TL;DR: Native identity platforms create an invisible perimeter, leaving non-native applications, legacy systems, service accounts, and AI agents outside effective governance, according to SailPoint. The real issue is not directory coverage but whether identity programs can enforce lifecycle control and audit depth across the full enterprise estate, while SailPoint’s Horizons of Identity Security 2025-2026 report says non-human identities now outnumber human ones by 45-to-1 and only 39% of organizations govern AI agents.
NHIMG editorial — based on content published by SailPoint: The invisible perimeter, unifying identity governance beyond native boundaries
By the numbers:
- Non-human identities now outnumber human ones by a 45-to-1 ratio in enterprise environments.
- Only 39% of organizations currently have governance controls in place for AI agents.
Questions worth separating out
Q: How should IAM leaders govern applications that sit outside the IdP in modern environments?
A: IAM leaders should treat out of IdP applications as first class governance scope, not exceptions.
Q: Why do native identity platforms leave risk behind in hybrid estates?
A: Because they often stop at the boundary of their own ecosystem.
Q: What breaks when offboarding does not reach every application?
A: When offboarding is incomplete, former users can retain active access in SaaS apps, shared groups, and delegated systems after they should be removed.
Practitioner guidance
- Define the native boundary explicitly Document which applications, databases, and workloads are governed only by the directory and which are governed through entitlement-level controls.
- Separate authentication coverage from governance coverage Track SSO reach, entitlement visibility, and revocation effectiveness as different control outcomes.
- Extend joiner-mover-leaver workflows to non-native systems Ensure offboarding and access change events propagate to ERP, payroll, supply chain, and other downstream systems where access can persist after directory revocation.
What's in the full article
SailPoint's full blog covers the operational detail this post intentionally leaves for the source:
- How its co-existence architecture is positioned across native directories and non-native systems
- The specific governance depth model used to distinguish SSO reach from entitlement control
- Examples of how AI-driven intelligence is applied to external applications and identity behaviour
- The webinar preview on borderless identity and ecosystem blind spots
👉 Read SailPoint's analysis of identity governance beyond native boundaries →
Invisible perimeter in identity governance: what are teams missing?
Explore further
Platform reach is not governance reach. The article correctly separates directory coverage from entitlement control, which is the distinction many identity programmes still blur. A system can authenticate users inside its native ecosystem and still leave high-risk external applications outside its governance perimeter. Practitioners should treat reach as a transport layer property, not a governance outcome.
A few things that frame the scale:
- Non-human identities now outnumber human ones by a 45-to-1 ratio in enterprise environments, according to The 2024 ESG Report: Managing Non-Human Identities.
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.
A question worth separating out:
A: Look for evidence that reviews, revocation, and entitlement monitoring are happening inside non-native applications, not just in the directory console. If the programme can only report logins and primary account status, it is measuring reach rather than governance. Real coverage shows up in downstream entitlement visibility and timely access removal.
👉 Read our full editorial: Identity governance beyond native boundaries needs a wider control plane