By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: CerbyPublished July 29, 2026

TL;DR: Identity governance platforms often count manual CSV uploads as connected apps, but those flat files are stale, incomplete, and hard to audit, creating false coverage and retained access risk according to Cerby. The governance problem is not connector coverage alone, but whether access data can be verified continuously rather than borrowed from a point-in-time export.


At a glance

What this is: Cerby argues that flat file imports are being misclassified as connected apps, which breaks completeness, freshness, and auditability in IGA governance.

Why it matters: IAM, IGA, and audit teams need a verifiable data path because reporting coverage that cannot be confirmed creates blind spots for recertification, retained access, and control evidence.

By the numbers:

👉 Read Cerby's analysis of why flat file apps break identity governance


Context

Identity governance depends on a simple premise: the platform's view of access should match the system's actual state. In practice, many enterprises still rely on flat file exports to represent apps that the IGA stack cannot reach directly, which means the governance record is a copy, not a live connection.

That distinction matters for NHI, human IAM, and lifecycle governance alike because certification, recertification, and audit evidence all inherit the weakness of the underlying data. When the source of truth is a scheduled CSV, the organisation is governing by snapshot rather than by verification.

Cerby frames the problem as a connectivity gap, but the governance issue is broader than connector coverage. The real question is whether identity teams can continuously verify entitlements across every application class, including systems inherited through acquisition, internal tools, and SaaS platforms with no viable connector.


Key questions

Q: What breaks when an IGA platform treats flat file uploads as connected apps?

A: The platform loses verification. A CSV only reflects what was exported, not what exists in the source system, so completeness, freshness, and auditability all weaken at once. That creates false confidence in certification results and can leave orphan accounts, service accounts, and privileged entitlements outside governance.

Q: Why do flat file feeds create more access risk than teams expect?

A: Because the risk is not just stale data, but stale decisions. If access reviews and recertifications run on quarterly exports, the organisation is certifying the past while claiming to govern the present. That gap is where retained access, missed privilege, and audit findings accumulate.

Q: How can security teams tell whether flat file governance is failing?

A: Look for apps where the platform reports coverage but the owner cannot prove current entitlement state without rebuilding evidence from tickets or emails. If reviewers routinely need manual reconstruction for privileged or in-scope accounts, the feed is not delivering reliable control evidence.

Q: Who is accountable when access evidence comes from a CSV instead of a live connector?

A: The governance owner remains accountable for the accuracy of the evidence, even if the data was exported by an app owner or operations team. In practice, the organisation should treat disconnected evidence as a compensating control with explicit risk acceptance, not as equivalent to system-collected proof.


Technical breakdown

Why flat files are not connected governance data

A flat file is a point-in-time export, not a live system integration. It only contains the fields the query asked for, the records the source system exposed, and the subset the exporter chose to include. That makes it structurally different from a direct connector, which can interrogate the system on schedule and reconcile deltas against current state. In IGA, that difference affects certification accuracy, entitlement completeness, and evidence quality. The platform may treat both inputs as equally covered, but the underlying assurance is not the same.

Practical implication: treat flat file feeds as provisional evidence, not verified coverage, until they are replaced with direct system connectors.

How stale entitlement data breaks access reviews

Access reviews only work when the data describes the current state of the account, role, and entitlement model. Quarterly or annual CSV feeds lag the operational system by months, so reviewers are asked to certify access that may already have changed, been revoked, or become excessive. Delta exports reduce file size, but they do not solve completeness or freshness. They can make the ingestion pipeline faster while still preserving blind spots in orphan accounts, service accounts, and hidden privilege tables. That means the review process is mathematically precise and operationally wrong at the same time.

Practical implication: shorten the interval between source-system syncs and certification campaigns, and block reviews that are based on stale exports.

Why auditors focus on the weakest file-based apps

Auditors know that flat file governance is easy to edit before ingestion and hard to reconstruct after the fact. A live connector gives them system-collected evidence; a CSV gives them a spreadsheet-shaped claim. That is why weakly governed apps attract deeper testing, more sampled accounts, and more requests for approval trails that owners must rebuild from email or tickets. The problem is not only control weakness, but evidentiary fragility. Once audit teams distrust the feed, they start testing the process behind the feed, which multiplies effort and cost.

Practical implication: prioritise the apps with manual uploads for remediation first, because they are the ones most likely to trigger audit scrutiny and exceptions.



NHI Mgmt Group analysis

Flat file governance creates a verification gap, not just a connector gap. The industry often talks about missing integrations as if the only issue is coverage, but the deeper failure is that identity teams start governing copies instead of systems. Once the IGA platform accepts a CSV as connected, it inherits whatever the exporter omitted, and that omission becomes part of the governance record. The practical conclusion is that verification, not ingestion, is the real control objective.

Identity governance was built on the assumption that connectivity implies current truth. That assumption fails when an app is represented by a manual export, because the platform can no longer prove completeness, freshness, or closed-loop remediation. The implication is not that manual reporting is slightly weaker, but that the governance model itself loses evidentiary integrity. Practitioners should stop treating flat files as a temporary integration class and treat them as a separate assurance tier.

Manual flat file feeds turn audit evidence into borrowed confidence. Certification results, board dashboards, and compliance attestations all look authoritative until someone asks how current the underlying data is and who validated the missing entitlements. Once the feed is a spreadsheet, the burden shifts from system-collected proof to human reconstruction. That makes the process expensive, slow, and easy to challenge. The practitioner takeaway is that any app dependent on human-exported evidence belongs in a high-risk governance queue.

Identity lifecycle controls fail when the offboarding and revocation loop is not machine-enforced. A CSV can tell the governance platform what access existed at export time, but it cannot confirm that removal actually occurred in the source system. That gap leaves orphan access and stale entitlements outside the lifecycle record. The implication is that lifecycle governance for disconnected applications must be judged by whether revocation can be verified, not by whether the app appears in a dashboard.

Flat file app coverage is a named governance debt that should be measured explicitly. The number of apps marked connected in the IGA console is not the same as the number of apps with live, system-collected evidence. Until teams separate those two counts, they will overstate control coverage and understate audit exposure. Practitioners should measure verified connections, not reported coverage, and make the delta a standing governance metric.

From our research:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • From our research: Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to The 2024 ESG Report: Managing Non-Human Identities.
  • The next governance breakpoint is not whether apps can be ingested, but whether identity teams can prove current state across human, NHI, and workload access without relying on exported copies.

What this signals

Flat file governance should now be treated as an evidence-quality problem, not an integration problem. Once identity teams start separating verified connections from reported coverage, they can expose the apps most likely to fail recertification and audit sampling. The fastest progress will come from routing high-risk systems into direct connectors and using the NHI Lifecycle Management Guide to reset how verification, not ingestion, defines control success.

Identity programmes that still rely on exported evidence will struggle against the assurance bar implied by NIST Cybersecurity Framework 2.0. The framework's govern and protect expectations assume evidence can be trusted, refreshed, and acted on. Flat-file dependencies make those outcomes harder to defend, especially where service accounts and other non-human identities sit behind the spreadsheet.

App portfolios will keep outpacing connector roadmaps, so the practical response is to formalise a 'verified connection' metric. Flat file coverage debt: the gap between apps counted as connected and apps actually readable from source will become a standing audit and risk measure. Teams that surface that gap early can prioritise remediation before it becomes a recurring exception pattern.


For practitioners

  • Separate verified connections from reported coverage Inventory every application that enters IGA through manual export, then tag it as flat-file governed rather than connected until a live connector is in place. Use that classification in risk reporting so dashboards show verified coverage, not just ingestion counts.
  • Prioritise high-risk apps for direct connectors Start with applications that hold privileged access, service accounts, or regulated data, because those are the feeds most likely to miss entitlements and trigger audit testing. Replace the CSV path with a direct connector before the next certification cycle.
  • Shorten the evidence freshness window Set a maximum age for entitlement evidence and block certifications when the source export is older than that threshold. If the system cannot sync frequently enough to support current-state review, the app should not be treated as fully governed.
  • Build audit-ready exception queues Create a remediation queue for every flat-file application so owners can document missing approvals, orphan accounts, and unresolved entitlements in one place. That reduces the scramble when auditors sample the weakest data sets.

Key takeaways

  • Flat file governance fails because identity platforms end up governing copies instead of live systems.
  • Reported app coverage can overstate real assurance, especially when certification and audit evidence come from stale exports.
  • Practitioners should measure verified connections, not dashboard counts, and move manual feeds into direct connectors first for the highest-risk apps.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Flat-file app coverage affects access provisioning and entitlement governance.
NIST SP 800-53 Rev 5AC-6Manual CSV governance can hide excessive privilege and stale access.
NIST Zero Trust (SP 800-207)Zero Trust depends on continuous verification, not snapshot evidence.
OWASP Non-Human Identity Top 10NHI-03Credential and entitlement governance is weakened when exports miss current state.

Treat manual export feeds as a control exception under NHI-03 until direct connectivity exists.


Key terms

  • Flat File Governance: A governance model that relies on exported reports, usually CSV files, instead of live system connections. It can provide a partial view of access, but it cannot prove completeness or freshness without additional controls, which makes it weaker for certification and audit evidence.
  • Verified Connection: A direct, system-collected identity data path that can read current accounts and entitlements from the source application. It gives governance teams evidence they can refresh and reconcile, instead of a static copy that may already be out of date when reviewed.
  • Identity Freshness: Identity freshness is the degree to which the governance system reflects the live state of accounts, groups, entitlements, and credentials. It is not just a performance metric. In practice, freshness determines whether access reviews, approvals, and offboarding actions are based on reality or on a delayed snapshot.
  • Coverage debt: Coverage debt is the gap between the assets a security platform should see and the assets it actually covers at a point in time. It grows when deployment, maintenance, or configuration work cannot keep pace with cloud churn, leaving risk visible only after the gap has already formed.

What's in the full article

Cerby's full article covers the operational detail this post intentionally leaves for the source:

  • How Cerby structures direct connectors for apps that cannot be integrated by the IGA platform
  • The operational differences between live connectors, scheduled exports, and flat-file ingestion for governance reporting
  • Examples of the manual app inventory problem across SaaS, cloud, and on-prem systems
  • Why audit teams focus on the weakest file-based apps and how that changes remediation priority

👉 Cerby's full post covers the connector model, audit scrutiny pattern, and governance gaps in more depth.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 30, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org