They should compare the number of applications in governance workflows with the number of applications found through discovery and network evidence. If those counts diverge materially, the programme is only covering the visible layer. Completeness, not process activity, is the real success measure.
What “complete” IGA coverage really means
Completeness is a coverage question, not a workflow question. The useful test is whether the governance programme sees the full application estate, including systems discovered outside the IGA tool, shadow applications, inherited platforms and anything exposed through network or configuration evidence. If governance only tracks what was onboarded, it measures process activity, not actual control reach.
That distinction matters because IGA can look healthy while still missing material parts of the estate. A strong programme closes the gap between what is formally governed and what is actually in use, then explains any residual variance as a deliberate exception rather than an inventory blind spot.
How to compare governed applications with discovered applications
Start with two independent counts: applications inside governance workflows and applications identified through discovery sources such as CMDB, SSO logs, network telemetry, SaaS discovery, cloud inventory and administrative review. Use the same scope definition for both counts, then reconcile duplicates, retired systems and shared platforms before judging the gap. The point is to test estate visibility, not to optimise one tool’s onboarding rate. IGA buyer evaluation should therefore include connector coverage, discovery quality and the ability to surface disconnected applications.
If the counts diverge materially, the programme is only governing the visible layer. That usually means one of three things: discovery is incomplete, onboarding is selective, or ownership is unclear. Each of those conditions changes the risk picture, because an application that is not in the governance population is also outside recertification, role mapping and access review discipline. IGA fundamentals are useful here because they distinguish the governance layer from the underlying application estate.
A practical check is to compare trend lines over time, not just a single snapshot. If discovery keeps finding new applications while governance coverage stays flat, the backlog is structural. If governance claims keep rising but discovery does not, the team may be inflating coverage by counting partial integrations, pilot connectors or deprecated systems as fully governed.
What signals show the gap is becoming operationally significant
The most important signal is not raw application count, but the share of business-critical systems that remain outside governance controls. A small gap in a low-risk lab environment is very different from the same gap in finance, customer access or privileged administration systems. Coverage becomes operationally significant when the uncaptured population includes systems with standing access, sensitive data, external users or privileged accounts. Access reviews and certification only work as intended when the application list is complete.
Another warning sign is mismatched ownership. If discovery finds applications that no one can confidently assign to a business owner, they will usually be absent from certification, role design and deprovisioning logic as well. That is not just a data problem, it is a governance failure because no one can attest that the access model is current or that exceptions are being reviewed on time. Joiner-Mover-Leaver controls depend on accurate application ownership and lifecycle status.
Where role engineering is in place, the same test applies at the entitlement layer. If role mining and recertification cover only the governed subset, the organisation can still carry excessive permissions and dormant access in the uncovered portion. That is why completeness should be measured alongside entitlement freshness, not separately from it. Role design discipline becomes unreliable when the application catalogue is incomplete.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | IGA completeness depends on finding all accounts and systems that should be governed. |
| Recommendation — Inventory all applications and accounts, then reconcile discovered systems against governed records. | ||
| NIST SP 800-53 Rev 5 | CA-7 — Continuous Monitoring | Comparing governed versus discovered applications is continuous control monitoring. |
| AC-2 — Account Management | IGA coverage is about whether access governance reaches every in-scope application and account. | |
| Recommendation — Continuously compare discovery evidence with the governed application population. Require every in-scope application to have accountable account and entitlement management. | ||
| ISO/IEC 27001:2022 | A.5.9 — Inventory of information and other associated assets | Complete IGA coverage requires an accurate inventory of governed applications and assets. |
| A.5.18 — Access rights | Coverage is incomplete if access rights on undiscovered applications are outside review. | |
| Recommendation — Maintain a reconciled inventory of applications and ownership before certifying coverage. Ensure access-rights review includes all applications identified through discovery. | ||
Practitioner Guidance
What to prioritise: Use the discovery gap as the headline metric. If a system can host access, credentials or entitlements but is not in the governed application set, treat it as a coverage defect until proven otherwise. The highest-value starting point is the set of business-critical applications that are discovered but not onboarded, not the easiest applications to certify.
What to verify: Verify that discovery sources are independent enough to catch missed systems, and that decommissioned or duplicate records are not masking real blind spots. Good coverage evidence is a reconciled population with a clear reason code for every exception, not a large number of workflow completions.
Decision rule: If the governed count and the discovered count diverge materially, pause any claim of programme completeness and fix inventory quality before treating certification results as assurance. If the gap is narrow and fully explained by retired, test or out-of-scope systems, then completeness is more credible.
Practitioner takeaway: An IGA programme is complete only when its governed estate matches the real estate closely enough that the remaining difference is intentional, explainable and risk-accepted.
Related resources from NHI Mgmt Group
- How can teams tell whether cloud security coverage is actually good enough?
- How can security teams tell whether recovery is actually complete after this kind of attack?
- How can security teams tell whether an IDOR fix is actually complete?
- How can teams tell whether faster scans are actually improving security coverage?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org