Skip to content

Wiz Service Catalog Adds Backstage Sync and ServiceNow Link

Wiz Service Catalog adds a Backstage sync and plans a ServiceNow CMDB link, tag-driven discovery and ownership policies to tie cloud risk to service owners.

Wiz Service Catalog services overview dashboard with discovery, inventory, ownership and risk panels
Wiz Service Catalog · Credit: Wiz

Wiz Service Catalog is gaining a Backstage sync, a planned ServiceNow CMDB connection and rule-based service discovery, all aimed at pinning cloud risk to a named service and a named owner.

Finding a risky cloud resource is the easy half of the job; knowing whose it is takes longer. Per Wiz, the facts that define a service (what it contains, who runs it, how it should be governed) are spread across cloud accounts, tags, developer portals and configuration databases. Backstage Software Catalog Sync pulls service descriptions, lifecycle stages, tags and ownership mappings from a team's Backstage portal into Wiz and keeps the hierarchy developers already use. The ServiceNow CMDB integration, which Wiz lists as upcoming, is meant to do the same for organizations that treat ServiceNow as their system of record.

Discovery is where the tagging problem shows. Wiz says Dynamic Discovery Rules, slated for its Q4 release, will read the tagging patterns an environment actually uses, pick out dominant keys such as app, service or component, and draw application boundaries from them without hand-maintained static rules. Where tagging is patchy, Network Inclusion Rules use live network traffic and cloud event telemetry to find the databases, storage buckets and messaging services an application talks to, then list them as related resources. Wiz also plans to let Wiz Service Catalog create services from non-compute resources such as buckets, databases, managed AI services and CDNs later in the year.

Service Posture Policies make ownership something that can fail a check. An organization can require every production service to have an owner, or every service to belong to a Wiz Project, and Wiz Service Catalog opens and closes Posture Issues automatically as services drift in and out of compliance. Wiz frames this as replacing periodic cleanup with continuous, auditable checks.

Once a service is in the catalog, Wiz attaches more context to it. The list covers service-scoped threat detections, identity entitlements including non-human identities, compliance scores against frameworks such as CIS and PCI DSS, cloud cost, WizOS container image migration suggestions, and AI components such as platform-hosted agents, foundation models and MCP servers. A new Services Board summarizes discovery progress, ownership gaps and project mappings, and new Workflows templates can notify owners through Slack, Jira or ServiceNow when a service breaks a posture policy, or start ownership outreach and approval flows when a new service appears.

All of this is a vendor describing its own features. The post offers no customer results, pricing or packaging, and no date beyond the fourth quarter for dynamic discovery. It is also uneven on readiness: Dynamic Discovery Rules appear as a coming release, yet the closing paragraph says they can already help teams build a working catalog. Every discovery path described here leans on tags or a developer portal that someone has kept accurate, so the quality of the ownership map in Wiz Service Catalog will follow the quality of that source data.

Share this story

Patrick Mercier

Patrick Mercier covers SaaS, enterprise software, and business automation for techshooked, from productivity suites to ERP and CRM platforms. He refuses vendor marketing as evidence, weighing total cost of ownership, integration burden, and the workflows where a platform earns its license cost.