apps, data systems, and cloud, with reviews, intelligence, and last-mile AuthZ automation, now inside ServiceNow after the 2 March 2026 close. Sonrai productizes cloud identity and permissions governance with a CIEM-leaning enforcement path: toxic combinations, unused privilege removal, and the Cloud Permissions Firewall that writes cloud-native org guardrails. Veza still covers cloud IAM visibility. Sonrai still builds on an identity graph.
For the wider CIEM shortlist see CIEM tools. NHI control planes live under non-human identity tools. More side-by-sides under Compare.
| Job | Authorization Access Graph for people and NHI across apps, data, SaaS, and cloud; reviews, intelligence, AuthZ automation (ServiceNow path) | Cloud identity and permissions with toxic-combination focus; Cloud Permissions Firewall for unused privilege and org-level least privilege |
|---|---|---|
| How a bad day closes | Search effective permissions, explain identity-to-resource paths, drive access reviews and AuthZ grant/revoke across systems | Generate cloud-native deny/guardrail policies from usage, quarantine dormant identities, restore privilege on demand via ChatOps |
| Operator morning unit | Access risks, review campaigns, and provisioning exceptions tied to the Access Graph | Unused privileged permissions, toxic paths, and staged Firewall / WALLy remediations awaiting approval |
| Deploy | SaaS Access Platform; connectors plus Open Authorization API for custom apps; ServiceNow integration in phases after Mar 2026 close | SaaS; read-only org-level cloud onboarding for AWS, Azure, GCP; enforcement via native SCP/RCP and peer org policies |
| License/pricing | Sales / ServiceNow packaging; no public dollar SKU (checked 11 Sep 2026) | Public floor: $15k/yr minimum; $150/account/mo for 10-50 accounts; 50+ quote; 14-day trial (checked 11 Sep 2026) |
| Who operates it | Identity, IAM/IGA, and security owners answering effective access across the enterprise app and data map | CloudSec / DevSecOps / IAM owners shutting down standing cloud privilege without rewriting every policy by hand |
That sentence is the Veza-shaped morning. If your operators still cannot answer effective access across SaaS and data systems, an Access Graph hire beats another cloud-only findings list.
We reviewed first-party documentation, pricing pages, product announcements, and live community threads. We did not test the products in paid production environments, so this is not a hands-on benchmark. This page does not include exploit proofs of concept.
Veza

Sonrai Security

Editions and pricing
Ownership and public meters diverge in 2026. Veza closed into ServiceNow on 2 March 2026 after a December 2025 intent announcement; packaging is sales-led. Sonrai still publishes a Cloud Permissions Firewall price floor and a 14-day trial path.
| Owner (2026) | ServiceNow (acquisition completed 2 Mar 2026; existing Veza agreements continue per first-party notes) | Independent Sonrai Security |
|---|---|---|
| How you buy it now | Sales / ServiceNow security and risk packaging; ask what ships in AI Control Tower this quarter | Self-serve trial signup plus sales for account-volume tiers |
| Public units | No public dollar SKU on veza.com pages checked 11 Sep 2026 | $15k/year minimum; $150/account/month for 10-50 accounts across AWS/Azure/GCP; 50+ custom (first-party pricing page, checked 11 Sep 2026) |
| What the invoice covers | Access Platform modules scoped in the quote: graph visibility, intelligence, reviews, lifecycle, AuthZ, Access AI | Cloud Permissions Firewall scope: unused privilege removal, region/service locks, dormant identity quarantine, privilege-on-demand, support tier |
| Self-serve start | Demo / enterprise onboarding | 14-day free trial (business email required on first-party FAQ) |
If procurement needs a published per-account meter and a trial this week, Sonrai has one. If procurement needs enterprise authorization across SaaS and data with ServiceNow workflow gravity, price Veza through that path instead of forcing a cloud-account spreadsheet.
Authorization graph across apps and data
| Primary surface | Access Graph across IdPs, SaaS, data systems, cloud, NHI, and custom apps via Open Authorization API | Cloud identity graph for AWS, Azure, and GCP identities, permissions, and related cloud resources |
|---|---|---|
| Effective access question | Who can take what action on what data, with path explanation and time-travel style investigation in product docs | Which cloud identities hold unused or toxic privilege combinations that create escalation paths |
| Governance follow-through | Access reviews, lifecycle, requests, and AuthZ automation on the ServiceNow path after the 2 Mar 2026 close (Access AuthZ announced 4 Nov 2025) | Remediation through Firewall policies and privilege-on-demand, not a full SaaS/data IGA campaign product |
| What teams argue about | Whether ServiceNow packaging covers the connectors and review workflows the IGA team already runs | Whether cloud-only least privilege closes the SaaS and data access-review backlog |
That is effective-permissions work. Between these two, Veza productizes that question across apps and data systems, not only cloud IAM JSON. Sonrai productizes the next step for cloud: turn unused and toxic privilege into enforceable org guardrails.
Cloud permissions guardrails
| Primary surface | Cloud access visibility and risk inside the broader Access Graph; not marketed as an org-level SCP/RCP generation product | Cloud Permissions Firewall: unused privileged permissions, dormant identities, unused services and regions |
|---|---|---|
| Enforcement shape | Intelligence, reviews, and AuthZ automation that change access in connected systems; buyer must confirm cloud policy write paths in the quote | Cloud-native org policies (AWS SCP/RCP and peer Azure/GCP controls) generated from usage with exemptions for active workloads |
| Toxic combinations | Access risk and privilege findings on the graph, including toxic permission language on Veza marketing; depth stays graph and review oriented | CIEM+ style toxic permission chains across multi-cloud identities as a product center, then Firewall remediation |
| 2025 agent layer | Access AI summaries for access risk analysis (Sep 2025) and Access Agents roadmap on the ServiceNow story | WALLy PAM AI agent (announced 7 Oct 2025) stages privilege fixes for human approval inside Firewall guardrails |
| What teams argue about | Whether graph findings become cloud org denials without a separate enforcement tool | Whether Firewall scope covers SaaS entitlements outside the cloud IAM map |
If the painful queue is standing cloud privilege that CNAPP tickets never clear, Sonrai is the clearer hire between these two. If the painful queue is access reviews and effective permissions across Salesforce, Snowflake, and custom apps, Veza is the clearer hire.
Where they overlap
Both sell identity graphs. Both talk least privilege for humans and machines. Both show up when an RFP says CIEM or authorization. Overlap is category language and some cloud visibility. It is not the same weekly queue: enterprise authorization across apps and data versus cloud permissions enforcement with org guardrails.
When to use both
Running both can make sense when the jobs stay separate: Veza (ServiceNow) for Access Graph reviews and AuthZ across SaaS and data, Sonrai for Cloud Permissions Firewall least privilege on AWS/Azure/GCP. That is complementary coverage, not two copies of the same CIEM.
Skip Sonrai for this pair if the committee only needs enterprise authorization and access reviews across apps and data, and cloud least privilege is already handled by native org policies or another cloud PAM. Skip Veza for this pair if the only funded job is cloud unused-privilege removal with a published per-account meter and trial, and SaaS/data IGA is already owned by SailPoint, Saviynt, or ServiceNow without the Veza graph.
Decide the weekly queue first. If the product must answer who can take what action on what data across apps and NHI, that is Veza on the ServiceNow path. If the product must enforce cloud least privilege with unused-permission guardrails, that is Sonrai. Only then open the quotes.
FAQs
Are Veza and Sonrai the same identity graph product?
No. Between these two, Veza leads with an authorization Access Graph across apps, data, and NHI plus governance automation on the ServiceNow path. Sonrai leads with cloud identity permissions, toxic combinations, and Cloud Permissions Firewall enforcement.
Is Veza still an independent vendor?
ServiceNow completed the Veza acquisition on 2 March 2026 (intent announced 2 December 2025). First-party notes say existing Veza agreements continue while capabilities integrate into ServiceNow security and AI Control Tower packaging. Ask which SKU invoices this quarter.
Does Sonrai publish prices?
Yes. First-party pricing checked 11 Sep 2026 lists a $15k/year minimum, $150 per account per month for 10-50 accounts, custom pricing above 50 accounts, and a 14-day free trial.
Does Veza replace a CIEM Cloud Permissions Firewall?
Not as the same job. Veza maps and governs authorization across a wide system surface. Sonrai’s Firewall is built to generate cloud-native org guardrails from usage. Some teams run both when both queues stay funded.
Is this a scored bake-off?
No. Order is editorial.