New Ponemon Report: The Hidden Security Threat of Disconnected Apps | Download Now

Flat File Governance is a Liability, Not a Bridge

Flat files in identity governance
Table of Contents

    Ready to see what Cerby can do for your disconnected apps?

    TLDR: Your IGA platform counts flat file apps as "connected." They aren't. A flat file is a copy someone exported, not a live connection, and that difference breaks governance three ways: the export misses accounts and entitlements no one downstream can see, the data is stale before anyone reviews it, and it's the first place auditors dig. You end up reporting coverage you can't actually verify. Cerby replaces those flat files with direct connectors, so disconnected apps feed governance the same way a connected app does.

    Identity governance was built on an assumption of connectivity. But in most enterprises, hundreds of apps are governed through manual CSV uploads that the platform counts as "connected." The gap between what dashboards report and what actually exists is where audit findings, retained access, and unexpected costs live.

    Enterprise application portfolios are growing faster than IGA connector catalogs. Organizations are adopting SaaS, standing up internal tools, and inheriting on-prem systems through acquisition at a pace that no identity platform's integration roadmap can match. When an app can't be reached with a viable connector, or building one isn't worth the cost, teams fall back on the oldest integration pattern in enterprise software: someone exports a report of who has access, drops a CSV in a shared location, and the platform ingests it on a schedule.

    For identity and security teams, this isn't just an inconvenient workaround. It challenges one of the core assumptions that modern governance has been built around: that what the platform shows you reflects what's actually there. Certification campaigns, access reviews, audit reports, and board-level risk dashboards all inherit their credibility from the data underneath them. When that data is a point-in-time export scoped by whoever ran it, the credibility is borrowed, not earned.

    A CISO running their IGA platform once told us every one of their 1,600 apps was connected. We asked how, since we knew a number of those apps had no viable connector. It turned out 400 of them ran on manual flat file uploads, and as far as the platform was concerned, that counted as connected.

    The industry often treats flat files as a coverage question, a temporary bridge until a connector exists. That framing doesn’t hold. A flat file isn't partial coverage. It's a different category of data entirely: a copy instead of a connection. And the difference between the two determines whether governance is something you can verify or something you have to take on faith.

    Completeness: The File Only Contains What the Export Was Built to Find

    The first major problem with flat file governance is that the file never contains everything.

    An export only captures what it was built to query. In practice, these reports are almost always scoped too narrowly (usually user error), or the source system's structure hides data during the export. Either way, the entitlements that exist in the app never make it into the file. The platform ingests the CSV, marks the app as represented, and no one downstream can see what was left behind.

    Replacing flat file feeds with direct connectors surfaces the same pattern almost every time: orphan accounts the export never showed, service accounts (often dozens per system), admin-level access living in a portion of the system the export didn't touch, and on multi-table platforms, users sitting in tables the report never queried. The more complex the application behind the file, the worse it gets. On cloud SaaS apps, we've seen feeds miss thousands, sometimes tens of thousands, of entitlements, accounts, and permissions.

    This is the same unaccounted-for access that shows up after the fact in incident data. Teams report that 58% of former employees retained access to systems after leaving (2025 Identity Automation Gap Report). When joiner, mover, leaver access isn't automated, nothing tells you it failed. That retained access persists quietly across the apps the flat files were supposed to account for, and you probably won't notice until you, or the auditors, go looking.

    Freshness: The Data Is Stale Before Anyone Reviews It

    The second problem is time.

    Most flat file feeds run quarterly, and some run annually. That means the platform can be reasoning over access data that's three to twelve months old. Every certification decision, every access review, every risk score built on that feed is a decision about the past presented as a statement about the present.

    Teams sometimes reach for delta exports as a fix, running smaller files more frequently. But delta exports exist to cut file size and processing load, not to fight staleness. Efficiency does nothing for completeness or freshness. A faster copy of an incomplete picture is still an incomplete picture.

    There's a second structural limitation here that matters just as much. Because a flat file is a copy, data moves one way into the platform and never back out. The platform can flag that an account should be removed, but it has no way to reach into the app and remove it. Someone has to do that by hand, and the platform never learns whether the fix actually landed, because nothing reports back. There is no closed-loop remediation and no confirmation. The next time you find out the truth is the next time the file lands.

    Scrutiny: Auditors Dig Where the Data Is Weakest

    The third problem is that flat files change how auditors behave.

    With a live connection, the platform pulls account and entitlement data straight from the app. A reviewer is looking at the current, system-collected state that no one touched by hand. A flat file is whatever someone exported and uploaded: point-in-time at best, and editable in a spreadsheet before it ever lands. Auditors know this, so they drill into the apps with the weakest supporting data, pick a few privileged or in-scope accounts, and ask the owner to reconstruct the approval trail from email and tickets.

    It's like a dentist poking around on a tooth. You find a soft spot, you dig.

    That scrutiny carries a number most security leaders never see, because it lands on the audit team's budget rather than the CISO's.

    “Each deep dive runs roughly $10,000 to $15,000 in work. A cycle that surfaces 20 or 30 findings reaches into the hundreds of thousands quickly.” – Donovan Blaylock, Head of Solutions Engineering, Cerby

    But the dangerous cost isn't the audit bill. It's false confidence. Flat file apps are usually filed as "connected," or at least "not disconnected." They appear in dashboards as covered and are reported up as governed, but they aren't. The data behind them is a quarterly guess that everyone involved already expects to be incomplete, and almost no one is still questioning.

    The New Governance Standard

    Identity governance is entering a period where the gap between reported coverage and actual coverage is no longer sustainable. Access changes faster, applications proliferate faster, and audit expectations are rising to match. The assumption that a quarterly snapshot is good enough belonged to a slower era.

    The organizations that adapt will be defined by how much of their environment they can actually verify, not by how many apps their dashboards count as connected. Verification requires a direct connection into the system: one that reads every account and every entitlement on a scheduled sync and feeds that back to the governance and audit functions that depend on it. A flat file tells you what someone chose to show you, three months ago. Governance is knowing what's actually there, as of a much more recent sync.

    This capability is not on the horizon. Cerby builds connectors for the apps your IGA platform doesn't reach, cloud or on-prem, through custom and pre-built automations. We've already built over 1,500 of them, so the apps that used to live in a CSV now feed governance and audit the same way a directly connected app does. That CISO governing 400 disconnected apps with flat files? She took care of it with Cerby.

    The future of identity governance will not be defined by the number of apps a platform claims to cover. It will be defined by how much of the environment can be verified, continuously and without human hands in the data. Flat files were a reasonable bridge for a slower era. They are a liability in this one.

     

    Ready to extend your identity perimeter
    further than ever before?