Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why do custom IGA connectors still leave coverage…
Governance, Ownership & Risk

Why do custom IGA connectors still leave coverage gaps?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 5, 2026 Domain: Governance, Ownership & Risk

Custom connectors do not remove the architectural dependency on an external API. They simply move the maintenance burden to one team for one environment, which often increases cost and slows recovery when the target system changes. That means the coverage gap is not solved, only financed differently, and often less efficiently.

Why custom connectors still miss systems that look “covered”

Custom IGA connectors can extend reach, but they do not eliminate the hard dependency on a stable external interface, data model, and permission path. Coverage gaps usually appear where the target system changes faster than the connector, exposes only partial APIs, or requires special handling that was never standardized. The result is not full coverage, but a narrower slice of managed access.

That limitation is structural, not just implementation noise. IGA Buyer's Guide is useful here because connector fit should be judged against lifecycle, reviews, and disconnected application coverage, not just whether a custom integration can be built.

When a connector is bespoke, the organisation also inherits environment-specific assumptions. If the source system, API version, or provisioning workflow changes, the connector can drift from reality even while the IGA platform still reports a successful integration. That creates an appearance of coverage without reliable control coverage.

Why maintenance debt turns into missed entitlement coverage

Connector gaps widen when the integration only handles the “happy path” of create, update, and disable, but not the edge cases that matter operationally: nested entitlements, indirect role assignment, approval exceptions, or service-specific lifecycle events. Over time, those unhandled paths accumulate as exceptions, manual workarounds, or shadow processes outside the governed flow.

IAM and IGA Basics is a good reference point because the missing coverage is often about entitlement governance, not just connector code. Access Reviews and Certification Guide reinforces the practical issue: if the connector cannot present accurate effective access, reviewers end up certifying incomplete data.

Connector maintenance also competes with change velocity. The team that owns the custom code must keep pace with target-system releases, schema changes, and authorization changes, which means coverage tends to erode in the places that are hardest to notice first: stale mappings, incomplete recertification, and delayed deprovisioning.

What to design for when coverage matters more than a one-time integration

The real question is not whether a connector exists, but whether the control model survives change. Coverage is strongest when the connector is paired with explicit ownership, tested lifecycle events, and a fallback path for the cases the API cannot represent cleanly. Without that, the connector becomes a maintenance promise rather than a governance control.

Joiner-Mover-Leaver (JML) Guide fits this problem because many gaps show up when accounts move, entitlements change, or leaver workflows leave behind residual access. Top 10 NHI Issues is also relevant where connectors must govern service accounts, tokens, or other non-human access paths that often fall outside human-centric onboarding and offboarding logic.

When organisations need broad coverage across many applications, the answer is usually not a bigger pile of one-off connectors. It is a tighter inventory of what must be governed, clearer rules for which systems qualify for automation, and a deliberate exception model for the systems that cannot be integrated safely or completely.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementCustom IGA connectors affect account and entitlement control coverage.
Recommendation — Automate account lifecycle coverage and verify exceptions for systems the connector cannot govern.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementConnector gaps often leave credentials and lifecycle actions partially governed.
AC-2 — Account ManagementIGA connectors directly support account creation, modification, review, and disabling.
Recommendation — Control credential lifecycle workflows where the connector cannot fully enforce access changes. Tie connector scope to account lifecycle requirements and reconcile any unmanaged accounts.
ISO/IEC 27001:2022A.5.18 — Access rightsConnector gaps create incomplete access-rights governance and review coverage.
Recommendation — Review access-right coverage for every system and close unmanaged entitlement paths.

Practitioner Guidance

What to prioritise: Treat “connector exists” as a starting point, not a control conclusion. First verify whether the integration covers the full access lifecycle, including revocation, entitlement change, and recertification data.

What to verify: Check whether the connector reads and writes the authoritative entitlement model, or only a subset of roles and accounts. If reviewers must rely on exports, spreadsheets, or manual reconciliation, the coverage gap is already real.

Common mistake: Teams often spend too much effort customising around a target system’s quirks and too little on measuring what remains outside automation. A thin but reliable connector is often better than a fragile “complete” one that cannot survive version drift.

Practitioner takeaway: Custom connectors reduce integration friction, but they do not remove the underlying governance problem, coverage is only real when the connector keeps pace with target-system change and exposes the access state needed to act.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 5, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org