TL;DR: Enterprises still leave most applications outside IGA coverage, while manual integration work drives high implementation costs and slow onboarding, according to Opnova. AI-native automation may reduce operational friction, but identity governance still depends on auditable approval, scope control, and lifecycle oversight.
NHIMG editorial — based on content published by Opnova: Blog Opnova Sweeps Black Hat Startup Spotlight Competition
By the numbers:
- For every dollar spent on IGA software, enterprises spend another five on global systems integrators for implementation, totaling $8-15 million per year on average.
- It cuts inference costs by 85% and drives gross margin above 75%.
- Opnova was selected from more than 100 early-stage companies as one of four finalists at the event held during Black Hat USA on August 4, 2026.
Questions worth separating out
Q: How should security teams handle disconnected applications that sit outside identity tooling?
A: Treat disconnected applications as part of the identity perimeter, not as exceptions to ignore.
Q: Why do disconnected applications create identity governance risk?
A: They create risk because the organisation cannot reliably see, certify, or revoke access through the same control plane used for integrated systems.
Q: What should IAM teams measure in AI-assisted support workflows?
A: Measure who can see case data, how often those permissions are used, and whether AI outputs are traceable back to source logs.
Practitioner guidance
- Define the disconnected application inventory Catalogue which applications sit outside out-of-the-box IGA coverage, then classify them by business criticality, privilege level, and ownership so remediation work targets the highest-risk gaps first.
- Separate automation eligibility from approval authority Set explicit policy for which identity operations can be executed by computer-use automation, which require human approval, and which must remain manual because the audit trail is not strong enough.
- Require evidence-rich workflow replay Insist on step-level replay records, approval timestamps, and exception artifacts for every automated identity change so operational convenience does not erase control evidence.
What's in the full article
Opnova's full post covers the operational detail this analysis intentionally leaves for the source:
- The Black Hat Startup Spotlight context and event positioning behind the announcement.
- Descriptions of the video learning, reflexive memory, and OPN-1 components used in the platform.
- The specific claim about enterprise application coverage and onboarding timelines cited by Opnova.
- The company background and deployment framing around bring-your-own-cloud and privileged access coverage.
👉 Read Opnova's analysis of AI-native identity governance for disconnected applications →
Disconnected applications and IGA coverage gaps: are controls keeping up?
Explore further
Application coverage is now an identity governance problem, not just an integration problem. When only a fraction of enterprise applications connect to IGA out of the box, the gap is not merely technical debt. It becomes a governance gap because access, change, and removal decisions happen outside the normal control plane. Practitioners should treat uncoupled applications as residual identity risk until they are brought under a reviewable operating model.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
A question worth separating out:
Q: Who should approve computer-use automation for privileged identity tasks?
A: Approval should sit with the team that owns the identity control, not only the team that built the automation. Privileged actions need clear accountability, reviewable evidence, and a revocation path if the workflow or application changes.
👉 Read our full editorial: AI-native identity governance exposes the application coverage gap