By NHI Mgmt Group Editorial TeamBased on Josys: “Josys AI Integration Builder: Closing the Identity Governance Gap” (December 1, 2025)

TL;DR: SaaS discovery without connection to the underlying application leaves access, least privilege, and lifecycle actions trapped in spreadsheets and manual review loops, according to Josys. The governance gap is not visibility alone but the inability to enforce policy where permissions actually live, which makes review, offboarding, and exception handling drift out of control.


At a glance

What this is: This article argues that discovering SaaS apps without connecting them for control leaves identity governance incomplete, because access decisions, reviews, and offboarding still happen outside the governed plane.

Why it matters: IAM and IGA teams need more than inventory, because unmanaged SaaS access creates blind spots in least privilege enforcement, lifecycle execution, and audit-ready accountability across human and non-human programmes.


Context

SaaS discovery tells you what exists, but it does not by itself govern who can use it. In IGA terms, a discovered application that is not connected remains outside the control plane, so access reviews, least privilege enforcement, and lifecycle actions cannot be executed consistently.

That gap matters because the identity problem is not missing inventory, it is missing enforceable control at the point where permissions live. When teams rely on spreadsheets, app hopping, and manual reviews, they create a fragmented operating model that scales poorly across human users and any non-human processes tied to SaaS access.


Key questions

Q: What breaks when SaaS discovery stops at inventory and not access control?

A: What breaks is the assumption that knowing an app exists reduces risk. If users still authenticate with passwords, pasted vault secrets, or saved browser credentials, the exposure path remains open. Discovery without control only increases visibility into the problem, it does not stop AiTM phishing, infostealer theft, or session replay.

Q: Why do unmanaged SaaS apps create identity governance risk?

A: Unmanaged SaaS apps create risk because they sit outside central visibility, which means IT cannot consistently enforce SSO, review entitlements, or offboard access. The longer an app remains invisible, the more likely it is to accumulate stale permissions, duplicate functions, and unmanaged data exposure.

Q: How can teams tell whether SaaS governance is actually working?

A: Look for evidence that discovered applications can be assigned an owner, tied to an access policy, and removed through an enforced workflow. If the platform can only report on SaaS usage but cannot drive deprovisioning or entitlement review, governance is still fragmented.

Q: What is the difference between controlling SaaS applications and controlling SaaS access?

A: Controlling SaaS applications means trying to approve, block, or standardise the tools people use. Controlling SaaS access means managing identity, permissions, and authentication around those tools. In modern workplaces, access control is the stronger lever because employees will still adopt the apps they need. Security gains come from visibility and governance at the identity layer.


Technical breakdown

Why SaaS discovery alone does not close the control gap

SaaS discovery provides visibility into application existence, but IGA requires a control relationship to the application itself. If the identity platform cannot connect to the app, it cannot enumerate permissions, enforce policy, or trigger lifecycle actions where access is actually granted. That creates a structural split between what the security team knows and what it can govern. The result is a visibility layer with no enforcement layer behind it, which is why discovery without connection becomes operationally misleading.

Practical implication: treat discovery as inventory, not governance, until the application is connected to the access control workflow.

How manual access reviews drift when permissions stay in apps

When permissions remain inside individual SaaS applications, reviewers are forced to assemble access evidence from app hopping, spreadsheets, and exported reports. That process creates timing gaps, stale evidence, and inconsistent interpretation of what counts as privileged or excessive access. In practice, the review becomes a documentation exercise rather than a governance action. Least privilege suffers because policy cannot be applied uniformly across systems that are not under the same control plane.

Practical implication: eliminate spreadsheet-based review loops for apps that contain sensitive access decisions.

Why lifecycle management breaks without application connectivity

Onboarding and offboarding depend on timely actions, and those actions fail when the identity system cannot reach the application. A disconnected SaaS app leaves permissions lingering after role changes or departure events, which turns lifecycle management into a manual chase across admin panels. That delay is not just inefficient; it widens the window for unused licenses, excess access, and audit exceptions. The governance issue is persistence of access after the business reason has changed.

Practical implication: require application connectivity before declaring onboarding, offboarding, or access removal processes complete.


Threat narrative

Attacker objective: The practical attacker benefit is prolonged access exposure inside applications that the governance system can see but not control.

  1. Entry occurs when a SaaS application is discovered but remains outside the connected access control plane, leaving permissions managed inside the app itself.
  2. Escalation happens through manual review loops and spreadsheet-driven administration, which can preserve excessive access and delay offboarding decisions.
  3. Impact is the accumulation of lingering access, unused licenses, and governance blind spots that weaken least privilege and auditability.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Discovery without control is not governance: A SaaS app that is visible but not connected still sits outside the identity control plane. That means the organisation has inventory, not enforceable governance, and the gap persists even when visibility appears complete. Practitioners should treat disconnected discovery as an unresolved control exception, not as partial coverage.

Spreadsheet governance creates policy drift: Once app access depends on exports, manual reviews, and app hopping, least privilege becomes inconsistently interpreted across the SaaS estate. This is not a tooling nuisance, it is a governance model that cannot scale because the enforcement point is missing. The practical conclusion is that auditability collapses when evidence and action live in different systems.

Lifecycle actions fail when applications are unreachable: Joiner-mover-leaver processes assume the governance system can actually execute changes inside the target app. When that connection is absent, offboarding and access removal become best-effort tasks, not governed outcomes. The implication is that lifecycle completeness must be measured by execution success, not by discovery coverage alone.

SaaS control coverage is the new identity boundary: The meaningful boundary is no longer whether the app is known, but whether access can be governed at the point of permission. That shifts programme design toward connected control, reusable integration coverage, and exception tracking for any app that cannot yet be managed centrally. Practitioners should measure governance by reachable control surface, not by app count.

Disconnected SaaS creates identity governance debt: Every discovered application that remains outside centralized access control adds debt in review effort, offboarding lag, and policy inconsistency. Over time, that debt shows up as overprivilege, stale access, and audit friction that teams eventually pay down manually. The discipline should be to reduce unmanaged application surface before the review workload overwhelms the programme.

From our research library:

What this signals

Control coverage is the real governance metric: Once apps are discovered, the next question is not how many were found but how many can actually be governed. Programmes that stop at inventory accumulate identity governance debt because access enforcement, review, and offboarding remain manual.

Connected applications reduce review friction: The operational value of integration is not just automation, it is that the access review now targets real permissions instead of reconstructed evidence. That shift matters across human access, service access, and any other SaaS-backed identity workflow.

Identity governance programmes should measure reachable control surface, not app count: A discovered SaaS estate that cannot be acted on is a partial control domain. The practical test is whether lifecycle actions complete in the application, because only then does visibility become governable.


For practitioners

  • Map discovered SaaS apps to control coverage Classify each discovered application by whether access, permissions, and lifecycle actions can be executed centrally. Use that list to separate governed apps from visibility-only apps.
  • Retire spreadsheet-based access reviews Replace manual review trackers with application-connected review workflows so reviewers can validate actual permissions instead of stale exports.
  • Block lifecycle completion for disconnected apps Do not mark onboarding, offboarding, or privilege changes complete unless the target application has accepted the change and the action is logged.
  • Track least-privilege exceptions by application Create an exception register for applications that cannot yet enforce policy centrally, then prioritise them by privilege exposure and business criticality.

Key takeaways

  • SaaS discovery without application connectivity leaves identity governance stuck at visibility, while permissions and lifecycle actions remain outside enforceable control.
  • Manual review loops and spreadsheet tracking create drift, stale evidence, and inconsistent least privilege across the SaaS estate.
  • The practical fix is to measure governance by connected control surface, not by the number of apps discovered.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIDisconnected SaaS access can preserve excessive permissions that never get enforced or reduced.
NHI-01 — Improper OffboardingOffboarding fails when the identity platform cannot reach the app where access persists.
Recommendation — Map disconnected SaaS access to NHI-05 and remove excess permissions at the application control point. Apply NHI-01 to every SaaS app that can outlive joiner-mover-leaver workflows.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about governing entitlements across SaaS applications.
Recommendation — Use PR.AA-05 to verify that permissions are governed where they are actually granted.
CIS Controls v8CIS-5 — Account ManagementManual SaaS reviews and delayed offboarding are account management failures.
Recommendation — Use CIS-5 to centralise account lifecycle handling across connected SaaS applications.

Key terms

  • SaaS Discovery: SaaS discovery is the process of identifying all sanctioned and unsanctioned software-as-a-service applications in use across the organisation. It matters because cloud assurance increasingly depends on seeing where apps share data, what permissions they hold, and which identities can reach them.
  • Access Control Plane: The layer that coordinates identity, policy, approvals, enforcement, and logging across multiple systems. It matters because modern access decisions are rarely made in one place, and fragmentation across tools can turn governance into disconnected evidence.
  • Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
  • Lifecycle Management: Lifecycle management is the process of creating, reviewing, rotating, and retiring identities and their secrets in a controlled way. For NHIs, it is essential because stale credentials, orphaned accounts, and incomplete offboarding are common paths to long-lived exposure and unauthorised access.

Deepen your knowledge

NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or IGA programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org