Because governance cannot control what it cannot see. When access lives in code, config files, APIs, or runtime dependencies, certification and offboarding processes miss active trust paths. That leaves organisations with policy on paper and unmanaged access in production.