TL;DR: Most IGA programmes govern only 13% to 15% of the application estate, leaving the rest to manual handling, and StackBob estimates that a 1,000-person organisation can absorb $12.9M in five-year costs, with 91.7% tied to the governance gap rather than platform spend. The real issue is not licence cost, but the operational, audit, and productivity drag created when access sits outside lifecycle control.
NHIMG editorial — based on content published by StackBob: IGA governance gaps cost more than the platform itself
By the numbers:
- The line items most finance and security leaders focus on account for 8.3% of the five-year cost.
- 1, or a 1,000-person organization, five years of that gap adds up to $12.9M in combined costs.
Questions worth separating out
Q: What breaks when IGA does not cover the full application estate?
A: When IGA does not cover the full application estate, joiner, mover, leaver processes fall back to manual handling, access reviews become inconsistent, and audit evidence fragments across local owners and ticket queues.
Q: Why do ungoverned applications increase identity lifecycle cost so much?
A: Ungoverned applications increase identity lifecycle cost because every access change requires human intervention.
Q: How can security teams tell whether IGA coverage is actually working?
A: Security teams can tell IGA coverage is working when access changes flow through automated lifecycle events, certification evidence is consistent, and manual tickets drop for the applications in scope.
Practitioner guidance
- Measure governance coverage by application estate, not deployment status. Build a complete inventory of applications, then classify each one by whether joiner, mover, leaver, certification, and offboarding workflows are actually enforced.
- Quantify manual fulfilment cost for every ungoverned application. Track helpdesk time, approver time, delay impact, and remediation work for apps outside lifecycle automation.
- Prioritise lifecycle extension where access delay is most expensive. Start with application groups that create the most JML tickets, the longest fulfilment queues, or the highest audit finding rates.
What's in the full article
StackBob's full article covers the operational detail this post intentionally leaves for the source:
- The five-category cost model behind the $12.9M estimate, including professional services, licence, internal labour, audit findings, and access delays.
- The working assumptions for a 1,000-person enterprise, including application counts, governed versus ungoverned coverage, and growth rates.
- The calculation method for manual provisioning, audit remediation, and productivity loss, useful if you want to test the model against your own estate.
- The cost comparison between extending governance to additional applications and leaving the manual queue in place.
👉 Read StackBob's analysis of the IGA governance gap cost model →
IGA governance gaps: what do they really cost enterprises?
Explore further
IGA coverage gaps are a control-cost problem, not a tooling footnote. The article correctly shifts attention away from platform licence spend and toward the hidden cost of the applications that never enter governance. In identity programmes, the financial drag usually comes from what remains manual, not from what was bought. Practitioners should evaluate IGA as a coverage and operating model issue, not as a procurement line item.
A few things that frame the scale:
- The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, according to The 2024 ESG Report: Managing Non-Human Identities.
A question worth separating out:
Q: Who is accountable for applications that sit outside IGA governance?
A: Accountability should sit with the application owner, IAM leadership, and the control owner responsible for lifecycle evidence. If an application is excluded from governance, that exception still needs a named owner, documented rationale, and a remediation plan. Otherwise, the organisation is accepting unmanaged access as a permanent state.
👉 Read our full editorial: IGA governance gaps cost more than the platform itself