TL;DR: Credential sprawl is spreading across SaaS apps, AI tools, and unmanaged accounts outside SSO, leaving exposure in the gap between provisioning and privileged access, according to 1Password. SSO and PAM still leave a governability blind spot when teams create work email logins and reuse credentials outside IT control.
Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “Live Demo EMEA - The credential sprawl tour: Is your department leaking secrets?”.
Key questions
Q: What breaks when users create accounts outside SSO and IT provisioning?
A: The identity lifecycle breaks first, because the account exists before central governance sees it.
Q: When should teams prioritise credential governance over extending SSO coverage?
A: Prioritise credential governance whenever users are signing up for SaaS or AI tools with work emails outside approved provisioning flows.
Practitioner guidance
- Map off-SSO account creation paths Identify every place users can create SaaS or AI tool accounts with a work email outside the identity provider, then classify those flows as identity intake points that require governance and review.
- Separate privileged from everyday credential governance Treat PAM as one layer and not the whole programme by extending policy, discovery, and revocation coverage to departmental accounts, shared logins, and user-created tool credentials.
- Inventory AI tool accounts created by business users Look for accounts created in Lovable, ChatGPT, Claude, and similar tools through employee signups rather than IT provisioning, then fold them into access review and offboarding processes.
Bottom line: Credential sprawl creates security exposure in the spaces between SSO and PAM, where user-created accounts often escape normal governance.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Credential sprawl is an identity governance problem, not just an access hygiene issue. The article shows that exposure now accumulates in accounts created outside SSO and outside PAM, which means the governance model itself is incomplete. Security teams are no longer dealing only with bad passwords or weak authentication. They are dealing with a population of identities that never entered the normal control lifecycle, so the practitioner conclusion is to govern the creation path, not only the authentication event.
A question worth separating out:
Q: What should teams do about unmanaged SaaS and AI accounts created by employees?
A: They should bring those accounts into the same ownership, review, and offboarding model used for other identity assets. The aim is not to ban tool adoption, but to make sure every credential has a clear owner, a lifecycle, and a deprovisioning path.
👉 Read our full editorial: Credential sprawl is outpacing SSO and PAM controls in 2026