TL;DR: Disconnected legacy applications still block recertification and provisioning at scale, and Opnova says one bank cut 15,000 manual tickets while shrinking six-month connector work into hours. The real issue is not automation speed, but governance coverage across the long tail of applications that IGA tools cannot reach.
NHIMG editorial — based on content published by Opnova: Video Closing Identity Governance's Last Mile: Sinan Eren on Opnova's Black Hat Win
By the numbers:
- A bank can burn through three to five million dollars and still only cover 20 to 30 percent of its application footprint when disconnected apps require custom connector builds.
Questions worth separating out
Q: How should IAM teams govern applications that cannot expose modern APIs?
A: Treat those systems as explicit governance exceptions, not informal edge cases.
Q: Why do disconnected apps create so many audit problems?
A: Because auditors need proof that access was granted, reviewed, and revoked consistently, not just a statement that policy exists.
Q: What are the signs that identity governance is not working in practice?
A: Common warning signs are repeated access workarounds, ignored approval workflows, super admins holding too much power, and teams bypassing the process because it is too slow or hard to use.
Practitioner guidance
- Map disconnected applications by governance criticality Classify legacy systems by whether they block recertification, provisioning, offboarding, or all three.
- Separate learned workflow automation from control ownership Require a named control owner for every replayed workflow so exception handling, approval logic, and evidence retention remain explicit.
- Build a recertification path for non-API systems Create evidence-backed review and approval processes for systems that only expose flat files, terminals, or custom admin screens, and document how those reviews are validated.
What's in the full analysis
Opnova's full analysis covers the operational detail this post intentionally leaves for the source:
- The computer-use and imitation-learning workflow used to turn manual admin actions into repeatable procedures.
- The service desk and identity engineering workflow that reduces connector delivery from months to hours.
- The bank case study behind the 15,000-ticket reduction and the access process changes that made it possible.
- The practical framing for disconnected applications that security leaders can use in audit and budget conversations.
👉 Read Opnova's analysis of identity governance for disconnected applications →
Disconnected applications and IGA: what should teams do now?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Disconnected applications create a governance ceiling, not just an integration backlog. Identity programmes are often measured by policy coverage, but disconnected estates prove that policy is not the same as enforceable control. When recertification, provisioning, and offboarding cannot reach the application, the programme has hit its operational ceiling. That is why the last mile matters more than the platform message, and why auditors eventually find the gap first.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, according to The State of Non-Human Identity Security.
A question worth separating out:
Q: Should organisations automate legacy access workflows before modernising the platform?
A: Yes, if the automation is reviewable and tied to a control owner. The practical decision is not platform replacement versus automation, but whether the organisation can reduce manual work without losing evidence, accountability, or exception handling across disconnected systems.
👉 Read our full editorial: Identity governance’s last mile: what disconnected apps change