What’s New in Wiz Service Catalog: Smarter Discovery, Governance, and Service-Level Context

Build your Service Catalog faster, keep service context current, and give teams a clearer path from cloud risk to accountability

Modern cloud environments are built around services, but the context that defines them – what they include, who owns them, and how they should be governed – is often scattered across cloud platforms, tags, developer portals, and CMDBs. Wiz Service Catalog brings that context together, making it easier to take action on security insights by connecting cloud resources and risk to the services, teams, and owners responsible for them. 

Since launching Service Catalog into GA, we’ve continued to invest in helping organizations bridge developer and security workflows with unified, service-centric visibility. Now, we’re taking Service Catalog a step further with a slew of new and upcoming discovery capabilities, integrations, posture controls, boards, and workflow templates to further help teams move from fragmented metadata to a shared, actionable operating model for cloud and AI security.

Build your catalog faster

The first challenge is turning the metadata an organization already has into a living model of its services. That requires incorporating existing developer portals, CMDBs, tagging conventions, and graph relationships, without requiring teams to manually recreate them.

For teams that manage service definitions in developer portals, Backstage Software Catalog Sync brings service descriptions, lifecycle stages, tags, and ownership mappings into Wiz while preserving the hierarchy developers already use. The upcoming ServiceNow CMDB integration will provide a similar path for organizations that rely on ServiceNow as their system of record, helping keep service information synchronized across security and IT operations.

Integrations like Backstage Software Catalog Sync bring service descriptions, lifecycle stages, tags, and ownership mappings into Wiz.

For cloud-native workloads, building a complete catalog shouldn't depend on handcrafted static rules or 100% tagging compliance. Dynamic Discovery Rules (Q4 release) will inspect an environment's real-world tagging patterns, extract the dominant service-identifying keys (such as app, service, or component), and dynamically build application boundaries. This eliminates rule maintenance, adapts to naming inconsistencies on the fly, and empowers application teams to own their security posture from day one.

Not every environment is consistently tagged, however. Network-based inclusion rules automatically bridge the gap between static cloud assets and real-world runtime behavior. They use live network traffic and cloud event telemetry to identify every database, storage bucket, and messaging service an application actually communicates with, dynamically mapping them as Related Resources in the Service Catalog. That means security teams and service owners get an accurate, real-time picture of their application’s true blast radius without chasing developers for tag updates or relying on outdated architecture diagrams.

Zero-touch dependency mapping: Wiz automatically adds connected databases, buckets, and queues to the Service Catalog based on live network traffic with Network Inclusion Rules.

Finally, later this year we’ll also be expanding the ways services can be discovered and maintained, including the ability to create services from non-compute resources such as buckets, databases, managed/AI services, CDNs, and more. Together, these capabilities both help teams build a more complete catalog with less manual mapping and also keep it aligned with the cloud as it evolves.

Operationalizing services with new posture policies

Mapping services is only the beginning. Ownership changes, new resources are deployed, and applications evolve. Without continuous oversight, a production service can lose its owner, a new application can launch without a project assignment, or service information can quietly fall out of date.

Service Posture Policies give teams a way to define and enforce standards for service configuration and ownership. For example, an organization can require every production service to have an owner or every service to be assigned to a Wiz Project.

Wiz automatically creates and resolves Posture Issues as services move in and out of compliance. This turns service hygiene from a periodic cleanup exercise into a continuous, auditable process, and helps teams catch gaps as they emerge.

Service Posture Policies give teams a way to define and enforce standards for service configuration and ownership.

With clear standards and continuous evaluation, organizations can keep their Service Catalogs accurate, actionable, and aligned with how their cloud environments operate today.

Understand every service in context

Accurate ownership provides the foundation. The next step is bringing together the security, compliance, and operational context teams need to understand each service as a whole:

  • Service Threats: Connect complex, multi-resource detection chains to the affected Service. When Wiz detects activities like lateral movement, privilege escalation, or data exfiltration, SOC analysts immediately see which business service and team are impacted, accelerating triage and incident routing.

  • Service-Level Identity Security: Bring full identity entitlements and non-human identity (NHI) analysis to the service level. Teams can map IAM roles, service accounts, and API keys directly to the services they power, making it easy to identify excessive permissions, toxic combinations, and credential exposure across service boundaries.

  • Secure Architecture Opportunities with WizOS: Surface container image migration opportunities directly to service owners, giving development teams a clear, prioritized path to harden their services from the build up. 

  • Service Compliance: Deliver real-time compliance posture scores for frameworks such as CIS, SOC 2, and PCI DSS, scoped specifically to the assigned resources within each Service.

  • Wiz Cloud Cost: Bring financial context alongside security risk by breaking down cloud spend and optimization opportunities at the service level, enabling SecOps, Platform, and FinOps teams to work from a single pane of glass.

Teams can now see additional service insights such as cost in the Service Catalog drawer.

In addition, we also continue to deepen AI visibility across services. For example, as teams deploy generative AI and autonomous agents, Wiz automatically identifies and catalogs AI components, including PaaS AI agents (AWS Bedrock, Azure OpenAI), foundation models, MCP servers, and AI datasets. Security teams can instantly filter for AI-powered services, audit agentic identities, and govern sensitive data flows to AI workloads.

Instead of investigating resources in isolation, teams can understand the complete story of a service: what it includes, who owns it, how it performs against organizational standards, where it is exposed, and what needs attention.

Turn ownership into action

All of this context converges in the new Services Board, giving teams an organization-wide view of discovery trends, ownership gaps, project mappings, and overall risk. 

The Services Board gives organizations an at-a-glance view of service discovery, ownership gaps, project mappings, and risk. It helps teams move from individual findings to a broader understanding of where service coverage is strong and where it needs improvement.

For leaders, it also provides benchmarks across discovery completeness, ownership coverage, compliance, threat exposure, and cost attribution. This makes it easier to track progress over time and identify the areas where better service ownership can have the greatest impact.

These views help answer questions such as which services are missing owners, where discovery or project-mapping gaps are growing, and which services carry the greatest security or compliance risk. More importantly, they provide the context needed to route those issues to the right teams.

New templates in the Wiz Workflows Catalog further help turn that visibility into repeatable action. Teams can automatically identify unowned services and route ownership requests, notify stakeholders through Slack, Jira, or ServiceNow when a service violates a Service Posture Policy, and enable developers to remediate issues through the engineering tools they already use.

Automate Service ownership and route service-level findings to responsible dev teams with new Workflow templates for services..

By combining Service Catalog and Workflows, you can automate lifecycle and response processes with multi-step, event-driven automations:

  • On Service Creation: Automate ownership outreach, verify tagging, or trigger Slack/Jira approval flows the moment a new service is discovered or synced.

  • On Service Issue Creation: Route consolidated, service-level findings directly to the responsible dev team’s backlog or alert channel with full service and code context attached.

The result is a clearer path not only from identifying risk to assigning it, but from assigning it to fixing it.

A shared operating model for the cloud

Wiz Service Catalog is more than an asset inventory: it is a unified operational lens for everything a team is accountable for, from security posture, threats, compliance, cost, to ownership maturity.

If you are already using Wiz Service Catalog, explore the new boards and Service Posture Policies. If you are just getting started, Dynamic Discovery Rules can help turn your existing tagging conventions into a working catalog faster today.

Continue reading

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management