TL;DR: Identity integration is a continuing maintenance burden, not a one-time implementation, because connectors break as applications, schemas, and auth requirements change, according to Opnova. The connector treadmill shows why governance programmes can be fully funded yet still drift, and why intent-driven automation matters more than brittle point integrations.
NHIMG editorial — based on content published by Opnova: The Connector Treadmill: Why Integration Never Ends Identity programs are sold on the idea that connecting an application is a one-time job
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
Questions worth separating out
Q: How should IAM teams budget for identity connectors that need ongoing maintenance?
A: Treat every connector as a recurring operating expense, not a one-time project cost.
Q: Why do identity connectors fail even when the application vendor says nothing changed?
A: Failures often appear when authentication requirements, entitlement schemas, or deprovisioning flows change upstream.
Q: What do teams get wrong about SCIM provisioning and deprovisioning?
A: They often assume the standard itself guarantees clean lifecycle execution.
Practitioner guidance
- Rebase the integration budget on lifecycle cost Separate initial connector build cost from annual maintenance, testing, and rework.
- Inventory applications by integration fragility Classify targets by schema volatility, authentication change frequency, and the need for custom logic.
- Measure governance drift, not just connector uptime Track entitlement sync failures, stale access records, and delayed deprovisioning alongside technical uptime.
What's in the full article
Opnova's full blog covers the operational detail this post intentionally leaves for the source:
- How Opnova frames the economics of custom connector maintenance across disconnected application estates
- The article's practical rationale for intent-based application operation versus rigid connector logic
- The section discussing why LLM-generated code reduces build time but not ongoing integration drift
- The vendor's own view of how governance evidence, approval gates, and verification should be layered around automation
👉 Read Opnova's analysis of the connector treadmill in identity governance →
Identity integration never ends: what the connector treadmill means?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
The connector fallacy is a governance assumption failure, not a tooling inconvenience. Identity programmes are often designed around the belief that integration is a bounded project with an end state. That assumption fails because applications, authentication methods, and entitlement models keep changing after go-live. The implication is that governance teams must stop measuring success by onboarding completion and start measuring it by sustained control quality across the application lifecycle.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
A question worth separating out:
Q: How do you know whether identity governance is becoming a treadmill?
A: Look for the point where a growing share of next year’s budget is spent keeping existing connectors alive instead of extending governance to new applications. Stale syncs, repeated rework, and delayed onboarding are early signals that the programme is sustaining itself rather than expanding coverage.
👉 Read our full editorial: The connector treadmill exposes the real cost of identity integration