Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Flat file app coverage in IGA: what governance teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: Identity governance platforms often count manual CSV uploads as connected apps, but those flat files are stale, incomplete, and hard to audit, creating false coverage and retained access risk according to Cerby. The governance problem is not connector coverage alone, but whether access data can be verified continuously rather than borrowed from a point-in-time export.

NHIMG editorial — based on content published by Cerby: Flat file governance and the gap between connected apps and actual coverage

By the numbers:

Questions worth separating out

Q: What breaks when an IGA platform treats flat file uploads as connected apps?

A: The platform loses verification.

Q: Why do flat file feeds create more access risk than teams expect?

A: Because the risk is not just stale data, but stale decisions.

Q: How can security teams tell whether flat file governance is failing?

A: Look for apps where the platform reports coverage but the owner cannot prove current entitlement state without rebuilding evidence from tickets or emails.

Practitioner guidance

  • Separate verified connections from reported coverage Inventory every application that enters IGA through manual export, then tag it as flat-file governed rather than connected until a live connector is in place.
  • Prioritise high-risk apps for direct connectors Start with applications that hold privileged access, service accounts, or regulated data, because those are the feeds most likely to miss entitlements and trigger audit testing.
  • Shorten the evidence freshness window Set a maximum age for entitlement evidence and block certifications when the source export is older than that threshold.

What's in the full article

Cerby's full article covers the operational detail this post intentionally leaves for the source:

  • How Cerby structures direct connectors for apps that cannot be integrated by the IGA platform
  • The operational differences between live connectors, scheduled exports, and flat-file ingestion for governance reporting
  • Examples of the manual app inventory problem across SaaS, cloud, and on-prem systems
  • Why audit teams focus on the weakest file-based apps and how that changes remediation priority

👉 Read Cerby's analysis of why flat file apps break identity governance →

Flat file app coverage in IGA: what governance teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Flat file governance creates a verification gap, not just a connector gap. The industry often talks about missing integrations as if the only issue is coverage, but the deeper failure is that identity teams start governing copies instead of systems. Once the IGA platform accepts a CSV as connected, it inherits whatever the exporter omitted, and that omission becomes part of the governance record. The practical conclusion is that verification, not ingestion, is the real control objective.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when access evidence comes from a CSV instead of a live connector?

A: The governance owner remains accountable for the accuracy of the evidence, even if the data was exported by an app owner or operations team. In practice, the organisation should treat disconnected evidence as a compensating control with explicit risk acceptance, not as equivalent to system-collected proof.

👉 Read our full editorial: Flat file governance is breaking identity assurance in IGA



   
ReplyQuote
Share: