By NHI Mgmt Group Editorial TeamDomain: Best PracticesSource: UnixiPublished May 28, 2026

TL;DR: Up to 80% of enterprise applications sit outside traditional SSO and remain largely invisible to security teams, according to Unixi, while password managers do little to enforce policy, prevent phishing, or offboard users cleanly. The deeper issue is identity sprawl beyond governed control, not simply weak user behaviour.


At a glance

What this is: This is a vendor blog arguing that organisations overestimate SSO coverage and underestimate unmanaged identities, shared accounts, and shadow SaaS outside the identity perimeter.

Why it matters: It matters because IAM, PAM, and NHI programmes fail if they only cover managed SAML apps and ignore the uncontrolled access paths where most operational risk now accumulates.

By the numbers:

👉 Read Unixi's analysis of identity dark matter, password managers, and unmanaged access


Context

Identity dark matter is the unmanaged access surface that sits outside formal SSO, lifecycle controls, and governance visibility. In practice, that includes non-SAML business portals, shared utility accounts, shadow SaaS, and AI tools adopted without security oversight. For identity teams, the problem is not just convenience tooling, but the fact that control planes stop where many real credentials begin.

The primary IAM issue is not whether a password vault stores secrets, but whether the organisation can enforce policy, revoke access, and prove oversight across the full access estate. When unmanaged apps and shared credentials sit outside the identity programme, recertification, offboarding, and audit evidence become incomplete. That creates a governance gap across human identities and NHI-style account estates alike.

This is a typical enterprise blind spot, not an edge case. Mature organisations often secure their core apps while leaving a much larger set of access paths in the dark, which is exactly where attackers, departing users, and shadow workflows tend to concentrate.


Key questions

Q: What breaks when organisations rely on SSO and password managers as their main identity controls?

A: The control model breaks when major parts of the application estate sit outside federation and the vault only stores secrets instead of enforcing policy. Teams lose visibility, cannot prove revocation at the target app, and often miss shared or residual access. That leaves the organisation with better convenience, but not better governance.

Q: Why do unmanaged identities increase IAM risk even when SSO and MFA are deployed?

A: Because SSO and MFA only cover interactive human authentication, not the full set of service accounts, secrets, and delegated machine credentials that operate outside login flows. If those identities are unmanaged, they can persist, multiply, and retain privilege without the same visibility that human access gets.

Q: How do security teams know whether a password vault is actually reducing risk?

A: They should look for three signals: whether the vault is tied to application-level revocation, whether it supports audit evidence for access reviews, and whether users still possess alternate ways to authenticate. If the organisation cannot answer those questions confidently, the vault is probably organising secrets rather than governing them.

Q: Who is accountable when a shadow SaaS app creates access and cost risk?

A: Accountability should rest with the business owner who introduced the tool, the technical owner who governs access, and the platform or procurement team that approved spend. If those roles are not defined, the organisation cannot close the loop on offboarding, revocation, or renewal, which is how shadow IT becomes persistent.


Technical breakdown

Why SSO coverage does not equal identity control

SSO consolidates authentication for apps that support federation, but it does not automatically govern every credentialed system in the environment. Many portals, legacy applications, shared accounts, and utility logins still use local passwords or ad hoc access methods. That means the identity provider may control the front door for some applications while leaving a large portion of the access estate unmanaged. Visibility and enforcement are different functions, and enterprises often confuse the two.

Practical implication: inventory every application that is outside federated authentication and treat it as a governance gap, not a convenience issue.

Why password managers do not create policy enforcement

Password managers reduce the user burden of storing and entering secrets, but they do not remove the underlying security dependency on user behaviour. If the person can see, copy, reuse, or disclose a credential, phishing and social engineering still work. A vault may centralise secrets, but centralisation is not enforcement. It also does not by itself prove that the account was revoked at the target application, which is the difference between storage and control.

Practical implication: do not count vault adoption as compensating control unless it is paired with application-level revocation and audit evidence.

Why shared accounts and shadow SaaS break lifecycle governance

Shared utility accounts and unsanctioned SaaS tools complicate joiner-mover-leaver processes because they are often invisible to formal ownership and recertification workflows. A user can leave, change role, or bypass governance entirely while the credential persists in the business process. That creates residual access that outlives the original business need. In identity terms, the lifecycle is not closed simply because the human relationship has ended; the application and secret still remain active.

Practical implication: extend lifecycle management beyond human accounts to shared, delegated, and application-specific credentials that support the business.


Threat narrative

Attacker objective: The attacker seeks durable access to business systems through credentials and accounts that the identity programme does not fully control.

  1. Entry occurs through unmanaged applications, shared credentials, or shadow SaaS accounts that sit outside SSO and normal monitoring.
  2. Escalation follows when users reuse weak passwords, disclose secrets through phishing, or leave residual access behind after offboarding.
  3. Impact lands as unauthorised access, lateral movement across connected systems, and incomplete forensic visibility when the identity estate is not fully governed.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity dark matter is a governance failure, not a tooling gap: the real problem is that many enterprise access paths never enter the control plane at all. SSO, vaults, and recertification only work on the identities they can see. Once the application estate extends beyond those boundaries, the programme has no reliable basis for enforcement, evidence, or offboarding.

Password managers are storage systems, not identity controls: they can reduce friction, but they do not revoke access at the application, stop password reuse, or prevent disclosure under pressure. That means they may improve convenience while leaving the security model unchanged. Practitioners should treat vaults as a user aid unless they are tied to policy enforcement and lifecycle closure.

Shared credentials create NHI-style accountability debt: when business portals, service accounts, and utility logins are owned informally, the organisation cannot prove who should have access, who used it, or when it should be removed. That breaks the assumptions behind access review and privilege governance. The implication is that lifecycle scope must extend to every credentialed actor, not just employees in the HR system.

Identity dark matter needs a named concept: control-plane blind spot: this is the gap between what the IdP governs and what the business actually uses. The more the stack depends on local passwords, shadow tools, and unmanaged logins, the more the identity programme becomes a partial map rather than a security control. Practitioners should assume any un-federated application is a candidate for hidden access risk.

Vault centralisation can concentrate risk while hiding it: a password vault may reduce user chaos, but it can also create a single place where secrets are organised without being governed. That matters because the attack surface shifts from scattered reuse to a concentrated repository of credentials and recovery paths. Identity teams need to evaluate whether the vault is reducing risk or simply reformatting it into a more convenient target.

From our research:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Our research also found that only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, which shows how narrow the confidence gap really is.
  • This connects directly to NHI Lifecycle Management Guide, where lifecycle closure is treated as a governance problem, not a storage problem.

What this signals

Control-plane blind spots are now a programme-level risk, because identity teams cannot defend what they cannot enumerate. In practice, the next maturity step is not another vault deployment, but a complete map of un-federated applications, shared accounts, and shadow tools that sit outside policy enforcement.

As organisations add AI tools and non-standard portals, the identity perimeter becomes more fragmented, not less. Teams should assume that any access path outside SSO will eventually bypass some combination of recertification, logging, or offboarding unless it is brought under explicit lifecycle ownership.

For practitioners, the operational signal is simple: if you cannot prove application-level revocation, you do not yet have closed-loop identity governance. That is the standard to measure against, whether the credential belongs to a person, a service account, or a shared business login.


For practitioners

  • Map the unmanaged access estate Build an application and credential inventory that includes non-SAML portals, shared utility accounts, shadow SaaS, and AI tools used outside IT oversight. Treat anything outside federation as governed risk, not as an exception to ignore.
  • Separate storage from enforcement Do not count a password manager as a control unless it is paired with application-level revocation, audit logging, and policy enforcement. Use it only where you can prove the secret is removed from the target system when access ends.
  • Extend lifecycle reviews to shared and delegated accounts Include service accounts, shared logins, and utility credentials in access reviews, ownership assignment, and offboarding workflows. If no accountable owner exists, the credential should be treated as an unresolved governance defect.
  • Eliminate residual access at the application layer Test whether deprovisioning actually removes the user from the application, not just from the vault or the directory. Confirm that revocation closes cached, remembered, and locally stored access paths, especially for high-risk portals.
  • Prioritise the highest-blind-spot systems first Start with the applications that sit outside SSO but hold sensitive data or operational authority. These are usually the fastest route to breach impact because they combine weak visibility with business-critical access.

Key takeaways

  • The article’s central claim is that SSO coverage does not equal identity control when large parts of the application estate remain outside governance.
  • The strongest evidence is the claimed 80% blind spot, plus research showing that weak passwords, reuse, and residual access remain common failure conditions.
  • Practitioners should measure control-plane coverage, application-level revocation, and lifecycle ownership across all credentialed access paths, not just federated apps.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01The article centers on unmanaged non-human and shared identities outside governance.
NIST CSF 2.0PR.AC-4Least-privilege access and access management are directly implicated by hidden credentials.
NIST SP 800-53 Rev 5IA-5Password and authenticator management are central to the password vault critique.
NIST Zero Trust (SP 800-207)The article exposes identity trust assumptions that zero trust should not leave implicit.

Apply IA-5 to ensure credential lifecycle, revocation, and reuse rules are enforced beyond storage.


Key terms

  • Identity Dark Matter: Identity dark matter is the hidden mass of old grants, unused credentials, and inherited access that exists in an environment but is not actively understood. In NHI programmes it becomes dangerous because autonomous systems can discover and reuse it at machine speed.
  • Control-plane blind spot: A part of the environment where security and governance tools cannot reliably see, validate, or enforce change. When resources are created outside code, the control plane has less context and weaker evidence about who changed what and when. Blind spots are where misconfiguration and accountability failures tend to persist.
  • Application-local Revocation: Application-local revocation is the act of removing access, tokens, licenses, and ownership inside the SaaS application itself, not just in the directory or SSO layer. It is necessary because many apps keep permission state after central authentication is disabled.
  • Shared Utility Account: A credential used by multiple people or processes to perform a business function such as shipping, administration, or platform support. These accounts often lack a stable owner, which makes access review, offboarding, and forensic attribution materially harder than with individually assigned accounts.

What's in the full article

Unixi's full blog post covers the operational detail this post intentionally leaves for the source:

  • The article's full comparison of password vault behaviour versus application-level access control for non-SAML apps
  • The specific examples of residual access, offboarding gaps, and shared account misuse that support the argument
  • The vendor's architecture claims around Universal SSO and decentralized key handling, which this analysis does not evaluate
  • The forensic-audit positioning for identifying unmanaged apps, missing MFA, and shadow SaaS profiles

👉 Unixi's full post details the dark matter control gap, vault limitations, and its proposed identity sovereignty model

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org