Join our Newsletter — 33% off our NHI Course

SaaS discovery vs access control: what IAM teams are missing

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: SaaS discovery without connection to the underlying application leaves access, least privilege, and lifecycle actions trapped in spreadsheets and manual review loops, according to Josys. The governance gap is not visibility alone but the inability to enforce policy where permissions actually live, which makes review, offboarding, and exception handling drift out of control.

Editorial analysis by NHI Mgmt Group, based on content published by Josys: “Josys AI Integration Builder: Closing the Identity Governance Gap”.

Key questions

Q: What breaks when SaaS discovery stops at inventory and not access control?

A: What breaks is the assumption that knowing an app exists reduces risk.

Q: Why do unmanaged SaaS apps create identity governance risk?

A: Unmanaged SaaS apps create risk because they sit outside central visibility, which means IT cannot consistently enforce SSO, review entitlements, or offboard access.

Q: How can teams tell whether SaaS governance is actually working?

A: Look for evidence that discovered applications can be assigned an owner, tied to an access policy, and removed through an enforced workflow.

Practitioner guidance

  • Map discovered SaaS apps to control coverage Classify each discovered application by whether access, permissions, and lifecycle actions can be executed centrally.
  • Retire spreadsheet-based access reviews Replace manual review trackers with application-connected review workflows so reviewers can validate actual permissions instead of stale exports.
  • Block lifecycle completion for disconnected apps Do not mark onboarding, offboarding, or privilege changes complete unless the target application has accepted the change and the action is logged.

Bottom line: SaaS discovery without application connectivity leaves identity governance stuck at visibility, while permissions and lifecycle actions remain outside enforceable control.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Discovery without control is not governance: A SaaS app that is visible but not connected still sits outside the identity control plane. That means the organisation has inventory, not enforceable governance, and the gap persists even when visibility appears complete. Practitioners should treat disconnected discovery as an unresolved control exception, not as partial coverage.

A few things that frame the scale:

A question worth separating out:

Q: What is the difference between controlling SaaS applications and controlling SaaS access?

A: Controlling SaaS applications means trying to approve, block, or standardise the tools people use. Controlling SaaS access means managing identity, permissions, and authentication around those tools. In modern workplaces, access control is the stronger lever because employees will still adopt the apps they need. Security gains come from visibility and governance at the identity layer.

👉 Read our full editorial: SaaS discovery without access control creates an IGA governance gap


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.