TL;DR: A broader shift toward identity-first security is reflected in Gartner’s 2025 Cool Vendor recognition for Orchid Security, with continuous application discovery, flow analysis, and orchestration aimed at exposing blind spots in managed and unmanaged identity paths, according to Orchid Security and Gartner. The real issue is not tooling novelty, but whether IAM programmes can see and govern identity as coded and as used across modern estates.
At a glance
What this is: Orchid Security’s post argues that Gartner’s identity-first security view points to a governance gap in enterprise apps, where hidden authentication and authorization paths create identity dark matter outside traditional IAM coverage.
Why it matters: This matters because IAM teams need evidence-based control over how applications actually handle identity, not just how accounts are provisioned, especially when unmanaged and embedded access paths sit outside standard onboarding and review processes.
Context
Identity-first security shifts the control point from perimeter assumptions to the application itself. That matters because many enterprise IAM programmes still govern identities at provisioning and onboarding, while the real risk sits in the runtime flows that applications use to authenticate, authorise, and expose access paths.
Orchid Security positions this as a visibility problem as much as a control problem: if enterprises cannot see identity as coded and as used, they cannot govern identity dark matter. The article frames Gartner’s recognition as evidence that application-level discovery and flow analysis are becoming central to IAM and governance decisions.
The topic is relevant to NHI, autonomous, and human identity programmes because the same governance gap appears whenever identity exists inside systems rather than only in directories. The article is most directly about enterprise IAM for applications, but the implications extend to any programme that must understand how access is actually enforced.
Key questions
Q: Where do IAM programmes fail when identity is embedded in applications?
A: They fail when governance stops at provisioning and never inspects the application’s actual authentication and authorization paths. In that case, access can exist outside directory records, recertification scope, and onboarding workflows. The result is partial assurance: the programme can describe who should have access, but not what the application really enforces.
Q: Why do hidden application identity paths create governance risk?
A: Because they break the assumption that all meaningful access passes through the central IAM process. When an application can create or sustain identity behaviour on its own, review, approval, and lifecycle controls lose visibility. That increases the chance that access remains active, mis-scoped, or unaudited even when the directory looks clean.
Q: What are the signs that identity-first security is failing in practice?
A: Common warning signs include excessive privileges, stale or unused identities, weak visibility into NHI activity, and access decisions that still rely on static rules instead of current risk. Teams should also watch for misconfigured IAM integrations, poor monitoring of third-party access, and delayed response to credential misuse. When these appear together, identity controls are probably not being enforced consistently enough.
Q: How should teams evaluate application identity controls versus directory controls?
A: Use application-level evidence as the test for whether directory controls are real in practice. If the application enforces different access paths, different tokens, or different authorization logic than the IAM record implies, the programme has a governance mismatch. That mismatch should be treated as a control defect, not a documentation issue.
Technical breakdown
Application-level identity discovery
Identity-first security starts by discovering the applications that actually issue, consume, or broker identity signals. In this model, discovery is not just inventory. It is the process of identifying where authentication and authorization logic lives, including embedded flows, unmanaged applications, and application-specific control paths that never reach the IAM team through normal onboarding. That matters because traditional governance assumes identity boundaries are explicit and centrally visible. Orchid Security’s framing, and Gartner’s commentary, both point to the need for runtime visibility into applications as the source of identity behavior.
Practical implication: map application identity flows before you try to govern them through directory-centric controls.
Authentication and authorization flow analysis
Authentication tells you who or what is presenting a claim, while authorization determines what that claim can do inside the application. Flow analysis looks at how those decisions are chained together across modern estates, including APIs and distributed applications. That is important because a large share of governance failures happen between provisioning and runtime, where the control plane says one thing and the application enforces another. The article’s central point is that hidden flow logic creates blind spots that standard IAM onboarding does not resolve, especially when applications evolve faster than governance processes.
Practical implication: compare application-enforced access paths against your IAM assumptions, not just against directory records.
Identity dark matter in enterprise governance
Identity dark matter is the unseen or unmanaged half of enterprise identity, where access exists outside formal IAM visibility. The term captures a structural problem rather than a one-off gap: if an application can create or sustain access without appearing in normal governance workflows, recertification and onboarding controls will miss it. Gartner’s view, as quoted in the article, places this problem inside the shift to identity-first security because perimeter-based models no longer explain where access risk now accumulates. The deeper issue is that governance loses accuracy when identity is embedded in code, orchestration, and application-native logic.
Practical implication: treat unseen application identity paths as governance debt, not as isolated exceptions.
NHI Mgmt Group analysis
Identity-first security is becoming a governance model, not just a visibility model. The article shows that the market is moving toward application-level identity control because provisioning-era IAM no longer captures how access is actually created and used. That shift matters because the control surface is no longer the directory alone but the application flow that enforces identity at runtime. Practitioners should treat this as a programme design change, not a tooling upgrade.
Application identity visibility is now a prerequisite for credible IAM, IGA, and compliance claims. If an organisation cannot trace authentication and authorization behaviour inside applications, its recertification, onboarding, and risk prioritisation decisions are built on partial evidence. That weakens governance even when directory hygiene looks strong. The practical conclusion is that identity assurance has to move closer to where applications make access decisions.
Identity dark matter is the right name for the control blind spot enterprises keep underestimating. The article’s strongest contribution is not the vendor recognition itself, but the framing of unmanaged and unseen identity paths as a structural governance issue. That concept is useful because it separates ordinary IAM backlog from access that never enters the programme in the first place. Practitioners should use the term to force discussion of what their current governance model cannot see.
Orchestration is becoming part of identity governance, but only when it exposes evidence rather than hiding complexity. The article suggests that application discovery, flow analysis, and automated onboarding can reduce manual effort, yet the governance value comes from making identity behaviour measurable. This is where identity-first security differs from older integration narratives. The implication for practitioners is to judge orchestration by whether it improves control evidence, not by whether it reduces ticket volume.
What this signals
Identity-first security should be treated as a programme boundary change. If identity governance cannot reach into application logic, then onboarding, recertification, and access review processes will continue to miss the places where access is actually enforced.
Identity dark matter: hidden application identity paths are no longer a niche architecture problem but a governance blind spot that will keep widening as enterprises rely on more distributed and API-driven applications. The practical response is to make application identity visibility a standard input to IAM and IGA decisions.
For practitioners
- Inventory application identity flows Identify where applications perform authentication, authorization, and identity propagation outside the core IAM stack, including unmanaged and embedded paths.
- Trace identity dark matter Document applications and access paths that never reach onboarding, review, or recertification workflows so governance can be extended to them.
- Compare runtime access to policy intent Test whether the access applications enforce matches what IAM and governance teams believe is provisioned, approved, or least-privileged.
- Prioritise evidence-based remediation Focus first on applications where hidden identity paths create the largest compliance, business, or operational exposure rather than spreading effort evenly across the estate.
Key takeaways
- The article’s core message is that enterprise identity governance now depends on seeing access where applications actually enforce it, not only where IAM provisions it.
- Hidden application flows create a governance blind spot because they can sustain access outside the normal onboarding and review lifecycle.
- The control implication is to move from directory-only oversight to application-level evidence when deciding what to govern first.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Hidden application identity paths often mask access that exceeds intended scope or governance visibility. |
| Recommendation — Inventory application identities whose actual access exceeds the scope recorded in governance systems. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centers on whether access permissions match what applications enforce in practice. |
| Recommendation — Validate application-enforced entitlements against IAM policy intent and investigate mismatches. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Authentication flows and identity tokens are part of the runtime control gap discussed here. |
| Recommendation — Review authenticator lifecycle and scope wherever application-native identity paths bypass central IAM. | ||
Key terms
- Identity-first security: Identity-first security is an approach that treats identity as the primary control plane for managing risk. Instead of relying mainly on network or endpoint boundaries, it uses identity context to decide what can happen, when it can happen, and under what conditions. That model is especially relevant where privileges move across human, non-human, and agentic actors.
- Identity Dark Matter: Identity dark matter is the hidden mass of old grants, unused credentials, and inherited access that exists in an environment but is not actively understood. In NHI programmes it becomes dangerous because autonomous systems can discover and reuse it at machine speed.
- Application identity flow: An application identity flow is the complete path by which an application authenticates, authorises, and exchanges identity data with users or other systems. It includes direct login, federation, service-to-service authentication, and exception handling, which means hidden flows can quietly undermine enterprise identity governance.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org