TL;DR: Fragmented identities and scattered data access create blind spots across SaaS and cloud, making it hard to know who can reach sensitive information and whether MFA or least privilege is consistent, according to Cyera. That gap becomes more dangerous as AI tools inherit user access and can surface data faster than teams can govern it.
Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “Cyera and Okta: Eliminating Identity and Data Access Blind Spots in the AI Era”.
Key questions
Q: What breaks when one person has multiple disconnected accounts across SaaS and cloud tools?
A: Access governance becomes incomplete because review, MFA enforcement, and entitlement cleanup all operate on partial identity data.
Q: Why does fragmented identity data increase risk when organisations adopt AI copilots?
A: AI copilots accelerate whatever access already exists, so fragmented identity records make it impossible to know what sensitive data the tool can surface through inherited entitlements.
Q: How do security teams know whether least privilege is actually working?
A: Least privilege is working when identities have narrowly scoped permissions, unused credentials are removed or quarantined, and repeated access reviews consistently shrink entitlements.
Practitioner guidance
- Consolidate fragmented user identities Map every employee and contractor account back to a single person across core SaaS and cloud services so access can be reviewed as one footprint, not several disconnected records.
- Review least-privilege drift by data domain Compare actual dataset reach against current role requirements so stale entitlements to finance, customer, and operational data can be removed quickly.
- Verify MFA coverage across all linked accounts Check whether every account tied to the same identity is protected by strong authentication, and treat gaps as a control failure rather than an exception.
Bottom line: Fragmented identities create governance blind spots because one person’s access is spread across multiple systems and no longer easy to certify end to end.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity-data blind spots are a governance failure, not a visibility nuisance: when one person is represented as multiple accounts, the organisation loses the ability to certify access with confidence. That breaks the assumptions behind MFA coverage, access reviews, and least privilege because the control owner no longer sees the full entitlement set. Practitioners should treat identity correlation as a governance prerequisite, not a reporting enhancement.
A few things that frame the scale:
- 96% of security operations teams report critical blind spots, most commonly in cloud infrastructure (74%) and identity and access behaviour (67%).
A question worth separating out:
Q: What should IAM and data security teams align first when closing identity-data blind spots?
A: They should align identity correlation, authentication posture, and dataset visibility into one operational view. That lets teams decide whether a user, contractor, or service account is reaching sensitive information through an approved path or through an unmanaged account.
👉 Read our full editorial: Identity-data blind spots in the AI era expose access risk