TL;DR: Many organisations treat SailPoint as the system of record for access governance while critical applications, administrative paths, lifecycle events, and audit evidence still sit outside governed workflows, leaving teams dependent on spreadsheets, screenshots, and local reconciliations for SOX and regulatory assurance, according to SafePaaS. That split model means governance is only real where coverage, evidence, and process integrity extend beyond the platform.
At a glance
What this is: This scorecard is a SailPoint governance coverage assessment that exposes where access review, lifecycle, and audit evidence still rely on manual workarounds.
Why it matters: It matters because IAM teams often overestimate governance maturity when certifications run, while auditors still encounter blind spots across applications, evidence chains, and offboarding paths.
By the numbers:
- 91% of former employee tokens remain active after offboarding, leaving organisations vulnerable to potential security breaches.
👉 Read SafePaaS's SailPoint governance coverage scorecard
Context
A governance scorecard is only useful if it exposes where access control, evidence, and lifecycle processes stop being trustworthy. In many IAM programmes, the platform is present but the governed model is incomplete, especially when critical systems, administrative access, and local approval paths remain outside the certification workflow.
For SailPoint-centered programmes, the real issue is not whether reviews run. It is whether the organisation can prove that high-risk access, joiner-mover-leaver changes, and audit evidence are governed consistently across every relevant application and access path. That is the difference between a deployed tool and a defensible governance model.
This pattern is familiar across mature IAM, IGA, and PAM programmes: control exists in one layer, but the audit story breaks in another. The scorecard is useful because it forces teams to measure coverage, evidence quality, process integrity, and business adoption together rather than assuming a single platform closes the loop.
Key questions
Q: How should IAM teams identify where SailPoint governance stops and manual control starts?
A: Start by mapping every critical application, administrative path, and lifecycle change against the governed workflow. If approvals, evidence, or entitlement updates happen outside the platform, that is not a minor exception. It is a control boundary that should be documented, owned, and either integrated or retired.
Q: Why do access certifications still feel weak even when reviews are completed on time?
A: Because timeliness does not equal decision quality. Certifications become weak when reviewers see broad role names instead of the entitlements, privilege depth, and business context needed to judge risk. A completed review can still miss excessive access if the evidence presented to approvers is too abstract.
Q: What breaks when security teams rely on screenshots and spreadsheets as audit evidence?
A: Point in time evidence goes stale the moment it is captured. Screenshots and spreadsheets may show a control existed on a specific date, but they cannot prove it still works after configuration changes, exception creep, or scope expansion. The result is a documentation gap that can hide enforcement failures and weaken audit readiness.
Q: Who is accountable when access governance relies on parallel local processes?
A: Accountability shifts to the business and application owners that created the exception, not the central IAM team alone. If a critical system is handled outside the governed workflow, the organisation must assign ownership for the gap, define the evidence it should produce, and track closure through audit.
Technical breakdown
Application coverage gaps in identity governance
A governance platform can only centralise what it can see and control. When critical applications are provisioned through service desks, admin consoles, local scripts, or direct changes, the identity record splits from the operational reality. That creates governed scope on paper but not in practice. The key technical issue is not integration count alone. It is whether the authoritative access model includes finance, HR, regional, legacy, acquired, and business-owned applications, plus the administrative channels that bypass formal request flows.
Practical implication: inventory every high-risk access path that does not resolve back into governed workflows and assign ownership before the next access review cycle.
Why certification quality depends on entitlement context
Access certification fails when reviewers see role labels instead of the entitlements and privileges that create actual risk. A meaningful review needs business context, such as legal entity, location, function, data sensitivity, and privilege depth. Without that context, reviewers approve at a surface level and the certification becomes a formality. The technical problem is not reviewer diligence alone. It is that the evidence model hides what is being approved, so the control cannot distinguish harmless access from technically risky access.
Practical implication: redesign certifications so approvers see the underlying entitlements, privilege level, and business context for every decision.
Audit evidence breaks when controls are distributed across systems
Audit evidence is strongest when request, approval, SoD evaluation, provisioning outcome, remediation, and sign-off remain traceable in one governed chain. In fragmented environments, that chain is broken across SailPoint, ticketing, spreadsheets, screenshots, and application logs. Auditors then need reconciliation rather than evidence. The technical failure is not the absence of data. It is the absence of a consistent, machine-traceable evidence model that can survive cross-system review without manual explanation.
Practical implication: map every audit assertion to a verifiable evidence source and remove any control that still depends on screenshots or offline files.
Threat narrative
Attacker objective: The objective is to exploit governance blind spots so access persists without reliable review, making abuse harder to detect and compliance harder to defend.
- Entry occurs when critical identities, approvals, or access changes are handled outside governed workflows and never become visible to the central governance record.
- Escalation follows when local workarounds, spreadsheets, and disconnected evidence allow excessive or stale access to persist without timely review or removal.
- Impact is audit exposure, inconsistent compliance evidence, and increased access risk because the organisation cannot prove who approved what, when, or why.
Breaches seen in the wild
- Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
- Sisense breach — unauthorized GitLab access led to exfiltration of access tokens, API keys and certificates.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Centralised IAM tooling does not equal centralised governance. A platform may be the system of record for some certifications, yet still leave critical applications, administrative channels, and evidence paths outside controlled scope. That means the governance model is split even when the tool appears embedded. The practical conclusion is that programme maturity should be measured by governed coverage, not by platform deployment alone.
Audit readiness collapses when evidence is fragmented across systems. Screenshots, spreadsheets, and local reconciliations are not just inefficient. They indicate that the evidence model has not been designed as a control in its own right. When auditors need manual translation between identity, approval, provisioning, and remediation data, the organisation has not achieved a reliable audit posture.
Access certification quality depends on whether reviewers can see the privilege that matters. High-level role names create false confidence because they hide the entitlements, locations, and data access conditions that drive risk. The result is compliant-looking governance with weak decision quality. Practitioners should treat entitlement context as part of the control, not as an optional enhancement.
Process integrity is the real test of SailPoint-centred governance. If joiner, mover, leaver, SoD, and privileged access handling still diverge by system, the programme has local exceptions masquerading as enterprise governance. That creates governance drift, where policy appears consistent but operational treatment is not. The implication is that lifecycle discipline must be measured across all access paths, not just the ones inside the platform.
Coverage gap is the right named concept for this topic: the distance between what the identity programme can certify and what the business actually uses. That gap matters because compliance failures often occur in the unmanaged middle, where access exists but evidence does not. Teams that cannot name their coverage gap cannot close it with precision.
From our research:
- 91% of former employee tokens remain active after offboarding, according to the 2025 State of NHIs and Secrets in Cybersecurity.
- 62% of all secrets are duplicated and stored in multiple locations, according to the 2025 State of NHIs and Secrets in Cybersecurity.
- For lifecycle governance depth, see NHI Lifecycle Management Guide for the operational patterns that determine whether access is truly revoked.
What this signals
Coverage gap: the gap between governed identity workflows and the access paths the business actually uses will remain the most common reason that audit preparation still feels manual. When platforms centralise review but not the surrounding evidence chain, teams inherit compliance friction even though they believe governance is already in place. Ultimate Guide to NHIs , Regulatory and Audit Perspectives helps frame why evidence quality matters as much as access control.
The programme signal here is straightforward: identity teams should stop measuring success by certification completion alone and start measuring how many critical access decisions still require spreadsheets, email approvals, or local extracts. That is where governance confidence is lost, and where the audit conversation usually begins.
The fastest maturity gain comes from treating access evidence as a governed asset. If the chain cannot be reconstructed without manual reconciliation, the control is not yet operationally trustworthy, regardless of how well the platform is configured.
For practitioners
- Map governed scope against actual access paths Compare certified applications, admin channels, service desk routes, and direct changes against the true high-risk application set. Name every system that is still outside governed scope and assign a remediation owner, risk rating, and target date.
- Rebuild certification views around entitlements Expose underlying privileges, not just roles, so reviewers can judge business and financial risk. Include business unit, entity, location, function, and data sensitivity in the review screen so approvals are informed rather than mechanical.
- Replace screenshot-based audit support with traceable evidence chains Link request, approval, SoD result, provisioning action, remediation, and final sign-off into one auditable trail. If any control still depends on screenshots or offline files, treat it as an evidence gap rather than a process preference.
- Test lifecycle integrity across non-SailPoint paths Verify that transfers, terminations, and privileged changes are removed or updated even where access is managed through local tools or manual processes. Use exceptions to identify where governance has drifted away from the identity record.
Key takeaways
- SailPoint coverage can look complete while critical applications, admin channels, and lifecycle events still sit outside governed scope.
- Audit confidence depends on traceable evidence chains and entitlement-level certification decisions, not on review completion alone.
- Teams should measure governance by real access paths and evidence quality, then close the gaps that still force manual reconciliation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | The article centers on governance gaps, stale access, and unmanaged lifecycle paths. |
| NIST CSF 2.0 | PR.AC-4 | Access permissions and lifecycle control are central to the scorecard. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management and lifecycle governance underpin the scorecard's JML concerns. |
Map non-SailPoint access paths to NHI-03 and close the coverage gaps that weaken certification and audit evidence.
Key terms
- Coverage Gap: A coverage gap is the space between what an access control programme claims to manage and what it actually governs in production. In PAM, this often appears when new resource types, teams, or protocols require exceptions, manual handling, or separate tooling, leaving important privileged pathways outside policy consistency.
- Certification Quality: The degree to which access reviewers can make informed, risk-aware decisions using meaningful entitlement data and business context. Good certification quality means the review is about actual privilege and exposure, not just nominal role names or checkbox approval.
- Audit Evidence: Audit evidence is the record set used to prove that access was authorised, limited, and revoked according to policy. For modern identity programmes, evidence must come from runtime logs, approval events, and lifecycle records rather than from manual spreadsheets assembled after the fact.
- Processing Integrity: Processing Integrity is an optional SOC 2 Trust Services Criterion that asks whether systems process data completely, accurately, timely, and with proper authorization. It matters most where incorrect output creates business risk, such as billing, payments, or regulated workflows. Evidence often includes input validation, reconciliation, error handling, and audit logs.
What's in the full article
SafePaaS's full article covers the scoring detail this post intentionally leaves for the source:
- The section-by-section scoring rubric for application coverage, certification quality, audit evidence, process integrity, and business adoption.
- The normalised scoring formula for environments that legitimately need N/A scoring.
- The interpretation bands that turn a score into a practical governance readout for audit and compliance teams.
- The suggested next-step assessment areas for identifying which access paths, evidence gaps, and local workarounds need attention.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org