New Ponemon Report: The Hidden Security Threat of Disconnected Apps | Download Now

The Identity Automation Crisis: What 500+ Leaders Exposed

Only 4% of organizations have fully automated their core identity workflows. That leaves 96% managing identity with manual, fragmented processes, and the gap is widest for disconnected apps: the business apps that don't support SSO, SCIM, or APIs. In this session, Cerby Chief Strategy Officer Matt Chiodi and security advisor Aaron Turner walk through what 500+ IT and security leaders revealed about the identity automation gap, why it persists, and how to close it without replacing the identity stack you already run.

What is the identity automation gap? It's the distance between the apps your identity tools can automate and the apps they can't. Cerby's research with 500+ IT and security leaders found that only 4% of organizations have fully automated their core identity workflows. The gap concentrates in disconnected apps, the apps that don't support SSO, SCIM, or APIs, so provisioning, access reviews, and offboarding for those apps stay manual.

Why is identity still managed manually for so many apps?

  • Many business-critical apps don't support the standards (SAML, OIDC, SCIM, APIs) that identity platforms rely on.
  • Access is granted through request portals and tickets, then fulfilled by hand.
  • Large organizations run divergent identity platforms, so no single system covers everything.
  • CISOs still have to attest to identities they can't see or control automatically.

What are the risks of leaving it manual?

  • Orphaned access: people keep logins to apps, payroll, and email after they leave or change roles.
  • Audit exposure: manual, inconsistent records make attestation and compliance harder.
  • Wasted time: teams lose thousands of hours a year to manual identity work. 
  • Higher stakes in regulated and critical-infrastructure environments, where lingering access is a real risk.

How do you close the identity automation gap? Automate the joiner, mover, leaver lifecycle for disconnected apps the same way you already do for federated ones. Cerby applies deterministic automation, provisioning, deprovisioning, credential rotation, and MFA enforcement, and passes lifecycle signals upstream and downstream so an offboarding in your source of truth carries through to the disconnected app. It extends the identity stack you already run (SailPoint, Okta, Entra ID, Ping, Oracle, ServiceNow) rather than replacing it. Customers such as monday.com have used this to recover significant manual hours and cost.

Presenters

Aaron Turner

Aaron Turner

Faculty

IANS

Matt Chiodi

Matt Chiodi

Chief Strategy Officer

Cerby

Ready to extend your identity perimeter
further than ever before?