TL;DR: Identity compromise now underpins 83% of cloud intrusions, and SailPoint argues that directory-bound governance leaves blind spots across non-native apps, legacy systems, and non-human identities. The real issue is not authentication alone but the collapse of enterprise-wide entitlement visibility once access moves beyond the primary directory perimeter.
Editorial analysis by NHI Mgmt Group, based on content published by SailPoint: “Exposing enterprise identity blind spots”.
By the numbers:
- Identity compromise now underpins 83% of all cloud intrusions.
Key questions
Q: What breaks when a primary identity directory cannot see downstream entitlements?
A: Least privilege becomes partial because the directory can confirm login without governing what the user can do inside non-native applications, legacy systems, or cloud infrastructure.
Q: Why do segregation of duties controls break down in hybrid and multi-application environments?
A: They break down because access governance is often built around one system at a time, while real users and service identities operate across several platforms.
Q: How should organisations govern non-human identities across their environment?
A: Start by inventorying every machine identity, assigning a human owner, and tying each one to a business purpose.
Practitioner guidance
- Define the governance perimeter Map where your primary directory stops governing entitlements, then document every application, database, and infrastructure domain outside that reach.
- Correlate accounts across systems Build a unified identity profile that joins multiple accounts to one person so SoD conflicts and orphaned access do not hide in separate platforms.
- Automate non-human lifecycle controls Inventory service accounts, APIs, and AI agent identities, then require ownership, entitlement review, and offboarding coverage for each.
Bottom line: Hybrid identity estates fail when directory control is mistaken for full governance across downstream systems.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Directory-bound governance is an incomplete control model for hybrid identity estates. A primary directory can enforce authentication and some native lifecycle actions, but it cannot by itself govern entitlements it cannot see. That makes the functional perimeter the real boundary of control, not the organisational boundary of risk. Practitioners need to treat coverage gaps as governance failures, not as an integration inconvenience.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: When does manual access attestation become a weak control for hybrid identity estates?
A: It becomes weak when teams have to stitch together spreadsheets and delayed logs to prove who had access across multiple systems. At that point, the evidence trail is stale, incomplete, and hard to defend, so access certification no longer reflects current entitlement reality.
👉 Read our full editorial: Identity blind spots in hybrid environments expose governance gaps