TL;DR: Identity compromise now underpins 83% of cloud intrusions, and SailPoint argues that directory-bound governance leaves blind spots across non-native apps, legacy systems, and non-human identities. The real issue is not authentication alone but the collapse of enterprise-wide entitlement visibility once access moves beyond the primary directory perimeter.
At a glance
What this is: This is a blog post arguing that ecosystem-bound directories leave critical identity blind spots across hybrid environments, especially for non-native apps, lifecycle gaps, compliance reporting, and non-human identities.
Why it matters: It matters because IAM teams must govern access across human, machine, and AI identities without assuming the primary directory can see or control everything.
By the numbers:
- Identity compromise now underpins 83% of all cloud intrusions.
- 63% of organizations remain trapped in low-maturity security postures, relying on manual processes and siloed architectures.
👉 Read SailPoint's analysis of identity blind spots across hybrid environments
Context
Identity governance breaks down when a directory can authenticate users but cannot see what they can do inside non-native applications, legacy databases, cloud infrastructure, or machine-driven workflows. That gap creates blind spots in entitlement management, lifecycle control, and audit evidence, which is why hybrid environments become harder to govern than the directory model assumes.
The post is fundamentally about the limits of ecosystem-bound identity tooling, not about authentication alone. It extends naturally to NHI governance because machine accounts, APIs, and AI agents often sit outside human-centric directories, which means the same perimeter problem now affects both human and non-human access.
SailPoint frames this as a visibility crisis across enterprise identity. The core issue is typical, not edge-case behaviour: most organisations still rely on a primary directory as though it can govern the full entitlement surface, even though modern environments extend far beyond that boundary.
Key questions
Q: What breaks when identity governance stops at the primary directory?
A: Governance becomes partial because authentication is visible while effective permissions remain hidden inside non-native applications. That leaves teams unable to certify, recertify, or remove toxic access with confidence. The practical result is an identity programme that can prove who signed in, but not what authority they actually exercised.
Q: Why do cross-system access reviews fail in hybrid environments?
A: They fail when accounts are fragmented and cannot be reliably linked back to one identity. Without that correlation, reviewers see isolated permissions instead of conflicting access patterns, so toxic combinations can survive multiple review cycles without being recognised as a governance issue.
Q: How should security teams govern non-human identities at scale?
A: Security teams should treat non-human identities as a lifecycle problem with ownership, review, rotation, and revocation built in from the start. Inventory is necessary but insufficient. The control objective is to ensure every service account, token, or automation identity has a clear purpose, a bounded scope, and a reliable offboarding path when it is no longer needed.
Q: When should organisations replace directory-native controls with an identity overlay?
A: They should do so whenever access extends into systems the native directory cannot govern at entitlement level. If the business depends on non-native apps, legacy platforms, or non-human identities, a dedicated overlay becomes necessary to provide complete visibility and policy enforcement.
Technical breakdown
Why directory perimeter models fail in hybrid identity estates
A primary directory typically handles authentication and basic account administration, but it does not automatically govern entitlements inside every downstream system. Once access crosses into non-native applications or infrastructure, the platform’s functional perimeter ends and entitlement visibility thins out. That is why identity security in hybrid estates depends on an overlay model that can reach across systems rather than assuming the directory is the system of record for all access decisions.
Practical implication: map where your directory loses entitlement visibility and treat those systems as separate governance domains.
Cross-system SoD depends on identity correlation, not logins
Separation of Duties fails when the same person has fragmented accounts across multiple systems that no native tool can correlate. A user can appear compliant in one platform while holding conflicting privileges elsewhere, such as invoice submission in one application and payment approval in another. The technical requirement is a unified identity profile that links those accounts so policy can evaluate toxic combinations across the full environment, not only within a single directory boundary.
Practical implication: correlate accounts across systems before you rely on SoD reports for audit or fraud prevention.
Non-human identities need lifecycle governance, not just discovery
Machine accounts, APIs, and AI agents can accumulate standing access outside HR-driven workflows because they do not follow human joiner, mover, leaver patterns. If they are not inventoried, tied to owners, and governed through lifecycle actions, stale permissions persist long after their business purpose changes. The article’s point is that non-human access becomes dangerous when it is left outside the same governance cycle that already applies to people.
Practical implication: bring non-human identities into the same lifecycle controls you use for offboarding and access review.
Threat narrative
Attacker objective: The objective is to exploit governance blind spots to gain durable access across systems that appear compliant at the directory layer but are not actually controlled end to end.
- Entry occurs when an attacker reaches a system whose directory login is governed, but whose downstream entitlements are not visible or controlled.
- Escalation happens when fragmented accounts, stale permissions, or unmanaged non-human identities provide broader access than the primary directory exposes.
- Impact follows when the attacker abuses hidden entitlements, toxic access combinations, or lingering accounts to move through hybrid systems without detection.
Breaches seen in the wild
- MongoBleed breach — MongoBleed exposed secrets across 87K MongoDB servers.
- Google Firebase misconfiguration breach — Firebase misconfigurations exposed 19.8M secrets across developer instances.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Directory-centric governance is no longer enough once access leaves the native perimeter. The article correctly identifies the structural gap between authentication and entitlement control. A directory can confirm identity, but it cannot by itself govern permissions inside every non-native app, database, or cloud control plane. Practitioners should treat perimeter-bound identity as a partial control plane, not a complete one.
Cross-system identity correlation is the control that makes SoD real. Separation of Duties is not an application feature, it is an identity outcome that depends on linking accounts back to one person or one non-human owner. Without that correlation, conflicting privileges can sit invisibly across systems and survive every local review. The practical conclusion is that SoD must be evaluated across the enterprise identity graph, not inside isolated platforms.
Unmanaged non-human identities are the fastest way for blind spots to become breach paths. Machine accounts, APIs, and AI agents often sit outside human HR processes, which means their access can persist after ownership changes or business drift. That makes NHI governance a lifecycle problem, not just a discovery problem. The implication is clear: if non-human identities are not governed with the same rigor as human access, the blind spot becomes an attack surface.
Post-authentication authorization is the right named concept for this problem space. The article shows that many organisations still overinvest in who logged in and underinvest in what they can do after login. That is where hybrid identity risk concentrates, because the real exposure sits in entitlements, cross-system privileges, and stale non-human access. Security teams should reframe identity coverage around authorization depth, not login completeness.
From our research:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to 2024 ESG Report: Managing Non-Human Identities.
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.
- Use the NHI Lifecycle Management Guide to translate discovery into provisioning, rotation, and offboarding controls.
What this signals
Post-authentication authorization becomes the governance battleground. As more access moves beyond the native directory, the practical question is no longer whether users can sign in but whether their entitlements are visible, correlated, and reviewable across the full estate. That shifts IAM programmes toward entitlement coverage, cross-system SoD, and non-human lifecycle control rather than directory completeness.
The post also points to a broader operating model change. Teams that still rely on manual review packs, spreadsheets, and siloed platform reports will continue to undercount risk, especially where machine identities and AI agents are involved. The more hybrid the environment becomes, the more governance must be expressed as an identity graph with policy attached, not a collection of isolated admin consoles.
For practitioners, the next step is to align the control model with the blast radius of the environment. If a platform cannot show who has what inside non-native systems, it cannot be the final authority for access governance. The stronger pattern is to pair native authentication with an enterprise identity layer and then validate that layer against the Ultimate Guide to NHIs , Key Challenges and Risks.
For practitioners
- Inventory entitlement visibility gaps List every application, database, cloud service, and machine identity domain where your primary directory cannot natively see entitlements. Mark those systems for separate governance because authentication coverage is not the same as authorization coverage.
- Unify cross-system identity correlation Correlate accounts that belong to the same person or non-human owner before relying on SoD reports, access reviews, or fraud checks. The goal is to expose toxic privilege combinations that would remain hidden inside fragmented account records.
- Bring non-human identities into lifecycle control Extend joiner, mover, leaver processes to service accounts, APIs, machine credentials, and AI agents. Offboarding, ownership changes, and periodic certification should apply to these identities just as they do to human users.
- Replace spreadsheet reviews with entitlement-aware governance Use policy and audit workflows that can evaluate real entitlements inside downstream systems instead of compiling manual evidence from spreadsheets. That reduces stale reporting and closes the delay between access change and governance visibility.
Key takeaways
- The core risk is not just weak authentication, but hidden authorization across systems the primary directory cannot govern.
- The evidence points to a maturity gap in both human and non-human identity oversight, especially where hybrid environments fragment visibility.
- The practical answer is enterprise-wide entitlement governance that includes lifecycle control for machines, APIs, and AI agents.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 — Insecure Authentication Methods | The post centres on unmanaged machine and AI identities that sit outside normal governance. |
| Recommendation — Inventory non-human identities and enforce ownership, scope, and lifecycle controls on every credential. | ||
| NIST CSF 2.0 | PR.AC-4 — Access Permissions and Authorisations | The article is fundamentally about hidden permissions and weak authorization visibility across systems. |
| Recommendation — Map downstream entitlements to PR.AC-4 and verify access is visible beyond the primary directory. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Least privilege is a central claim in the post's treatment of post-authentication authorization. |
| Recommendation — Apply AC-6 to reduce hidden entitlements and remove access that cannot be justified end to end. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article focuses on fragmented accounts, offboarding delays, and incomplete account governance. |
| Recommendation — Use CIS-5 to centralise account visibility and revoke stale access across all connected systems. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | Hidden identity gaps create opportunities for credential abuse and movement across hybrid systems. |
| Recommendation — Hunt for credential abuse and cross-system movement wherever directory visibility ends. | ||
Key terms
- Post-Authentication Authorization: Post-authentication authorization is the decision layer that governs what an identity can access after login succeeds. It matters because SSO and MFA prove identity, but they do not limit entitlement scope, which is where many cloud access failures and over-privilege problems emerge.
- Identity Blind Spot: An identity blind spot is any gap where an organisation cannot fully see, inventory, or govern an identity and its access rights. Blind spots are especially dangerous for NHIs because they often live in code, pipelines, or third-party integrations outside normal review cycles.
- Cross-System Separation Of Duties: A governance control that prevents one identity from holding conflicting permissions across different systems. It only works when accounts are correlated back to a single person or owner, because fragmented identity records can hide toxic access combinations that would be obvious in one platform.
- Non-Human Identity Governance: Non-human identity governance is the practice of managing, controlling, and auditing every machine identity across its full lifecycle. It covers service accounts, API keys, tokens, certificates, and AI agent credentials — ensuring each has a defined owner, scoped privilege, rotation schedule, and revocation path. Without governance, NHIs accumulate silently and become the primary attack surface in cloud and automated environments.
What's in the full article
SailPoint's full blog covers the operational detail this post intentionally leaves for the source:
- The full five blind spots mapped one by one, including post-authentication authorization, SoD, lifecycle, compliance, and non-human identity governance.
- Connector and entitlement coverage details for non-native databases, ERP systems, cloud infrastructure, and machine identity environments.
- The article's own framing of the co-existence model between native directory controls and enterprise-wide governance.
- The webinar reference for practitioners who want the broader discussion that sits behind the blog narrative.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on September 16, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org