TL;DR: Identity hygiene depends on visibility, governance, and modern SSO coverage, because shadow SaaS adoption and token-based SSO weaknesses can expand attack paths across the enterprise, according to Unixi. The core issue is that IAM programmes often assume they can govern what they cannot see, which fails once users create unsanctioned application accounts.
At a glance
What this is: This is a commentary on identity hygiene that argues shadow SaaS visibility, approval controls, and modern SSO coverage are now basic IAM requirements.
Why it matters: It matters because IAM teams have to govern human access into SaaS sprawl, where unmanaged application adoption can bypass identity policy, weaken assurance, and widen the blast radius of credential theft.
By the numbers:
- 80% of employees adopt SaaS applications without IT approval, with 10% reporting data breaches or data loss as a result.
- Only 5.7% of organisations have full visibility into their service accounts.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
👉 Read Unixi's analysis of identity hygiene, shadow SaaS, and SSO risk
Context
Identity hygiene is the discipline of keeping identity systems visible, governed, and aligned to policy across users, applications, and access pathways. In a cloud-first environment, that means security teams cannot treat SaaS adoption as a side issue, because unsanctioned applications quickly become part of the access fabric.
The article’s central warning is that visibility gaps create governance gaps. If teams cannot discover shadow SaaS, they cannot review its access paths, apply approval workflows, or understand where authentication tokens and credentials are being stored and reused.
For practitioners building an IAM programme, the immediate question is not whether users will adopt external applications, but whether the organisation can see, approve, and control that adoption before data and access sprawl outrun policy. The Ultimate Guide to NHIs covers the broader lifecycle implications of that visibility gap.
Key questions
Q: What breaks when organisations cannot see shadow SaaS and third-party integrations?
A: Access reviews lose their value because they only cover what is visible. Hidden tenants, unmanaged apps, and missed OAuth connections create a blind spot where data can move through approved-looking channels without effective oversight. In that situation, the organisation is certifying a partial picture, not the real access estate.
Q: Why do shadow applications increase breach risk even when SSO is in place?
A: Because SSO only covers the systems it reaches. Shadow applications often keep separate credentials and weaker recovery paths, so they become alternate entry points and lateral movement pivots. A strong IdP does not help if attackers can move around it through unmanaged applications that still trust local identity material.
Q: What do IAM teams get wrong about SSO coverage?
A: Teams often mistake central login for complete control coverage. In reality, SSO does not automatically govern local application accounts, service identities, or privilege assigned outside the identity provider. The most common mistake is assuming one authentication path means one governance model, when the two are not the same.
Q: Who should be accountable when an employee buys an unsanctioned SaaS app?
A: Accountability should be shared, but security needs a defined control owner. Procurement should stop unauthorised spend, IAM should track the identities and integrations created, and legal or risk teams should review vendor exposure. Without a named owner, offboarding and recertification usually fail.
Technical breakdown
Why shadow SaaS breaks identity hygiene
Shadow SaaS is software adopted outside formal IT approval, but the identity problem is broader than app sprawl. Every unsanctioned application creates its own authentication surface, data boundary, and account lifecycle, often disconnected from central IAM policy. When corporate email is enough to create an account, the enterprise loses a reliable inventory of where identities exist, where data is copied, and which authentication flows are in play. That undermines recertification, offboarding, and policy enforcement because the system being governed is partly invisible.
Practical implication: treat unsanctioned SaaS discovery as an IAM control requirement, not just a security operations task.
Why traditional SSO does not close the control gap
Single sign-on reduces password sprawl, but it does not automatically solve SaaS governance. Traditional SSO still depends on token handling, protocol trust, and application coverage, which means a breach of the identity provider or token relay can expose multiple connected services at once. It also leaves gaps where not every application is integrated, forcing users back into local accounts and passwords. Identity hygiene fails when SSO is treated as the control endpoint rather than one layer in a broader access governance model.
Practical implication: map where SSO coverage ends, then govern the remaining direct-authentication paths as separate risk domains.
Approval workflows are the control layer visibility needs
Visibility without control only produces inventory. Approval workflows create the decision layer that determines whether a new SaaS application can be connected to the enterprise identity plane, used with corporate data, or left outside policy. In identity governance terms, this is where discovery becomes enforcement: the organisation decides which apps are admissible, which need compensating controls, and which should be blocked entirely. That decision point matters because cloud adoption often begins with convenience, not risk assessment.
Practical implication: route shadow SaaS discovery into a formal approval and exception process with clear ownership.
Threat narrative
Attacker objective: The attacker objective is to exploit unmanaged SaaS accounts and authentication blind spots to reach data that enterprise controls do not cover.
- Entry occurs when an employee uses corporate email to create an account in an unsanctioned SaaS application without IT review.
- Escalation follows when data, credentials, or collaboration artefacts accumulate in applications that central IAM cannot fully see or govern.
- Impact arrives as sensitive organisational data spreads across unknown services, increasing breach exposure and weakening account lifecycle control.
Breaches seen in the wild
- Azure Key Vault privilege escalation exposure — Azure Key Vault Contributor role misconfiguration enabled privilege escalation.
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity hygiene fails first at discovery, not at enforcement: If an organisation cannot identify shadow SaaS, every downstream control becomes partial by definition. The article is right to frame visibility as the foundation because IAM governance only works on assets that are known, mapped, and reviewable. Practitioners should treat discovery coverage as the first measure of control integrity.
SSO coverage is not the same as SaaS governance: The article correctly separates authentication convenience from security completeness. SSO can centralise login without centralising application lifecycle, token handling, or data placement, which leaves identity sprawl intact in a cleaner-looking form. Teams should re-evaluate any programme that equates federation with full control.
Approval workflows are where policy becomes executable: Shadow SaaS becomes a governance issue only when organisations decide which applications can join the identity plane and under what conditions. That makes approval workflow design, exception handling, and app risk classification the operational core of identity hygiene. The practical conclusion is that governance must precede convenience.
Modern identity programmes need visibility across human and machine boundaries: The same blindness that allows shadow SaaS to proliferate also affects service accounts, API keys, and other non-human identities when they are not inventoried or reviewed. The broader lesson is that identity hygiene is not just about users logging in safely, but about every identity type being discoverable, governed, and offboarded on time. Practitioners should align human IAM, NHI governance, and SaaS access oversight into one operating model.
From our research:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- From our research: 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs.
- That visibility gap is the same operating problem that shadow SaaS creates for human IAM, and it becomes harder to close when identity boundaries keep expanding.
What this signals
Identity hygiene is becoming a combined human and non-human governance problem. The same organisations that struggle to see shadow SaaS often also struggle to inventory service accounts, tokens, and other non-human identities. That means IAM, IGA, and NHI governance can no longer be run as separate disciplines if the goal is policy coverage rather than partial visibility.
Shadow SaaS discovery should be treated as an access governance signal. If a team cannot see where users are creating unsanctioned accounts, it also cannot reliably know where data, approvals, and authentication tokens are accumulating. The forward implication is that discovery, federation coverage, and app approval telemetry need to sit on the same reporting plane.
The operational shift is from managing login convenience to managing identity surface area. Teams that still measure success by SSO adoption alone will miss the places where local accounts, unmanaged applications, and manual exceptions continue to grow.
For practitioners
- Inventory unsanctioned SaaS creation paths Identify where employees can create accounts with corporate email, then map those services to data handling, authentication, and lifecycle ownership gaps.
- Measure SSO coverage by application class Separate applications with enforced federation from those still using local credentials so teams can see where identity controls stop.
- Place shadow SaaS into approval workflows Route newly discovered apps through a formal review that checks business need, data access, and identity integration before use is tolerated.
- Review token and credential exposure in SaaS sprawl Assess where auth tokens, passwords, and API credentials are stored or reused across unapproved applications and collaboration tools.
Key takeaways
- Identity hygiene breaks when visibility is incomplete, because governance cannot be enforced across unknown applications and account paths.
- The article’s data point on shadow SaaS adoption shows that unmanaged application creation is already a mainstream control problem, not an edge case.
- Practitioners should connect SaaS discovery, approval workflows, and federation coverage into one identity governance model before sprawl outpaces policy.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Application access management fits the article's SaaS approval and control emphasis. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management is central where employees create unsanctioned SaaS accounts. |
| NIST Zero Trust (SP 800-207) | The article argues for tighter verification across cloud-first access paths. |
Map SaaS approvals and exceptions to PR.AC-4 and close the gap between discovery and enforced access policy.
Key terms
- Identity hygiene: Identity hygiene is the practice of discovering, normalizing, and enriching identity records so governance can rely on them. It reduces ambiguity across directories, platforms, and operational systems, and it makes access review and remediation possible at enterprise scale.
- Shadow SaaS: Shadow SaaS is the set of unauthorised or unreviewed software-as-a-service tools used outside central security governance. These applications often bypass normal identity controls, making them difficult to inventory, monitor, and harden against credential-based abuse.
- Sso coverage: SSO coverage measures how much of an organisation’s application estate authenticates through central single sign-on. Low coverage usually means fragmented access paths, weaker policy enforcement, and harder offboarding, which makes it a useful signal for governance maturity.
- Approval Workflow: An approval workflow is the governed sequence that determines whether a request becomes active access. It usually combines routing, policy checks, and evidence capture. For identity teams, the important question is not how fast it runs, but whether each decision remains attributable and reviewable.
What's in the full article
Unixi's full article covers the operational detail this post intentionally leaves for the source:
- How the session framed identity hygiene as a practical IAM resilience issue in a cloud-first environment.
- The article's examples of shadow SaaS adoption, unmanaged accounts, and data spreading into unknown applications.
- The distinction it draws between SSO convenience and the broader control problem of application governance.
- The concluding rationale for modern SSO coverage and stricter SaaS approval processes.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
Published by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org