The IGA Playbook: Automating Identity and Closing the Coverage Gap for Disconnected Apps
Thank you all so much for joining us today. We really appreciate it. This is Belle Lepe. I'm the CEO at Cerby. Francis Odom is our guest speaker and star speaker. Excited to have you here, Francis, and and thank you so much for taking the time. Francis, of course, is over at software analyst cyber research as the chief cybersecurity analyst and excited to have been collaborating with him. And we're gonna be going through the two two two thousand twenty five IDA playbook focused on automating workflows and and closing the coverage gap. So without further ado, I'm gonna hand it off to Francis here in a moment. But what I did wanna mention as we're going through this presentation, if you all have any questions, please feel free to write them in to the chat or to the q and a. We'll make sure to field them either throughout the presentation or towards the end. So questions are absolutely welcome. Thank you so much. But with that, Francis, I hand it over to you. Excited to get going. Amazing. Thank you so much, Bill, for having me. Thank you so much to to team for hosting this platform, and thank you all. So really excited to do this presentation and really just to speak about the role of identity governance, managing the governance and access controls. Many of you are I imagine a lot of our participants, whether you're a practitioner already, whether you've been in the industry for a while, we're all very familiar with this ecosystem of identity governance. And so we did a major, we did a report earlier this earlier this year with the software analyst cyber research where we, identified and and spoke to different identity, leaders as well as we do some a lot of our research in which we wanted to share some of the key findings of what we're seeing happen as of twenty twenty five as it relates to identity governance. And and so a big part of that is how do we automate a lot of workflows and how do we, close a lot of the coverage gaps that still exist today, within IGA. So that's let me so I'll go to maybe kick off our conversation is to, first of all, just take a high level look at the identity governance ecosystem as as as we know it today. I will say in general, you know, the IGA market, it still remains one of the largest markets within cybersecurity. We and then, obviously, within identity. We know huge amounts of money, huge budgets, goes into a lot of identity governance projects. And I think one thing we do know is IGA is at an inflection point. If if anything, when we did this report, that was a key, finding for us in which we found out that IGA now is actually evolving from just the back office compliance checkbox, you know, to becoming more of a much more core element for how identity leaders think about what needs to be done. You know? And I think, yes, we do have full scale IGA, vendors at the bottom, but above, we see there's the identity governance centric vendors and also the role that identity governance automation vendors are also gonna be playing here. And part of our big conversation today is really talking about the new, the new trends that are helping to redefine this IGA market as it relates to nonhuman identities, the the growth of SaaS applications, you know, as well as disconnected applications. And and so our goal is really to speak to what's happening as it relates to what's changing across this entire market ecosystem. And so those are some of what we're we're gonna be talking through. Also wanted to set the context too, you know, for for many leaders, you know, who who might be might not be as fully familiar with all of your core components of your IGA. I think it's important to remember a huge part of IGA today really has to do with the who, what, and when when we talk about identity security. And I think it's very much more distinct from the how that might be a force from an SSO or an MFE type provider. You know? And I think it's very, very important for our participants to know all of these core elements or these core different attributes that make up your IGA ecosystem, each of these areas are changing as it relates to some of the trends that I did mention, earlier. Right? The the relentless growth of SaaS applications that includes managing as well as unmanaged, you know, I audit frameworks that are changing either how companies are going about doing auditing now, for example, one of the core attributes of an IGA, entitlements management. You know? And then also even things around access request and certification as it relates to modern applications to do, or how we actually go about doing fulfillment and provisioning. And I think one thing I did wanna stress is when we think about the core basics or the core functions of IGA, each of these different elements and processes are evolving. Again, all due to this relentless growth in SaaS applications, different, identity frameworks that are coming up, and then just the lack of visibility that a lot of leaders still face today. So the next piece we wanted to also just build upon to is we try traditional IGAs on where they do fall short in in in today's market. I will say almost you could almost think of it as one of the Achilles heels, quite frankly, for a lot of, for a lot of traditional IGO identity governance solutions primarily has to do with SaaS and application sprawl that has actually happened. You know? I think enterprises now, you know, have an average of over a thousand applications. You know? However, most IGO vendors, you know, barely have enough connectors to really help them map and and connect to a lot of these applications that are being used across the enterprise. You know, and that literally leads us to a situation whereby we have almost about a thirty to fifty percent coverage gap for for for quite a few companies. You know? And and and this actually could vary. You know? Some really large enterprises have a significantly high amount of gaps that they're actually facing. I think another piece that's also adding to a number of these things has to do with the role of nonhuman identities, you know, with with the role that AI will play over the next, over the next few years. I mean, we're maybe even months at this point, the rapid progression that we're seeing in in terms of eject AI is leading is is is making leaders, really have to highly think about how they go about implementing identity governance again. But as it relates to a lot of your service accounts, a lot of your bots that increasingly have access to a lot of very, very important sensitive data or sensitive information. And last but not the least is still a lot of the manual task, a lot of the manual processes that are involved in IGA today. You know, over eighty percent, you know, of still a big part of provisioning Joyner and then how employees move and and and leave, especially off boarding. A lot of these JML events that you need in an IGA governance solution. You know? Many of these are still on spreadsheets. A lot of there's still a lot of offense service accounts, and and I think we need to have a conversation on how do we help the industry solve solutions around many of these areas where traditional IGA and identity governance and solutions to help that. I think another thing that I we do wanna maybe create more of a spotlight. You know, in the previous slide, we had this section about applications for in terms of what's happening, within the industry. I think there was a really, really good report by SEBI that I do definitely want to highlight that I think many leaders will find this very fascinating, a lot of the insight. But I'll just I won't go through every part of it, but I'll just share maybe some key highlights from that report. You know? Roughly about, what, ninety six percent of, security leaders, you know, still rely on very manual steps, you know, to help them go about provisioning, rotation, and and offboarding. A lot of again, some of those GML events that I just talked about in previous slide. You know? On the ten percent drives, you have automation to automate the number of users. And I think this is one thing you we do realize is many of these processes that are still being done on spreadsheets could be automated if you have a good solution. You know? We also wanna talk about the, disconnected applications. You know? I think a huge part of the gap that that we talked about is, you know, roughly about, what, thirty percent or so business critical applications, you know, still lack basic, identity hygiene, MFA, encryption, and and and the likes. You know? Additionally, so, you know, eighty nine percent of organizations, you know, admits that, you know, they still have issues around ex employees, you know, still retaining access. So, like, a failure as it relates to a lot of your off boarding events. You know? And we have a number of other data points here that do show that currently, leaders do have a lot of automation gaps. Many things are still being done manually, and especially as it relates to managing a lot of the disconnected applications, and especially a lot of those shadow applications that you might have within your enterprise. And, Francis, actually, just Yes. Apologies for interjecting. But, you know, one thing I I will mention here from from this the service side of things that you're not alone. Right? If you're looking at this percentage and and, you know, one of the takeaways should be just about every enterprise that certainly we've encountered does have this issue. Right? And so you're not alone if you're you're realizing that you have manual workflows. This is a widespread widespread problem, and virtually every company that we've encountered still has, as as as you mentioned, Francis, a number of manual workflows around the joiner mover lever life cycle. Absolutely. Absolutely. No. Thank you. Thank you for doing thank you for adding that context. Absolutely. Great. So, yeah, I won't speak to this slide, but it gives it just gives a lot of data as it relates to nonhuman identities, service accounts, and then a lot of the sprawl that we're actually seeing with nonhuman identities. It's adding a huge element of complexity to to to the coverage gap many, leaders are facing today. So one key finding, one key finding from our, we we provided solutions because I think in identity, we we have this tendency to speak about problems, problems, problems, challenges, challenges, challenges. However, you know, we don't many people don't like to talk too much about what a solution, what are practical, actionable steps that leaders could actually take today right away to actually, go about, fixing the number of these problems and all of these coverage gaps that we did talk about. So we did have a few things that obviously were mentioned and, obviously, the the different processes. Right? The different processes leaders could take depending on, depending on the part of your organization where you have the most gap. Right? You you might be stronger on the particular part of your enterprise, maybe on the provisioning part of it, but maybe the onboarding part is still a big challenge. And and so I'll just briefly go through a few of these, and then, myself and Bill will maybe just have more of a broader conversation. But, again, you could take one of these automation imperatives that that we did provide to leaders. So first of all, I will say, the first thing, again, the five major automation solutions that we did have here for leaders, I will say one of them, the biggest one is around automating a huge part of your identity life cycle processes. Right? And I think, one thing we did really, really speak to when we did this report so far is the lack of automation. Many things are still done very manually. And one of the core things we really wanna advise, recommend, and so any practitioner leader who who might be joining us is linking a lot of your HR events to a lot of your SAMI connectors. And and so in most cases, you know, on the provisioning side, you know, this might be around how new hires get access, you know, what are the controls that you do have, what are the core processes that we actually have, and or as it relates to how when throughout your whole life cycle within the enterprise, what do we actually do we have actually have good processes around cutting down a lot of the manual provisioning or throughout your whole life cycle within the enterprise. So the big part of our recommendation here, quite frankly, is linking and connecting a lot of your HR systems, again, to your connectors back to a lot of your IGA controls that you might have within within your enterprise. Again, that's that was one key thing, and we we hope hope a huge part of this will help, solve that. Second piece here is consolidating a lot of your identity data in in into into your major solutions. And and so what this could be is you using solutions, you know, that have federated integrations with all major IDPs. You know? So you might be using Okta, or maybe on an Entra, depending on your IDPs. But we do think a core part of eliminating a number of these, a core part of really just helping to reduce a lot of the failed IG deployments today really just exist because of silos. And so finding vendors and and solutions that actually integrate very, very closely with your IDPs, Azure AD, ServiceNow, depending okay. So that the goal here is there's a very, very tight integration across them to cut down on a number of the manual gas and silos that that that does exist there. A third one, obviously a third another point we we did talk about here is just AI driven continuous certification. And so, obviously, some leaders here we know have really, really traditional quarterly campaigns, quarterly review campaigns that are very manual and and very, time sensitive. But could we actually use AI? We've seen this with some vendors who've actually been able to use AI to actually automate and make these processes much easier. You know? I think the big one we're really gonna go over here is extending, coverage to all applications. And maybe I'll just go through this in in my next slide instead. And so I think three major ways in which we think to help, extend our coverage is definitely number one here, leveraging RPA to automate the number of key identity workers. I'll be happy to talk to Bill to expand more on here. Second piece here as it relates to extending to all apps is, you know, extending this to a lot of your least privileged controls. So you might have a power solution. You you wanna make sure that it's connected to that. You wanna be able to have good audits coverage to a lot of your long term applications as it relates to web, SaaS, depending on wherever your users are, accessing things from. And last but not the least here, it has to do with leveraging a solution that's easily able to plug and play, into your existing solution. So one challenge we know, and I speak to many leaders, is they don't want to replace. They they there's always there's always that challenge of trying to replace a lot of your solutions that you have internally. And one, advice, you or my advice to leaders is to find solutions that are able to easily augment or just work side by side with a lot of your IAM, IGA, Powerstack, and help you do a lot of use a lot of the what we just talked about around automating a lot of your of your identity life cycle management, credential management, or as it relates to privileged access control. But maybe at this point, Bill, I'll I'll maybe happily have you chime in, if if there's any point here that you really wanted to go deeper on. No. And and and thank you so much for for going through contents of the report. Again, very spot on based on what we have seen across the industry as well, so always good to see that resonance. You know, there's maybe starting with with one of the last points that you mentioned and and would love to maybe elaborate on a little bit. You know, our our what we typically see is that, IGA is a journey. And when Cerby is typically coming into the picture, apologies for that, background noise, they've already invested sometimes seven figures, eight figures, into an identity governance administration program. And, unfortunately, they're usually only fifteen, twenty percent of the way through to achieving the coverage that they want to achieve. And so, you know, your last point there, I think, is so critical. All of them are, certainly, but maybe starting with the last one because it's it's important to make what has already been invested in work. Right? Because the the typical IGA program, again, will be, years, in in the making. And what they have been able to stand up works well for the, you know, that that twenty percent. But the question is, how do you close the gap for the remaining eighty percent? And, you know, one of the things that Cerby is really focusing on is how do you fundamentally alter the unit economics? So that, you know, hey. You're maybe eighty percent of the way through the budget that you've allocated for IGA, but you're only twenty percent of the way through, from a coverage perspective. How do you make sure that that remaining twenty percent of the budget can actually cover the last eighty percent? And so that's where our approach around leveraging not just traditional robotic process automation technologies, but layering on, as you you represented in the prior slide, artificial intelligence capabilities to make sure that, that that certification and the actual maintenance of those connectors, is always up to date. And so that's a little bit of what we've seen, in terms of being able to to extend that. You know, I'm I'm curious, Francis, on on your end as as you look as you've spoken to folks in the space, have you heard any of those anecdotes? Does that resonate with what you're also seeing in terms of those percentages of eighty percent of the way through the budget, only twenty percent of the way, against, you know, the the intended universe of applications to connect? Yeah. No. Absolutely. One hundred percent. You know, one thing we hear I mean, a big part of identity, IGAs today is still very services oriented, and so a big part of many leaders, quite frankly, have a lot of, service integrators and SIs who are helping them. Maybe I'll maybe I'll just move to my last slide here, but, and then we could talk through a a number of the points. But one of the big challenges we hear whenever as it relates to speaking to leaders is the fact that they still spend and invest a lot of money with their seventh graders to actually help them grow and improve and enhance a lot of the IGA solutions. And but you still hear the the same problem with issues we connect us connect to or maybe HR systems or a lot of your core ServiceNow systems or ITSM systems, whatever systems you have internally. And they still have that huge gap as it relates to a lot of applications. So definitely and I think now too, we what advancements we're seeing in AI, we there's a lot of capabilities around helping to, at least, view connectors rapidly, and I think that's obviously one thing I do like about service solution to help to close a lot of these, a lot of these gaps much more fast quickly. I think another thing, to also bring up here is what you guys do as it relates to a lot of the RPA recorders, a lot of your RPA type connectors. I mean, do you maybe want to share more as it relates to that? Like, in terms of your UI recording, because I think one thing I really like about what you guys do there is you guys are actually able to you have a UI, recording bot, you know, that's able to mimic, you know, an IT or help desk analyst, you know, and see their entire process, and then is then able to then rotate secrets or push patch keys on a schedule. Do you wanna maybe speak more to what you guys do and use on the RPA front? Absolutely. You know, one of, there there are two dynamics that are that I that I think are helpful to call out. One is that, you know, another kind of driving factor that you mentioned earlier on in the presentation is that there's just a lot of apps. There's there's a lot of sprawl, and there's a lot of heterogeneity. Right? The the moment you start talking about disconnected apps across this this SaaS application sprawl environment, a lot of them don't support standards. And so as a consequence, you're seeing different, different entitlement structures. You're seeing, some of them are on premise. Some of them are browser based. Some of them are accessible to the public Internet. Some of them are not. And so there's just a substantial amount of heterogeneity. And then the second kind of motivating factor here is that oftentimes when you're looking at these applications that have not yet been connected to the incumbent IGA platform, all of the subject matter expertise around how you permission a user, how you provision a user, is in someone's head. Right? It's it's not documented, somewhere. It's it's, it's, you know, a handful of people that are hands on keyboard that are actually doing the work. And and so as we encountered that dynamic quite a bit, we realized that we needed to find a way to scalably handle that heterogeneity, but also be able to learn from the subject matter experts. Right? You know, for for example, we we do a lot of work in the health care space. We do a lot of work in the financial space. We're yet to find two companies that leverage a banking mainframe the same way or leverage an electronic health records system the same way. And so what we did is we built something that we call CerbyScout. And what CerbyScout does is, as Francis mentioned, is it allows us to learn from the end user and how they use the application, and that directly trains our agent, that builds the robotic process automation routines. And so, again, when you look at this problem, there's a lot of sprawl. There's a lot of heterogeneity. There's a lot of information that only exists in the head of heads of the subject matter experts. We've had a lot of success bringing those subject matter experts into the, robotic process automation training process to actually directly train what we're doing. And so this is one of the things that allows us to create those connectors much faster. And more or less on first go, have them properly mimic, and in some cases, enhance what the human operators were doing already. And so, yeah, Francis, you're you're you're you're exactly exactly right. I'm I'm curious as you've seen and and, again, had a have conversations with folks. Do you do you see any of that dynamic where, you know, the subject matter experts have all the knowledge in their head and it doesn't really exist across the the rest of the organization? Oh, def I mean, definitely. I think definitely. That's that's definitely a big challenge. And I do think, you know, that's that was really one thing when I when we're doing our research because, again, we we've spoken and we've done a lot of work across the industry in terms of the different solutions we've seen, but that's one thing we definitely really liked about that. To your point, yes. Or even if you do have a lot of employees who who might have this this that who might have this knowledge, they don't wanna have to repeat doing this task over and over. And, like, especially with retaining secrets, they're very manual and cumbersome job for for many teams, you know, or or pushing past you that is specifically scheduled. If you could literally just have a bot that you could just run that and automate that, like, absolutely. And so you do have a situation whereby it's also, allowing those analysts or IT admins to focus on much more important things, you know, as opposed to and then also to your point, I think beyond just even just the basic, it helps augment that and better complement a lot of what they do. So I think that's definitely a big one. How about, just what are the solutions, you know, for other leaders who might be watching this too in terms of I know we talked about, some of the work you guys are doing on Connect as well. What are other solutions, you know, that you that you are seeing on the field or it could be even very, successful case studies of, again, companies that have a lot of these coverage gaps and and how they could actually go about, reducing those and and and closing those gaps that maybe that SEVY has that they're using on the market too? Yeah. You know, you know, one of the dynamics that I think is worth calling out is, you know, sometimes when we start working with the identity teams and we mention our solution, the the the conversation tends to really be focused on legacy on premise applications. I I would say that's where a lot of the time the mind goes to. It's like, well, like, I really only have this, with that domain of of applications. But one of the things that we've started to see as we work with, even companies that I I would say are more digitally native, meaning that they tend to be companies that were built sometime in the last ten years, is they also have this provisioning, permissioning, deprovisioning problem with SaaS based applications. And, you know, one of the things that we do internally is every year to year and a half, we work with folks like yourselves to to create a list of the top ten thousand applications used across the enterprise. And then we exhaustively go identify how many of them support SCIM, how many of them support APIs to be able to carry out these, flows programmatically. And one of the things that we saw that you you saw on a slide a few, few slides ago is that ninety three percent of the top ten thousand applications do not support a programmatic way to be able to handle this joiner mover lever flows, and a good majority of them are SaaS applications. And so it's a long winded answer to your question, but I I I think the key takeaway there is this is not just a problem with legacy applications, whether they're on premise or what have you. It's something that actually spans all genre of of applications. And so we've we've been able to help our customers with all all manner of applications, again, whether they're browser based, SaaS based, on premise, banking mainframe, green screen terminals, mobile based. We do a fair amount of work in the Asia Asia Pacific region. And so that's what's necessary if you really wanna be able to close that coverage gap. You need to work everywhere that your application owners are working. And guess what? It's not always a very clean browser based experience. Sometimes it's it's, you know, a point of sale system, for example. And so that's one of the key things that we've developed to be able to meet the customer and the application owner, wherever, wherever they might be. And, you know, maybe kinda posing that question back to you in in a form, I'm curious as as you've met with well established companies, digitally native companies, what what do you see in terms of what the mix is of on premise applications, SaaS based applications? Do you see customers kinda having that moment of, hey. I I actually have this problem across all my applications for all, not just a particular, you know, version of it or or type of it? Absolutely. Yes. Absolutely. I mean, I think to your point, both the on prem and the SaaS, piece are definitely mean, I think definitely you do have a lot of the it could be sometimes on prem, sometimes a lot of your SaaS. But I think what's more fascinating to your point too is just how I think a lot of people think, yes, applications that, yeah, that were viewed, like, last ten years or thereabout much more modern application. I think a lot of people underestimate how much there's still coverage gap for those ones. And I think any any and the whole reason for this being when we think about the infrastructure stack for a lot of your traditional IG or identity governance solutions, they're just they were just never really built to interconnect very well or talk really well with a lot of your modern SaaS applications. And so you still have a situation whereby companies that we need to make that connection, together. And so it's it's definitely one that we do hear about. I do definitely usually, a lot of unmanaged applications in so many cases, companies don't even know of applications that their employees are using, within within the enterprise. And so I think there's still that visibility components of we don't even know the unknown unknown. Right? It's almost like the unknown unknown, and and you need to have this ability to be able to feed data, you know, from s p SSPM tools or CASB logs or whatever to just be able to help you identify a lot of or manage applications beyond just what we already know exists with your normal SaaS based Workday, BAM, HR, SAP, system. So it's definitely one I I do completely resonate with what you're seeing as well. And then I think the last piece here as well is also just around, how we actually go about enhancing just something I hear around is rotating passwords or API tokens on schedule, even for some that you already see. I I think that's another thing too. Or, you know, or how do you enforce MFA, you know, for those existing? So so sometimes, yes, you might already have the applications within your your controls, how do you actually enforce a lot of these joint mover lever process? And I think that's where you find a lot of the cumbersome processes. And I do think there's also a reason why we also need this identity orchestration layer for a lot of your much more modern based applications. So it is absolutely something that I do resonate with you as well, but, on both sides. One question I had for you, maybe if you wanted to help the audience, I I see this in the audience is, how many applications would you guys see today are currently, like, within service integration network? And and, obviously, how fast could you guys support new ones? Because I think another problem enterprises do find is, okay. Now you've helped me discover my existing applications. You really need to help me to enforce a lot of these GML controls or, provisioning, but how fast could you actually support new ones? You know, if they have if they're going through a digital transformation, they they will rapidly bring in. There's this need for continuous discovery. So maybe if you wanted to just share more on that. Absolutely. You know, we've, today, we have a little bit over twenty one hundred, two thousand one hundred, out of the box integrations, that span everything from what you mentioned, password rotation, enabling federated login for non SSO supporting apps to connectors that focus on joiner mover lever flows. So we have a very large ecosystem of out of the box applications. And as we work with partners like Savient, for example, we're able to help really make the existing platform just connect to a much broader ecosystem of of applications. Now at the same time, one of the other things that we realized is, you know, you mentioned you mentioned discovery as a concept quite a bit, and I think it's so critical within this domain Across, you know, our top fifty customers, we've discovered seventeen thousand disconnected applications. And so it's a very large ecosystem of potential applications that are yet to be connected. And and so, you know, when we started looking at those numbers, one of the things we realized is it's not enough to just have a large library of of connectors. You also need to be very fast at creating them. And and so one of the things that we're very good at doing is we can turn around new integrations quite quickly. You know, for on premise connections, that can take up to ten business days. But for, browser based, we're typically looking at a two, sometimes five day a business day turnaround. And so we made it very easy to basically have this workflow now where within three weeks, when you discover the application, we can have that connected. And based on what we've seen, that is the line speed record. That is much faster from what, you know, you might see in in a more typical circumstance. And so we have a a great library of connectors, but I think more importantly, we're also very fast at creating them. And and one of things we're working on is actually opening up that that that ecosystem so that our customers can actually create the connectors themselves. Now, maybe one question on the back of that that was also posed by the audience is how does Cerby deal, with the joiner mover lever flow with orphan accounts? And and so how the the service system operates, in in that case is that, there there are two ways. One, we can be given a service account on the application in question, and then that service account will basically crawl, the application to identify all of the users inside of that application, and then we'll link back every user record found in that application back to the upstream, source of identity truth, whether that's an IDP or or an IGA platform. And so once we've discovered the individual users and link the user records to the upstream identity source of truth, if any action occurs in the IGA platform, we're then able to propagate that action downstream to the previously disconnected application. Now one of the really nice things about this automatic audit, and this was one of the concepts and imperatives that you mentioned, three slides ago, Francis, is that you then start to be able to automate a lot of these manual audit and compliance reviews. If you can automatically crawl crawl the members, listing in the application and then automatically reconcile who's in the downstream application with who's in the IGA platform, you start to discover orphaned accounts. You start to discover maybe users that are over permissioned. And because we can also help with single sign on, you also start to discover users who are permissioned but haven't used the application in quite some time. And so a lot of that really starts with with with that, that discovery piece initially. One one question back to you, Francis. You know, one of the things that we've seen is there's also sometimes inertia around IGA programs, meaning that, users kinda just get used to running manual workflows, and they don't realize, how manual it is and how much time is spent. Are there any strategies that you're seeing could be effective for for customers in terms of, or or, you know, IGA, folks running IGA programs in terms of really understanding just how much manual work is going into, you know, supporting the status quo? Yes. For sure. I will say it obviously depends. It really does depend. But, definitely, I mean, it's it's still a very it's one that hate to say, but sometimes it it's one of the like it's IG, whenever you you mentioned this to to a security leader with CSO, they're just like, oh, they they just have this huge agitation because it's just it's because of the manual process, it's just a huge amount of complexity. And and as we all know, like, a lot of your the firms that these that I speak to, these are usually your largest the largest companies, usually a Fortune five hundred type companies that have these big IGA programs and and and services. But I will say for sure, I mean and this that was what propelled this report was, you know, a big piece of it being around how do we automate as much solutions. I think that's the and that's at least one goal in which we could actually help to reduce a number of the complexities that have been associated. But, yeah, I think the very big one, in terms of solutions that I think has worked for leaders now is how do we use AI now to build rapid connectors? Because, again, the visibility and the discovery and the coverage gap, that one just isn't going anywhere in terms of all of your different systems, workday service now, your HR system, your IG, and a lot of your SaaS applications. How do we actually have the does this integrate their workflow across each of them? And I think that's still it still continues to be one of the biggest, complexities. But you know what? How do we now use a lot of modern, technologies to help you connect us fast? And I do to to continue to cover a lot of these gaps. And I do think that was one emphasis we still continue to give to leaders. And, obviously, I think we really like what you guys are doing there in terms of what you guys are building in terms of building this all recorded base or different types of connectors to to improve that. That's definitely one. I think number two, has to relate to we get we used we have to use the word AI, but, again, we we have the ability of AI to actually help us in terms of risk based access controls or our AI assisted certifications and other solution that we do give it. And so a lot of this might be around using AI to now you could actually build AI models that actually help you with role mining, that could help you around continuous around continuous attestations. You know? Especially, this is more around, like, you know, how do we slash how do how do we actually satisfy auditors' demand in terms of how we're actually providing new reports. So those were modern technologies, if you wanted to call them, as to helping companies solve for these old traditional problems. But, again and most sometimes too, lot of these also comes down to processes internally. You know, what are the types of processes you have in place? Because sometimes technology might not always the it might not always be a lot of the time, you might have broken processes internally as it relates to how maybe your HR systems, your SMI systems, SMIM systems are talking. So those are just some things that, at least right now, we're we're we're giving. So, we we advise that, obviously, any child and nonhuman identity has its own risk and and discoverability challenges and governance controls around that. But have you seen any other successful it could be maybe financial institutions. Maybe maybe give us an example, Bell, within maybe the financial services. This is a very prominent problem we know in that in the industry. It'd be great if you had maybe some examples of, it could be the kinds of applications you guys support with them, but also more importantly, how do you guys what advice is or even successful case studies do you have, of of how they've been able to overcome these challenges in gas? Absolutely. We have a number of, customers in the financial, services fintech space. And, you know, as an aside, one of the interesting things about, the the financial space is, you know, it tends to be a more highly regulated, space. And so you you have, frameworks like, Sarbanes Oxley that actually, place a not restriction, but very strong guidelines on on how you manage access to applications that are within scope of SOX. And so, you know, what we end up seeing is with our credit union customers, regional banks, major banks, you know, private equity type customers is there there are two types of applications that are usually driving most of the friction. One is the the banking mainframes. Right? Mainframes still exist, whether you want them to or not. I I frequently hear our investors say, you know, they were talking about, mainframes dying in the eighties, and they had a banner, sales year in the, the late twenty tens. And so mainframes are are here, and, they they will be sticking around. And so we see a lot around helping automate the join mover lever flow for your banking mainframes, which again take, you know, manifest in a variety of different forms. The other application family that we see a lot within the financial space are all of the reporting portals. Right? When you're in a highly regulated space, you need to, typically report things back up to the government. And, you know, this is this is not a, taking a, a a shot at at the government portals, but they don't support single sign on, and it's often shared identities. And if they are individual identities that users are using to access, the provisioning process sometimes requires picking up the phone and calling, to get someone added or sending an email. And so these are the types of applications that are, you know, that latter case are thrust on top of the financial services, players, and and they kinda have to meet the application where the application is. And so those are some of the common app families that we found, and we've been able to come in and completely one hundred percent automate those workflows that, again, in some cases are involving things like picking up the phone and and and calling the application owner to actually add a user on their end. So that's a little bit of what we've seen. We have another, question here, coming, coming in, from an audience member. Just reading it here. With Servi building its inventory of connectors, do you see yourself getting into the ISPM space? It sounds like you already offer some of these insights. You know, let me maybe answer that from the, Sturby, perspective, and then Francis would love to kinda hear your your your more kind of general, perspective there. You know, we we see ourselves as focusing on that last mile of identity. There are already very strong incumbents who have built, remarkable and very robust policy engines, whether it's in the I s, PM space or other adjacent spaces, SSPM, Francis, you mentioned, you know, SaaS security posture management. And so we, our goal is to partner. Our goal is to go get that struck unstructured previously inaccessible data and make it available, to the systems that our customers have already invested in. Because, again, you know, we don't necessarily see the problem as being the the incumbents. It's the fact that there's just a lot of heterogeneity. There's lot of applications for all. And so we wanna be able to activate that data and put it in a format that is consumable, by the systems that our our customers have already, have already purchased. And so sometimes that may mean that we are generating the insights and then handing it off to the I ISPMs. But we believe that that's a dynamic that works best within existing budgets, existing technology investments. Because, again, you know, we talked a lot about IGA. To some extent, it's also true in the ISPM space. These are large program budgets, and, you know, there's certainly the sunk cost fallacy. But if if you can make what's already been stood up work better and give it more coverage, we find that that's usually a better winning strategy. I'm curious, Francis, what what you've seen more generally in in this space. Oh, man. Def I mean, ice cream is a big topic. And for people who are who who might not be aware about identity security posture management. I think we actually did a report earlier this year. We we did a report around identity and top surface manager, but one of the biggest pieces of that was we spoke to what's happening as it relates to ISPM. And and, obviously, ISPM is definitely one of the biggest conversational point I would definitely say I've maybe had with security leaders. Again, it all comes to this visibility gap. You know? Well, obviously, SEBI helps to do this, especially as it relates to applications, on prem, SaaS applications. But more broadly, I think when we think about a traditional identity stuff for most leaders, your your access management authentication controls, your IGA, and your PAM, and maybe ITDR. Across your broad spectrum of identity solutions, there is still a gap as it relates to seeing all the different identities that does exist and then having some common layer or some common layer that actually integrates everything together. And I think that's what's led to this category of ISV, and it's actually a fairly new area. So it's a big conversation point because there's just so many loopholes around discoverability and visibility as it relates not only just human, but I think nonhuman identities has actually significantly made this much more complex. So number one, ISBM, it's a big theme. It's a big conversation we hear and continues to still be one. But, obviously, as it relates to the likes of WesCEV, I mean, it definitely is something for for you guys to definitely think about, but I think Sebi does a really good job as it relates to doing a lot of that same discoverability as it relates to all of your shadow application that does exist at different. But I do think that one is definitely still a big one because a lot of the time, you you can't secure, protect, or enforce permissions or even understand excessive permissions if you don't know what's happening with those, specific applications. And so definitely see that. But more broadly, yes. I think increasingly, ISBN is a big conversation. I do we recommend that for every leader today to have some type of discovery engine that feeds into your modern IGA program that gives you clean data across everything. But with that, I believe that was the the last question. Francis, I wanna thank you again so much for taking the time out of your I I know super busy schedule to to speak with us and and share all of these wonderful insights. I also want to give thanks and appreciation to the very large audience that joined us today. If you have any questions, please feel free to reach out to either me, bell, bell at survi dot com, b e l at survi dot com, or Francis. Francis, I'll let you share your contact details as well. But I wanted to thank everybody so much for the time, and Francis, especially, thank you as well for the time. No. Thank you very much, Bill, for having me. Thank thank you to, Sebby for hosting this. I think it's a big conversation. I think a lot of companies and enterprises struggle with a number of these. And I think you mentioned this, Bill, early on. You don't have to feel alone if you feel like some of this gap exists with you. And I think the goal here is to, help share different solutions, that are working and provide a framework for leaders there. Please feel free to reach out to any of us. I'm at the software analyst, cyber research at substack dot com, and and you you could find me easily there. And then maybe one last thing I'll just share is a number of resources that we have, as it relates to any of this topic. So, obviously, I did a report around from complexity to control using automation to transform enterprise identity security. It goes through a lot of these concepts, and then I also have, identity and task office management that covered a lot of these discoverability challenges with ISPMN, you could this is a way you could find me for more information. Well, thank you very much, everyone, and, it's a pleasure doing this. Excellent. Thanks again. Thanks all. Thank
Identity governance is not broken. It is incomplete. Traditional IGA and IAM tools govern the apps that speak standards like SAML, OIDC, SCIM, and APIs, but a large share of business apps do not, and those disconnected apps fall outside your coverage. In this on-demand session, Cerby CEO Bel Lepe and independent cybersecurity analyst Francis Odum (SACR) break down how leading teams close that coverage gap by automating identity workflows for disconnected apps, without replacing the IGA they already run.
What is the IGA coverage gap? IGA and IAM platforms manage users well for apps that speak standard protocols. Apps that lack SSO, SCIM, or APIs can't be governed the same way, so they get provisioned and deprovisioned by hand, tracked in tickets and spreadsheets. The result is a coverage gap estimated at 30 to 50 percent of an organization's apps, where access is slow to grant, slow to remove, and hard to audit. That is where orphaned accounts and audit blind spots pile up.
How do you close the coverage gap without replacing your IGA? Cerby extends the IGA and IAM you already run, such as SailPoint, Okta, Entra ID, Ping, Oracle, and ServiceNow, to the apps they can't reach. It plugs into your existing approval and lifecycle flows and performs the last-mile actions on the disconnected app: provisioning and deprovisioning access, rotating credentials, enforcing MFA, and reconciling who has access. Because Cerby reconciles each app's users against your identity source of truth, it surfaces orphaned accounts, over-permissioned users, and dormant access you couldn't see before, and it does this deterministically, using your existing policies, not by replacing your stack.
How fast can new apps be brought under governance? Cerby maintains a large library of out-of-the-box integrations (2,100+) and builds new ones quickly, typically within days for browser-based apps, so a newly identified app can be under governance in weeks rather than quarters.
What the session covers: Bel Lepe and Francis Odum walk through the current state of IGA automation and a practical playbook for closing the coverage gap, automating the joiner-mover-leaver lifecycle for disconnected apps, extending governance and audit to every app, and maturing your IGA strategy without a rip-and-replace.
Presenters
Francis Odum
Chief Cybersecurity Analyst
SACR
Belsasar Lepe
Co-Founder and CEO
Cerby