Join our Newsletter — 33% off our NHI Course

Identity governance without visibility: where do controls break down?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Most IGA programmes still govern the 30% to 40% of applications they can see while the 60% to 70% shadow layer remains outside reviews, provisioning, and audit evidence, according to Zluri's analysis. The governance problem is not weak policy design, but incomplete discovery that leaves access truth fragmented across systems and teams.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Identity Governance and Administration - A Visibility-First Guide”.

Key questions

Q: What breaks when organisations do not have a complete inventory of applications and identities?

A: A partial inventory breaks governance before it breaks technology.

Q: Why do access reviews miss real access in shadow IT environments?

A: Because review scopes usually follow the systems tied to the IdP, not the full application estate.

Q: How can security teams tell whether IGA coverage is actually complete?

A: They should compare the number of applications in governance workflows with the number of applications found through discovery and network evidence.

Practitioner guidance

  • Map the full application estate before certifying access Build a current inventory of all applications, including shadow IT, team-managed tools, and unfederated systems, before relying on access reviews.
  • Reconcile IdP records against application logs Compare directory access with application-side evidence so you can see where the IdP undercounts actual users or misses local identities.
  • Extend offboarding to non-federated applications Verify that leaver workflows revoke access in systems outside SSO, especially tools where credentials or local accounts persist independently.

Bottom line: Identity governance fails when review and lifecycle workflows only cover the applications the IdP can already see.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Visibility is not a supporting control in identity governance. It is the control boundary that determines whether governance exists at all. When organisations certify access against an incomplete inventory, they are not governing the estate, only the portion already mapped by their tools. That distinction matters because IGA can look mature while still missing a large share of actual access. The practitioner conclusion is simple: governance coverage must be measured against the full application surface, not the federated subset.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Should organisations prioritise discovery before automation in identity governance?

A: Yes. Automation amplifies whatever inventory it is built on, so automating a partial view only produces faster partial governance. Discovery first gives the programme a complete control surface, which makes reviews, provisioning, and offboarding materially more reliable.

👉 Read our full editorial: Identity governance fails when visibility comes second


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.