TL;DR: Fewer than 7% of roughly 10,000 applications support SCIM, leaving most enterprise apps outside automated provisioning, deprovisioning, and access governance workflows, according to Cerby. That app gap turns identity lifecycle management into manual work, with orphaned accounts, delayed removals, and fragmented audit trails becoming structural rather than exceptional.
At a glance
What this is: This is an analysis of why disconnected applications undermine IAM and IGA automation, with the central finding that standards coverage is far below enterprise app diversity.
Why it matters: IAM and IGA teams need this because lifecycle governance only works when provisioning, deprovisioning, and access reviews reach the full app estate, not just the standards-compliant minority.
Context
Disconnected applications are enterprise apps that cannot be managed through standard identity integrations such as SAML, OIDC, or SCIM. When that happens, authentication may still work, but lifecycle management falls back to manual steps, local credentials, or ad hoc workflows that sit outside IAM and IGA control.
Cerby argues that this gap is not a temporary integration problem. The article frames app diversity, legacy systems, and private web applications as a permanent feature of the enterprise stack, which means identity programmes have to govern the whole portfolio rather than the subset that cleanly supports modern standards.
Key questions
Q: What breaks when an application has no SCIM or federation support?
A: Lifecycle automation breaks at the point where identity systems can no longer push authoritative changes into the app. Access changes then depend on tickets, scripts, or manual handling, which increases the chance of stale access, delayed offboarding, and weak audit evidence. The core issue is not inconvenience but loss of control over who still has access.
Q: When does manual lifecycle management become a security risk?
A: Manual lifecycle management becomes a risk as soon as entitlement changes depend on tickets, email, or human memory. At that point, access can lag behind role changes, former users can retain permissions, and temporary access can outlast the business need. The practical signal is persistent mismatch between current role and active entitlement.
Q: What are the signs that IAM coverage is only partial?
A: A partial IAM programme usually shows up as a split between federated apps and locally managed apps, plus inconsistent offboarding completion and fragmented evidence for access reviews. If teams can prove lifecycle control in SaaS but not in on-premises or private systems, the control model is incomplete.
Q: How should teams govern apps that cannot be automated through identity tools?
A: They should govern them as exceptions with explicit ownership, documented manual controls, and stronger verification of revocation. If automation is impossible, the control objective shifts to making manual execution auditable, repeatable, and tied to application criticality rather than leaving it informal.
Technical breakdown
Why SCIM coverage stops lifecycle automation
SCIM is the protocol that lets identity systems create, update, and deactivate accounts automatically across applications. When an app does not support SCIM, identity teams lose machine-to-machine lifecycle control and must rely on tickets, scripts, or local admin actions instead. That breaks the link between source-of-truth events such as joiner, mover, and leaver changes and downstream access changes. The article’s core point is that this is not an edge case. Most of the app estate still sits outside SCIM coverage, so lifecycle automation becomes partial by design.
Practical implication: Treat SCIM coverage as a portfolio governance metric, not a feature checkbox.
Why non-federated apps create governance blind spots
A federated app authenticates users through an IdP, but a disconnected app may manage identities locally and never surface lifecycle events back to central governance tools. That creates a gap between authentication control and access governance control. Teams may know who signed in, yet still lack reliable control over whether accounts should exist, remain enabled, or be reviewed. In practical terms, the identity plane and the application plane drift apart. The article shows that this drift is what turns otherwise mature IAM and IGA programmes into partial control systems.
Practical implication: Map which critical apps still rely on local identity stores and separate them from federated coverage.
How manual provisioning becomes structural risk
Manual lifecycle execution introduces human delay, inconsistency, and incomplete records. Helpdesk tickets, spreadsheets, and email chains may keep access changes moving, but they also make it difficult to prove who approved what, when access was removed, or whether revocation actually completed. The risk is not just operational overhead. Manual handling creates orphaned accounts, delayed removals, and fragmented audit trails that compound over time. Once app coverage gaps become normal, identity governance loses the ability to enforce consistent joiner-mover-leaver outcomes at scale.
Practical implication: Replace manual fallbacks with compensating controls where automation is unavailable, especially for leaver workflows.
Threat narrative
Attacker objective: The practical attacker objective is to exploit stale or orphaned access in unmanaged applications where central identity controls no longer enforce revocation.
- Entry begins when users and administrators must authenticate directly to disconnected applications because they cannot be federated through centralized identity controls.
- Credential and account exposure follows when lifecycle events do not reach those applications, so provisioning, deprovisioning, and access review actions remain incomplete or delayed.
- Impact appears as orphaned accounts, stale access, and fragmented audit trails that prevent central governance from proving who still has access.
Breaches seen in the wild
- Internet Archive breach 2024: An exposed GitLab token opened Internet Archive code and 31 million user records; unrotated Zendesk tokens let the attacker back in weeks later.
- Cloudflare Thanksgiving breach 2023: One service token and three service accounts left unrotated after the Okta breach gave a nation-state attacker access to Cloudflare's Atlassian systems.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
The app gap is no longer an exception problem, it is the operating model. Identity programmes that assume most applications can be governed through standards-based provisioning are already misreading enterprise reality. Cerby’s data point that fewer than 7% of roughly 10,000 applications support SCIM is the signal: lifecycle control coverage is structurally incomplete, not merely under-implemented. Practitioners should treat disconnected apps as a permanent governance tier, not a backlog item.
Disconnected apps create identity governance debt. The debt is not only manual effort. It is the accumulation of accounts, approvals, and audit evidence that cannot be centrally enforced or reconciled. Over time, that debt shows up as orphaned access, delayed removals, and reviews that happen after the risk window has already passed. The practical conclusion is that IAM and IGA maturity must be measured by reach, not by tool deployment.
Standards-first identity design has hit its boundary. SAML, OIDC, and SCIM work well where vendors implemented them, but they do not define the enterprise baseline anymore. Modern application portfolios mix SaaS, on-premises, mobile, thick client, and private systems, so governance has to account for coverage variance across those classes. That means lifecycle architecture must be built around partial automation, not assumed universality.
Manual offboarding is not a process weakness, it is a control failure. When access removal depends on email chains, helpdesk queues, and spreadsheet follow-up, the control objective changes from enforcement to hope. The result is delayed revocation and unverifiable completion across systems that matter most. Teams should judge leaver governance by whether revocation is provable across the full estate.
Disconnected apps expose a lifecycle orchestration gap across human and machine access patterns. The same governance problem appears whenever access exists outside the control plane that issues, updates, and revokes it. That makes lifecycle orchestration the more important concept than any single integration standard. Practitioners should redesign governance around reachability of access states, not around whether a given app supports a preferred protocol.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
What this signals
Disconnected apps force identity teams to move from automation-first thinking to coverage-first governance. The real question is no longer whether the IdP works, but which parts of the application estate it never reaches. Practitioners should track disconnected coverage as a programme risk because that is where lifecycle drift, access lag, and audit gaps accumulate.
Lifecycle orchestration, not federation alone, is the control boundary that now matters. Authentication can be clean while provisioning and deprovisioning remain manual, which means many programmes are only partially governed. The next maturity step is to measure whether access states can be reached, changed, and revoked across every application class, including private and legacy systems.
For practitioners
- Inventory disconnected applications by lifecycle coverage Classify apps by whether they support SCIM, expose user management APIs, or require local administration so you can see where joiner, mover, and leaver workflows break down.
- Prioritise leaver workflows for manual apps For apps outside IAM and IGA control, build a revocation sequence that confirms account disablement, token removal, and audit evidence rather than assuming a ticket closed the loop.
- Separate authentication from lifecycle governance Do not treat SAML or OIDC support as proof that an app is governed. Track whether provisioning, deprovisioning, and access review are actually automated for each application.
- Replace spreadsheet-based access tracking Move manual records into a governed inventory that can show current ownership, approval history, and revocation status for disconnected apps and their privileged accounts.
Key takeaways
- Disconnected applications turn identity lifecycle management into a partial control problem, not a fully automated one.
- The main evidence is that SCIM and related standards cover only a minority of enterprise apps, while the rest require manual handling.
- The practical response is to govern lifecycle reach, not just federation, so revocation and access review work across the full app estate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Disconnected apps leave accounts behind when leaver workflows cannot reach them. |
| NHI-03 — Vulnerable Third-Party NHI | Apps outside central control often depend on vendor-specific or local identity paths with weak governance. | |
| Recommendation — Map disconnected-app offboarding gaps to NHI-01 and verify revocation across every unmanaged system. Review third-party and private app access paths for NHI-03 exposure where lifecycle control is incomplete. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about whether permissions and entitlements can be managed across the full application estate. |
| Recommendation — Use PR.AA-05 to confirm entitlements can be granted, changed, and revoked across every app class. | ||
| CIS Controls v8 | CIS-5 — Account Management | Manual account handling and orphaned access are direct account management failures. |
| Recommendation — Apply CIS-5 to standardise account lifecycle handling for disconnected applications. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The article highlights stale accounts and manual revocation where credentials are not centrally managed. |
| Recommendation — Use IA-5 to govern credential lifecycle and validate revocation in apps outside automated workflows. | ||
Key terms
- Disconnected Application: An application that is not integrated with the organisation's central identity and access stack. Access is often managed through shared passwords, manual approval, or local admins, which makes revocation, evidence, and ownership harder to enforce consistently across the application lifecycle.
- Lifecycle Automation: The automation of identity events such as onboarding, access changes, and revocation so governance follows the full user or account lifecycle. It reduces manual errors, shortens exposure windows, and helps organisations enforce consistent access controls at scale.
- Identity Coverage: The portion of an organisation’s application and account estate that is actually reachable by central identity controls. For disconnected environments, coverage is not just about count or inventory. It is about whether policy, lifecycle, and verification can be enforced end to end.
- Manual Provisioning Tail: The group of applications and access paths that remain outside automated IGA flows after the core platform is live. This tail is often the hardest part of the estate to govern, because it relies on people, queues, and memory rather than policy-driven execution.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org