Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Identity consolidation and app coverage: what IAM teams need now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 2827
Topic starter  

TL;DR: Identity-focused M&A in late 2025, combined with faster identity automation and AI-driven discovery, is pushing comprehensive app coverage from a future goal to an operational expectation, according to Cerby and the executives it cites. The real test is no longer whether identity matters, but whether enterprises can govern the applications they already own before coverage gaps become technical debt.

NHIMG editorial — based on content published by Cerby: 2026 identity consolidation and the five trends shaping IAM programs

By the numbers:

Questions worth separating out

Q: How should security teams handle disconnected applications that sit outside identity tooling?

A: Treat disconnected applications as part of the identity perimeter, not as exceptions to ignore.

Q: Why do disconnected apps create persistent IAM risk?

A: Disconnected apps create persistent risk because they often bypass the controls that make identity programmes effective: onboarding, access review, change tracking, and deprovisioning.

Q: How do you know if identity coverage is actually improving?

A: Track the percentage of applications under governed access control, and separate that metric from total seat counts or login volumes.

Practitioner guidance

  • Measure identity coverage by application class Segment your application estate into governed, partially governed, and unmanaged groups, then weight the gap by business criticality.
  • Prioritise last-mile applications first Target marketing tools, social platforms, HR and finance portals, and on-premise systems that lack standard connectors.
  • Constrain AI to deterministic identity tasks Allow AI to assist with discovery, workflow generation, and anomaly detection, but keep permission grants and secret handling inside deterministic controls with explicit approvals.

What's in the full article

Cerby's full article covers the operational detail this post intentionally leaves for the source:

  • How Cerby defines the practical path to 100% app coverage across disconnected tools
  • The specific operational examples behind the monday.com coverage increase and what changed in six months
  • The budgeting and staffing model Cerby describes for treating identity as a dedicated function
  • How the article frames AI-assisted discovery without letting AI take over sensitive identity decisions

👉 Read Cerby’s analysis of 2026 identity consolidation and app coverage →

Identity consolidation and app coverage: what IAM teams need now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 weeks ago
Posts: 1125
 

Identity consolidation is becoming a market signal, not a governance solution. The current M&A wave shows that identity has moved into the centre of security architecture, but buying identity capabilities does not equal governing enterprise identity risk. Vendors can add pieces of the stack, yet disconnected applications, offboarding gaps, and policy drift still live in the customer environment. Practitioners should read consolidation as confirmation that identity matters, while continuing to own their own coverage model.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage.

A question worth separating out:

Q: Should organisations let AI handle permission changes in identity workflows?

A: Only if the workflow can tolerate deterministic output and strong guardrails. AI is useful for discovery and analysis, but direct permission changes and credential handling are high-risk actions because a small error can create a broad access problem. Keep those changes inside approval-based, predictable execution paths and use AI for support rather than authority.

👉 Read our full editorial: Identity consolidation is reshaping enterprise governance in 2026



   
ReplyQuote
Share: