TL;DR: Identity governance implementations still absorb 30 to 60 percent of year-one spend in services, while fewer than 7 percent of enterprise applications support SCIM and more than half of IGA deployments are distressed, according to Opnova and Gartner. AI changes the economics underneath the iceberg, but the governance model still needs to separate strategic architecture from connector toil.
At a glance
What this is: This analysis argues that the “GSI tax” in identity governance is driven less by license cost than by the ongoing manual work needed to integrate and maintain disconnected applications.
Why it matters: It matters because IAM, IGA, and PAM teams need to distinguish strategic governance work from repetitive integration toil if they want budgets, renewals, and operating models to hold up over time.
By the numbers:
- Vendor research puts implementation services at 30 to 60 percent of Year 1 total spend, on top of a median annual contract of around $113,000.
👉 Read Opnova's analysis of the GSI tax in IAM budgets
Context
Identity governance often looks like a software purchase, but in practice it behaves more like a long-running integration programme. The primary problem is not the licence alone, but the amount of manual work required to connect disconnected applications, keep those integrations alive, and make governance operational across a changing application estate.
For IAM and IGA teams, that means the budget conversation should focus on operating load, connector maintenance, and application onboarding throughput, not just procurement terms. The article frames AI as a way to reduce repetitive integration toil, while the strategic governance work still requires human judgment and programme ownership.
Key questions
Q: How should identity teams reduce the hidden cost of IGA implementations?
A: Identity teams should split the cost of governance into deployment, connector maintenance, and steady-state operations. The biggest savings usually come from reducing bespoke integrations and manual review paths, not from shaving licence costs. If a large share of spend is maintaining what already exists, the programme needs operating-model redesign, not just another renewal negotiation.
Q: Why do disconnected applications create identity governance risk?
A: They create risk because the organisation cannot reliably see, certify, or revoke access through the same control plane used for integrated systems. That produces blind spots in entitlement visibility, audit evidence, and offboarding, especially as the application count grows.
Q: What signals show an IGA programme is becoming unsustainable?
A: The clearest signals are a growing onboarding queue, rising maintenance spend, and a backlog of applications that never reaches full integration. If the oldest queued items are measured in months or years, the programme is no longer keeping pace with the business. That is usually a governance capacity problem, not a tool problem.
Q: Should organisations use AI for identity governance before they clean up data and policies?
A: No. AI should not be asked to decide access when identity records, entitlement labels, and policy rules are inconsistent. The better sequence is to normalise data, standardise approval criteria, and then apply AI to assist with scale, because automation amplifies the quality of the inputs it receives.
Technical breakdown
The connector treadmill in identity governance
Identity governance platforms depend on connectors, APIs, and workflow logic that rarely stay stable for long. When an application lacks SCIM or native integration, teams fall back to custom scripts, manual provisioning steps, and spreadsheet-driven access reviews. Each of those artifacts creates maintenance debt because application UIs, endpoints, and ownership models change faster than most governance programmes can absorb. The result is a treadmill: new apps enter the queue faster than old ones are fully onboarded, and the programme spends more of its life preserving yesterday's work than extending governance to new systems.
Practical implication: measure connector maintenance as a recurring operating cost, not a one-time deployment task.
Why integration became a permanent condition
The old identity governance assumption was that integration was a project with an endpoint. That model no longer fits modern enterprises, where acquisitions, SaaS churn, internal app changes, and shadow IT continuously alter the application landscape. In that environment, integration is not a launch milestone but an ongoing condition. The problem is not just scale. It is volatility. Every time ownership changes or a vendor updates its interface, the governance layer has to adapt, or the control breaks. This is why services-heavy delivery models became normal in the first place.
Practical implication: design your governance operating model for change, not for a fixed application inventory.
Where AI can reduce IGA toil without replacing governance
AI can change the economics of repetitive integration work by helping systems adapt to application changes more quickly than hand-built connectors can. That matters most in the long tail of disconnected applications, where bespoke engineering has historically consumed the most effort. But AI does not remove the need for architecture, policy design, or risk ownership. It changes which layer is automatable. The governing question is whether AI is being used to reduce mechanical toil or simply to disguise unresolved operating complexity behind a faster workflow.
Practical implication: separate AI-assisted integration from governance decisions, and keep policy ownership with the identity team.
Threat narrative
Attacker objective: The objective is not external compromise but operational exhaustion, where governance capacity is diverted into maintaining brittle integrations instead of controlling access effectively.
- Entry occurs when disconnected or poorly integrated applications enter the identity governance scope without native support, forcing manual onboarding and custom connector work.
- Escalation follows when those fragile integrations break after application updates, turning routine maintenance into recurring access-control rework.
- Impact is an identity programme that spends renewal cycles preserving old integrations instead of extending governance to new systems, leaving access reviews and provisioning incomplete.
Breaches seen in the wild
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
- DeepSeek breach — DeepSeek breach exposed 1M+ log lines and sensitive secret keys.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity governance is still paying for a broken integration assumption. The industry built IGA around the idea that application onboarding is a finite project, but enterprise applications change continuously. That assumption fails when connector upkeep becomes a permanent operating condition, and the implication is that budget models built around launch cost are structurally incomplete.
The connector treadmill is the real cost centre in IAM programmes. The visible licence is only the starting point. The hidden spend sits in custom connectors, maintenance rebuilds, and manual access review workflows that keep breaking as applications change. Practitioners should treat that recurring work as the primary economic signal in IGA, not as an implementation inconvenience.
AI changes the economics of toil, not the economics of governance. AI can reduce the manual burden of adapting integrations to changing applications, especially in the long tail where SCIM is absent. But strategy, policy, and accountability still require human ownership. The implication is that AI should be assessed on how much repetitive work it removes, not on whether it makes the governance programme look automated.
Disconnected applications create identity blast radius through maintenance debt. When onboarding queues stretch into years, the governance programme is no longer scaling with the business it serves. That delay widens the window in which access remains unmanaged, and the risk is not just inefficiency but unmanaged privilege persistence across the application estate. Practitioners should reframe backlog as governance exposure.
Field-level concept: connector treadmill. This is the repeating cycle in which new application integrations outrun the team's ability to maintain old ones, so budget gets consumed preserving the existing estate rather than expanding coverage. The practical consequence is that identity leaders need to price for continuous integration operations, not just deployment milestones.
From our research:
- NHIs outnumber human identities by 25x to 50x in modern enterprises, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- The governance pattern behind identity sprawl is easier to see in Ultimate Guide to NHIs - Lifecycle Processes for Managing NHIs, which shows why lifecycle control is the next budget pressure point.
What this signals
With Ultimate Guide to NHIs showing that NHIs outnumber human identities by 25x to 50x in modern enterprises, the next budgeting mistake is to treat connector work as a peripheral service line. The programme that cannot absorb application churn will keep buying temporary labour instead of durable governance capacity.
Connector treadmill: when onboarding queues, brittle integrations, and recurring rebuilds become the dominant cost centre, the identity programme is funding preservation rather than coverage. That matters because the business does not experience the licence model. It experiences the backlog, the manual exceptions, and the delayed access decisions that fall out of it.
For practitioners
- Re-baseline IAM spend against recurring integration load Separate licence cost, initial deployment services, and ongoing connector maintenance in every renewal review. If maintenance is consuming a growing share of the budget, the programme is operating as an integration factory rather than a governance control plane.
- Map the unmanaged application long tail Count how many in-scope applications lack a native supported connector or stable API path. Use that figure to identify where custom engineering, manual reviews, and brittle scripts are silently driving operating cost.
- Measure onboarding queue age and throughput Track how many applications are waiting for integration, how long the oldest item has been waiting, and how much new work lands each quarter. A queue measured in years is a sign the operating model is losing to application change.
- Use AI only for repetitive integration tasks Apply AI to reduce connector adaptation work, workflow updates, and other mechanical toil, but keep policy decisions, access rules, and exception handling under identity team governance.
Key takeaways
- The article's central claim is that identity governance cost is dominated by integration toil, not software price.
- Vendor and analyst evidence in the piece points to a structural backlog problem, with services-heavy delivery and distressed IGA programmes reinforcing the same pattern.
- Practitioners should budget for continuous connector maintenance, not just implementation, if they want IGA to scale with the application estate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Access provisioning and review are the core governance functions discussed in the article. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege depends on reliable governance workflows across connected applications. |
| NIST Zero Trust (SP 800-207) | Zero Trust assumes continuous verification across application access paths. |
Treat disconnected applications as a test of whether your zero-trust model still works beyond native integrations.
Key terms
- GSI tax: The GSI tax is the gap between software licence cost and the much larger amount spent making identity governance work in the real world. It includes implementation services, connector rebuilds, manual processes, and ongoing operational support that appear only after procurement.
- Connector treadmill: The connector treadmill is the repeating cycle in which new application integrations are added more slowly than existing ones need maintenance. In identity governance, this creates a permanent backlog and shifts budget from expanding coverage to preserving fragile integrations.
- Disconnected Application: An application that is not integrated with the organisation's central identity and access stack. Access is often managed through shared passwords, manual approval, or local admins, which makes revocation, evidence, and ownership harder to enforce consistently across the application lifecycle.
What's in the full article
Opnova's full blog covers the operational detail this post intentionally leaves for the source:
- How Opnova frames the economics of the GSI tax across renewal, expansion, and implementation cycles
- The specific application integration patterns that create recurring maintenance work in disconnected environments
- The article's practical checklist for judging whether AI can reduce connector toil in your environment
- The budgeting questions Opnova says CISOs should ask before the next IGA renewal
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
Published by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org