Join our Newsletter — 33% off our NHI Course
Home FAQ Architecture & Implementation How should mid-market security teams implement identity governance…
Architecture & Implementation

How should mid-market security teams implement identity governance when applications are added outside formal procurement?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 1, 2026 Domain: Architecture & Implementation

Mid-market teams should start with visibility first, then layer governance on top of the real application estate they discover. That means continuously identifying SaaS, AI tools, browser extensions, and other shadow access paths, then applying access reviews, policy enforcement, and segregation of duties controls where risk is highest. Governance built on assumptions usually misses the fastest-changing parts of the environment.

Why Mid-Market Teams Need Governance Beyond Procurement

When applications arrive outside formal procurement, identity governance breaks first at visibility and only later at control. Mid-market environments often accumulate SaaS, browser extensions, AI tools, and partner-connected services faster than they can be reviewed, which is why governance based only on approved purchase records misses the real attack surface. NHI Mgmt Group’s Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into service accounts, and 97% of NHIs carry excessive privileges.

That matters because shadow applications rarely stay isolated. They often introduce OAuth grants, service tokens, API keys, and delegated admin rights that outlive the original business need. The result is a governance gap where access reviews are performed on the formal inventory, while the fastest-growing access paths sit outside it. For a practical baseline on control priorities, the NIST Cybersecurity Framework 2.0 is useful for mapping governance objectives to inventory, risk, and access control.

In practice, many security teams discover the scope of unmanaged access only after a plugin, SaaS integration, or vendor token has already been used to reach production data.

How to Build Governance on the Real Application Estate

Effective identity governance starts with discovery, not policy drafting. Mid-market teams need a repeatable way to identify what is actually connected to business systems, then classify each application by data access, privilege, and owner. That includes shadow SaaS, AI copilots, OAuth-connected tools, browser extensions, and internal scripts that authenticate with long-lived credentials.

A workable model is to combine continuous discovery with lightweight control tiers:

  • Inventory everything that requests access to email, files, source code, finance, customer systems, or AI data sources.
  • Map each application to a named business owner and technical owner before granting or renewing access.
  • Review OAuth scopes, service accounts, and API keys for excessive privilege and remove unused grants.
  • Apply segregation of duties where applications can create, approve, and act on the same data.
  • Use short-lived credentials and conditional access for higher-risk integrations rather than permanent tokens.

This is where NHI governance and identity governance converge. The moment a shadow application obtains a token, it behaves like a non-human identity with its own lifecycle, privileges, and offboarding requirements. NHI Mgmt Group’s Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs is relevant because offboarding, rotation, and revocation need to happen when use ends, not when procurement paperwork catches up.

For control design, NIST SP 800-53 Rev. 5 helps translate this into inventory, access enforcement, and revocation requirements that can be applied consistently even when the app was never formally bought through procurement.

These controls tend to break down when shadow apps are created by departments with local admin rights and no central logging, because the security team cannot reliably see the grant, the owner, or the revocation path.

Where Mid-Market Governance Usually Breaks Down

Tighter governance often increases operational overhead, so teams have to balance speed against review depth. That tradeoff is real in mid-market organisations, where security staff are smaller and business teams expect fast onboarding. Current guidance suggests using risk-based tiers rather than trying to subject every tool to the same review cycle.

One common exception is low-risk productivity software with no data or identity privileges. Those tools may only need periodic inventory confirmation. By contrast, applications that can read mail, sync files, modify CRM records, or issue AI-generated actions should be treated as high-risk regardless of how they entered the environment. This is especially important for vendors and plugins, where the direct business value can obscure the identity risk.

It is also worth separating application ownership from user ownership. A user who installed the app is not always the right person to approve its continued access, and governance fails when those responsibilities blur. The strongest programs tie each application to an owner, a review cadence, a revocation path, and a backup contact for offboarding. For broader context on how organisations are approaching NHI risk, the State of Non-Human Identity Security reports that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps.

The approach is simple in principle but difficult in practice: governance only works once the real estate is known, and mid-market teams usually learn that estate is larger than procurement records suggest.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Shadow apps create unmanaged NHIs that must be inventoried before governance works.
NIST CSF 2.0ID.AMIdentity governance depends on an accurate asset and application inventory.
NIST AI RMFAI-connected apps introduce governance risks through opaque, changing behaviour.
CSA MAESTROGOV-1Agent and app governance both require ownership, policy, and lifecycle controls.

Continuously discover and inventory non-human identities, then assign owners and review cycles.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 1, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org