TL;DR: Identity-focused M&A in late 2025, combined with faster identity automation and AI-driven discovery, is pushing comprehensive app coverage from a future goal to an operational expectation, according to Cerby and the executives it cites. The real test is no longer whether identity matters, but whether enterprises can govern the applications they already own before coverage gaps become technical debt.
At a glance
What this is: This analysis says identity consolidation is making comprehensive app coverage an operational expectation, while many enterprises still cannot govern the applications they already have.
Why it matters: IAM and security teams need to treat disconnected apps, AI-assisted discovery, and identity lifecycle coverage as one governance problem rather than separate initiatives.
Context
Identity consolidation is reshaping how enterprises think about governance because the control problem is no longer limited to a few high-value systems. The primary challenge is now app coverage across a sprawling environment, where disconnected applications sit outside standard identity tooling and leave governance incomplete.
Cerby frames 2026 as an inflection point for IAM programmes because vendor consolidation is happening faster than enterprise coverage remediation. The article argues that acquisition activity confirms identity’s strategic value, but it does not eliminate the structural gap created by apps that are still unmanaged or only partially governed.
The article also places AI and machine identity inside the same governance conversation. That matters because discovery, workflow generation, and credential handling now intersect with a much larger application estate and a large non-human identity footprint.
Key questions
Q: How should teams handle applications that do not support standard identity integration?
A: Treat those applications as governance gaps, not technical edge cases. Build a coverage inventory, rank apps by business criticality and exposure, and decide which disconnected systems need immediate onboarding into identity workflows. If an application cannot be governed, it should be explicitly tracked as risk debt rather than left invisible in the programme.
Q: Why do disconnected applications create identity governance risk?
A: They create risk because the organisation cannot reliably see, certify, or revoke access through the same control plane used for integrated systems. That produces blind spots in entitlement visibility, audit evidence, and offboarding, especially as the application count grows.
Q: What do IAM teams get wrong about AI-driven identity security?
A: They often treat AI-driven features as a tooling upgrade rather than a governance shift. The real issue is whether policy, lifecycle control, and telemetry can work together across human and non-human identities when access patterns are more dynamic than traditional review cycles.
Q: How do organisations decide when to prioritise coverage over more point controls?
A: Prioritise coverage when the gap is that important apps or identities are still outside governance, because more point controls do not fix invisibility. If the estate itself is only partly covered, the highest-value work is to widen control reach before adding more refinement. Coverage comes first when the blind spot is bigger than the control improvement.
Technical breakdown
Why disconnected applications stay outside identity control
Disconnected applications are systems that do not support the standards or APIs required for normal identity automation. In practice, that means they often remain outside provisioning, access review, and offboarding workflows even when they are operationally important. The article’s point is not that these apps are rare, but that they have historically been left behind because integration was too slow or expensive. Modern connector approaches reduce that excuse, but they do not erase the underlying governance problem: if the app is outside the identity plane, the control plane is incomplete.
Practical implication: inventory the apps that still sit outside standard identity tooling and treat them as governance gaps, not exceptions.
How AI changes identity discovery and workflow generation
AI is being applied to identity operations in two different ways. First, it can help auto-discover applications and generate integration workflows faster than manual methods. Second, it introduces decision risk when used in identity workflows that require deterministic outcomes. Even a small error rate matters if the system can place a credential in the wrong field or assign permissions incorrectly. The architectural issue is not whether AI can assist, but whether the workflow tolerates variability. For identity governance, discovery and orchestration are more suitable than autonomous permissioning.
Practical implication: constrain AI to discovery and workflow assistance, and keep permission assignment and credential handling deterministic.
Why machine identities now belong in the same governance model
The article’s machine identity point is operationally important because app coverage is no longer only about human users. APIs, service accounts, and OAuth tokens create a much larger identity surface that often grows faster than human access can be reviewed. When those identities are over-permissioned, the governance problem shifts from access convenience to blast radius. That is why coverage and lifecycle management have to include both user-facing applications and the non-human identities attached to them.
Practical implication: extend coverage metrics to service accounts, APIs, and tokens, not just human access paths.
Threat narrative
Attacker objective: The objective is to exploit governance blind spots created by disconnected applications and over-permissioned identities before the enterprise closes them.
- Entry occurs through unmanaged or weakly governed applications that sit outside standard identity tooling, creating blind spots in the enterprise control plane.
- Credential and permission sprawl follow when these applications are onboarded without consistent lifecycle controls or review coverage.
- Impact emerges as coverage gaps accumulate into technical debt, delayed access governance, and a wider attack surface across both human and machine identities.
Breaches seen in the wild
- JumpCloud breach 2023: North Korean hackers breached JumpCloud and abused its device commands framework against a few customers; all admin API keys were reset.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity consolidation is now a governance problem, not just a market trend. The article shows that major vendors are buying identity capability because the market now expects identity to be part of the core security stack. That does not mean enterprises have solved governance; it means identity has become the control surface everyone must now cover. The practitioner conclusion is that consolidation raises expectations faster than most programmes can currently meet them.
Coverage debt is the real structural gap. The most important finding here is not the headline M&A activity, but the fact that many enterprises still lack control over the applications they already own. This is a classic governance blind spot: the estate exists, the business depends on it, and the identity programme does not fully see it. The implication is that coverage metrics must become a board-level operational signal, not a technical afterthought.
Identity automation only helps when the workflow is deterministic. The article’s AI discussion is useful because it separates discovery and orchestration from permission assignment. That distinction matters for human IAM, NHI governance, and autonomous systems alike, because identity decisions that tolerate variability create audit and risk problems immediately. The practitioner conclusion is to treat AI as an accelerant for inventory and workflow design, not as a substitute for controlled decision points.
Machine identity governance is part of the same coverage story. The article notes that enterprises now have far more machine identities than employees, and many are over-permissioned. That is not a side note; it is the evidence that app governance, human access, and NHI lifecycle are converging into one management problem. The practitioner conclusion is to govern the application estate and the identities inside it as a single control system.
2026 will separate programmes that scale from programmes that stall. Cerby’s analysis argues that the technical and economic barriers to broader coverage have fallen. What remains is programme design, ownership, and prioritisation. That means identity teams will be judged less by intent and more by whether they can expand coverage across the long tail of applications without creating operational drag.
What this signals
Coverage debt now defines identity maturity. Enterprises that only govern the easy applications will keep accumulating blind spots, especially as vendor consolidation raises expectations for end-to-end identity coverage. The practical signal is that coverage percentage should be treated as a governance metric alongside access delay and exception count.
Identity automation is becoming a design discipline. The next phase of IAM is not more tooling by itself, but better decisions about which workflows can be automated safely and which must remain deterministic. That distinction matters across human IAM, NHI governance, and emerging autonomous use cases.
Machine identities are part of the same estate problem. As application coverage expands, the boundary between human access governance and NHI lifecycle management keeps fading. Programmes that measure only employee access will miss the real scale of privilege exposure.
For practitioners
- Audit application coverage gaps Map every application against current identity controls and flag any system outside provisioning, access review, or offboarding coverage.
- Classify disconnected apps by risk Prioritise the last mile applications, especially marketing tools, social platforms, HR portals, finance portals, and on-premise systems that sit outside standard connectors.
- Constrain AI to deterministic workflows Use AI for discovery and workflow generation, but keep permission assignment and credential handling under deterministic rules and review gates.
- Extend governance to machine identities Include APIs, service accounts, OAuth tokens, and other non-human identities in coverage metrics, lifecycle reviews, and exception tracking.
- Treat identity as a dedicated function Assign clear ownership for identity programme coverage, lifecycle operations, and continuous remediation instead of folding it into a part-time admin role.
Key takeaways
- Identity consolidation is pushing enterprise teams to treat coverage as a core governance requirement rather than a future aspiration.
- The article’s core warning is that acquisition activity does not close the gap created by disconnected applications already in production.
- IAM programmes that expand coverage, constrain AI to deterministic tasks, and include machine identities will be better positioned for 2026.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article highlights over-permissioned machine identities at enterprise scale. |
| NHI-09 — NHI Reuse | Disconnected apps and shared workflows often lead to reused identities and unmanaged trust paths. | |
| Recommendation — Inventory overprivileged machine identities and tighten access scope before coverage gaps expand. Eliminate reused non-human identities across disconnected applications and enforce unique ownership. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article warns against using agentic AI in identity decisions that require deterministic behaviour. |
| Recommendation — Constrain agentic identity workflows so privilege assignment cannot be abused or misrouted at runtime. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The central issue is incomplete coverage of permissions and entitlements across the app estate. |
| Recommendation — Expand authorization coverage to include disconnected apps and non-human identities. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article’s governance gaps increase credential abuse and movement opportunities across the estate. |
| Recommendation — Map coverage blind spots to credential access and lateral movement paths in your detection strategy. | ||
Key terms
- Identity Coverage: The portion of an organisation’s application and account estate that is actually reachable by central identity controls. For disconnected environments, coverage is not just about count or inventory. It is about whether policy, lifecycle, and verification can be enforced end to end.
- Disconnected Application: An application that is not integrated with the organisation's central identity and access stack. Access is often managed through shared passwords, manual approval, or local admins, which makes revocation, evidence, and ownership harder to enforce consistently across the application lifecycle.
- Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
- Deterministic Workflow: A deterministic workflow is a fixed sequence of investigation steps that produces the same output when given the same inputs. In SOC automation, it reduces variability, improves auditability, and creates a stable evidence trail before any AI reasoning is applied.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org