By NHI Mgmt Group Editorial TeamDomain: Best PracticesSource: SecureAuthPublished December 22, 2025

TL;DR: Enterprises now average more than 200 SaaS applications, with 45% classified as shadow IT, and that sprawl fragments identities, hides access, and leaves orphaned accounts behind, according to SecureAuth. The governance problem is no longer authentication alone; it is the inability to maintain a single control plane across disconnected applications.


At a glance

What this is: This is an analysis of how SaaS proliferation creates identity silos, visibility gaps, and orphaned access across enterprise applications.

Why it matters: It matters because IAM, IGA, PAM, and security teams need a unified way to provision, deprovision, and review access across a rapidly expanding application estate.

By the numbers:

👉 Read SecureAuth's analysis of SaaS identity sprawl and IAM control gaps


Context

SaaS sprawl creates a basic identity governance problem: the more applications an enterprise adds, the harder it becomes to know which identities exist, where they live, and who can still use them. In a fragmented estate, provisioning and offboarding are rarely consistent, so access decisions drift away from the control model IAM teams think they operate.

The primary issue is not just scale. It is the combination of identity silos, shadow IT, and disconnected lifecycle controls that makes access reviews incomplete and deprovisioning unreliable. For most organisations, the gap between policy and actual application access is now wide enough to create persistent risk.


Key questions

Q: How should security teams govern access across SaaS sprawl?

A: Security teams should govern SaaS sprawl with one inventory, one policy model, and one review process that covers both human and non-human access. The practical goal is to connect application approval, entitlement review, and revocation to business ownership. Without that linkage, access governance becomes a manual cleanup exercise instead of a control system.

Q: Why do SaaS identity silos create orphaned accounts and access drift?

A: SaaS identity silos create orphaned accounts because lifecycle events stop at the boundary of each application. If a system is not tied into SCIM, review workflows, or offboarding processes, accounts can remain active long after the user has left or changed role. That is how access drift becomes persistent instead of temporary.

Q: Why does SaaS adoption create IAM and data governance risk?

A: SaaS adoption creates risk because access, data placement, and accountability are distributed across multiple parties. The organisation still owns the data and the identity decisions around it, even when a vendor hosts the service. That makes IAM, legal review, and procurement part of the same control plane, not separate functions.

Q: Should organisations prioritize SCIM, CASB discovery, or access reviews first?

A: If the estate is fragmented, start with discovery so you know which applications exist, then prioritize SCIM for the systems that hold the most sensitive or persistent access. Access reviews should run after the major gaps are visible, otherwise you only certify bad data. Sequencing matters more than tool count.


Technical breakdown

Why SaaS identity silos break centralized IAM

Each SaaS application tends to become its own identity island unless it is connected to a common provisioning and authentication layer. When users have separate local accounts, IAM teams lose visibility into entitlement overlap, duplicate identities, and dormant access. SSO helps with login consistency, but it does not by itself solve lifecycle governance. SCIM is what turns identity changes in the source directory into downstream joiner, mover, and leaver events across applications. Without that linkage, access remains scattered across systems that security teams cannot reliably enumerate.

Practical implication: inventory every SaaS app that still maintains local identities and prioritize integration for provisioning and deprovisioning first.

How shadow IT turns into orphaned account risk

Shadow IT matters because application owners often buy SaaS tools outside standard IAM workflows, which means those tools may never be onboarded to the deprovisioning process. The result is orphaned accounts, stale permissions, and disconnected administrators who are outside normal governance reviews. CASB discovery can expose some of this hidden estate, but discovery alone does not fix lifecycle control. The real issue is whether the enterprise can bring unmanaged applications into a policy-bound identity process before access persists past the business need.

Practical implication: use discovery to find unsanctioned SaaS first, then enforce a governance path that brings each app under lifecycle control.

Why access reviews fail when the control plane is fragmented

Access reviews depend on accurate entitlement data, complete application coverage, and a consistent model for who owns each account. In a SaaS-heavy environment, those assumptions break quickly because some apps are federated, some are locally managed, and some are invisible to the central IAM stack. That makes recertification noisy and often incomplete. A universal identity layer does not mean one product for everything; it means one governance model that spans the whole application estate, including external applications and delegated administration paths.

Practical implication: require every connected SaaS app to feed entitlement data into the same review workflow, even when the app is managed by a different team.


NHI Mgmt Group analysis

SaaS sprawl creates an identity control problem before it becomes an authentication problem. The article is really about governance loss across many application boundaries, not about login friction. Once identities are distributed across dozens or hundreds of SaaS systems, the enterprise no longer has a single source of truth for access, lifecycle, or accountability. That is why the first failure is visibility, not credentials.

Identity silos turn joiner, mover, and leaver processes into partial controls. A user can be provisioned in one system, remain active in another, and never appear in a central review queue. That means the enterprise may believe it has lifecycle governance while still carrying dormant access in forgotten applications. The practical conclusion is that lifecycle control must be measured at the application layer, not assumed from the directory.

Shadow IT is not just an asset discovery issue, it is a governance boundary problem. When applications are bought and managed outside the identity team, the control plane stops at the edge of the sanctioned stack. That creates a named gap: the universal identity layer becomes incomplete wherever unsanctioned SaaS bypasses provisioning and review. Practitioners should treat unsanctioned application onboarding as an identity governance requirement, not a separate IT cleanup task.

The real risk is identity sprawl with inconsistent enforcement. The article’s figures point to a market condition where SaaS scale grows faster than governance maturity. That makes automated enforcement, cross-application provisioning, and revocation workflows the difference between manageable complexity and permanent entitlement drift. The discipline now is less about adding more identity tools and more about collapsing silos into one governable control model.

From our research:

  • The average enterprise now uses 144 non-human identities for every human identity, according to The NHI and Secrets Risk Report.
  • A separate finding in the same report shows that nearly half of exposed secrets reside outside code repositories, which is where many SaaS-driven identity workflows now leak.
  • For practitioners, the next step is to pair application discovery with lifecycle control, using Ultimate Guide to NHIs , Key Challenges and Risks as the governance baseline.

What this signals

SaaS sprawl is now an identity governance problem, not merely an application management problem. When enterprises cross the threshold into hundreds of applications, the central question becomes whether the identity programme can still prove who has access, where it came from, and how it will be removed. The control model has to follow the application estate, not the other way around.

Identity control-plane fragmentation: This is the point where directory-centric thinking stops being sufficient. Once shadow IT and delegated administration spread across the business, the enterprise needs a governed inventory, not just a login standard, and that inventory has to feed lifecycle controls.

With nearly half of exposed secrets now living outside repositories, per The NHI and Secrets Risk Report, identity governance has to extend into collaboration tools, logs, and SaaS admin paths where access often escapes review.


For practitioners

  • Map every SaaS application to an identity owner Build an authoritative inventory that includes sanctioned apps, shadow IT, and delegated admin paths so every system has a named governance owner and a review path.
  • Centralize provisioning with SCIM and federation Use SCIM for lifecycle changes and SSO for authentication consistency, but require both to be tied to the same source of truth so account creation and removal stay aligned.
  • Bring shadow IT into discovery and control Use CASB discovery to identify unsanctioned applications, then decide whether each one is blocked, onboarded, or folded into the standard lifecycle process.
  • Automate recertification across all connected systems Run access reviews against the full application estate, including external SaaS, and remove any entitlement that cannot be traced to a business owner or current use case.

Key takeaways

  • SaaS proliferation turns IAM into a visibility and lifecycle problem long before it becomes a login problem.
  • Shadow IT and fragmented provisioning create orphaned access that standard directory controls cannot reliably remove.
  • Enterprises need a universal identity layer, but the real requirement is governed coverage across every connected application.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Identity permissions management fits fragmented SaaS access control.
NIST Zero Trust (SP 800-207)Zero Trust requires continuous verification across distributed SaaS identities.
NIST SP 800-53 Rev 5AC-2Account management governs provisioning, deprovisioning, and dormant account removal.
OWASP Non-Human Identity Top 10NHI-03Credential and lifecycle drift are central non-human identity risks in SaaS estates.

Treat unmanaged SaaS accounts and stale access as NHI-03 governance gaps requiring inventory and control.


Key terms

  • Identity Silos: Identity silos are isolated identity systems that manage access independently and do not share policy or lifecycle signals cleanly. They create fragmented governance, duplicate administration, and inconsistent audit outcomes, especially in hybrid and multi-cloud environments.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • Orphaned Account: An orphaned account is an identity that remains active without a clear owner or business purpose. These accounts are dangerous because they often escape review, retain unnecessary access, and provide attackers with low-friction entry points into otherwise governed environments.
  • SCIM Provisioning: SCIM provisioning is a standardized way to sync identity information between systems. It helps automate account creation, updates, and removal across connected applications. Its main value is interoperability, but it still depends on accurate upstream data and governance over what access should actually be issued.

What's in the full article

SecureAuth's full analysis covers the operational detail this post intentionally leaves for the source:

  • How SecureAuth recommends centralizing provisioning and deprovisioning across mixed SaaS estates
  • Which discovery approaches it highlights for finding shadow IT and unmanaged applications
  • The specific role it assigns to SSO, SCIM, CASB, and identity governance policies in the control stack
  • How its platform positioning maps to workforce and partner identity use cases

👉 The full SecureAuth post covers the SaaS sprawl model, recommended controls, and platform context.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org