TL;DR: Identity governance platforms often count manual CSV uploads as connected apps, but those flat files are stale, incomplete, and hard to audit, creating false coverage and retained access risk according to Cerby. The governance problem is not connector coverage alone, but whether access data can be verified continuously rather than borrowed from a point-in-time export.
NHIMG editorial — based on content published by Cerby: Flat file governance and the gap between connected apps and actual coverage
By the numbers:
- A CISO running their IGA platform once told us every one of their 1,600 apps was connected.
- Teams report that 58% of former employees retained access to systems after leaving.
Questions worth separating out
Q: What breaks when an IGA platform treats flat file uploads as connected apps?
A: The platform loses verification.
Q: Why do flat file feeds create more access risk than teams expect?
A: Because the risk is not just stale data, but stale decisions.
Q: How can security teams tell whether flat file governance is failing?
A: Look for apps where the platform reports coverage but the owner cannot prove current entitlement state without rebuilding evidence from tickets or emails.
Practitioner guidance
- Separate verified connections from reported coverage Inventory every application that enters IGA through manual export, then tag it as flat-file governed rather than connected until a live connector is in place.
- Prioritise high-risk apps for direct connectors Start with applications that hold privileged access, service accounts, or regulated data, because those are the feeds most likely to miss entitlements and trigger audit testing.
- Shorten the evidence freshness window Set a maximum age for entitlement evidence and block certifications when the source export is older than that threshold.
What's in the full article
Cerby's full article covers the operational detail this post intentionally leaves for the source:
- How Cerby structures direct connectors for apps that cannot be integrated by the IGA platform
- The operational differences between live connectors, scheduled exports, and flat-file ingestion for governance reporting
- Examples of the manual app inventory problem across SaaS, cloud, and on-prem systems
- Why audit teams focus on the weakest file-based apps and how that changes remediation priority
👉 Read Cerby's analysis of why flat file apps break identity governance →
Flat file app coverage in IGA: what governance teams are missing?
Explore further
Flat file governance creates a verification gap, not just a connector gap. The industry often talks about missing integrations as if the only issue is coverage, but the deeper failure is that identity teams start governing copies instead of systems. Once the IGA platform accepts a CSV as connected, it inherits whatever the exporter omitted, and that omission becomes part of the governance record. The practical conclusion is that verification, not ingestion, is the real control objective.
A few things that frame the scale:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to The 2024 ESG Report: Managing Non-Human Identities.
A question worth separating out:
Q: Who is accountable when access evidence comes from a CSV instead of a live connector?
A: The governance owner remains accountable for the accuracy of the evidence, even if the data was exported by an app owner or operations team. In practice, the organisation should treat disconnected evidence as a compensating control with explicit risk acceptance, not as equivalent to system-collected proof.
👉 Read our full editorial: Flat file governance is breaking identity assurance in IGA