
An IGA maturity model that grades the thing every other model ignores — application connectivity
Your IGA program isn't immature because it lacks features. It's immature because it can't reach your applications — and almost no maturity model on the market grades that directly.
We've spent fifteen years scoring identity programs on capabilities: do you have a governance platform, roles, certifications, a joiner-mover-leaver workflow? Check the boxes, climb the ladder. But you can own every one of those capabilities and still be governing a fraction of your estate, because the platform only governs what it can connect to. The maturity ladder we've been climbing measures the tool. It should be measuring the reach.
The gap the numbers keep pointing at
Start with how few programs are actually mature. SailPoint's 2025 Horizons of Identity Security — a survey of 375 IAM decision-makers — puts 63% of organizations in the lowest two of five maturity stages, and only about 10% in the top two (SailPoint, 2025). Most programs are stuck near the bottom.
Now look at why. Omdia found that at organizations averaging roughly 1,100 applications, only about 54% are adequately integrated with IGA — leaving nearly half the estate outside formal governance, largely because those apps don't speak SAML, OIDC, or SCIM and building connectors is slow and costly (Omdia, via Dark Reading). Different studies put the ungoverned share anywhere from a large minority to a clear majority; the exact number is soft, but the direction never wavers. And it shows up in the failure rate: Gartner reports that over half of IGA deployments are "distressed" — missing their functional, budget, or timing commitments (via CyberArk). The most-cited reason isn't a missing feature. It's that teams are "stuck working manually on some applications" after all the investment.
That's the tell. The bottleneck isn't governance capability. It's connectivity.
Three words that aren't the same thing
Here's the distinction the industry blurs, and the one your maturity model has to make explicit. Between an app existing and an app being managed, there are three separate states:
- Inventory — you know the application exists. Discovery, an SSO catalog, a CMDB row.
- Governance — the application is under policy. It has an owner, a certification schedule, an audit expectation.
- Connectivity — you can actually read and write identity state in it. Pull the accounts, push a deprovision, reconcile entitlements.
Most programs quietly conflate the second and the third. Picture a single application: it has a named owner, it's on the quarterly access review, and it has no API, no SCIM, no connector. Every quarter a reviewer ticks a box next to a list of users — a list someone exported by hand months ago. You can attest to that app all day and change nothing inside it. You've inventoried it and governed it on paper, with zero connectivity underneath. That's not governance. That's attestation theater: you're certifying a spreadsheet someone typed, not the live state of the system. Governance without connectivity is a policy you can't execute. The whole reason the coverage numbers matter is that connectivity is the gate that turns inventory and governance from paper into reality.
The maturity model, graded on reach
So grade the reach. Here's the ladder, with each rung gated not by which features you own but by how much of your application estate you can actually govern.
Two things about this ladder. First, most programs that believe they're "mature" are sitting at Level 3 — platform bought, core apps wired, and a long tail of applications managed by emailing app owners. On a feature checklist they score well. On reach, they've barely started.
Second, that top rung isn't aspirational hand-waving anymore — it has a name. Gartner introduced IVIP — Identity Visibility and Intelligence Platform — on its 2025 Hype Cycle for Digital Identity, defined as the layer that gathers and visualizes identity data across every IAM domain, explicitly complementary to IGA rather than a replacement for it (Gartner, via Veza). Alongside Identity Security Posture Management, IVIP is where "Actionable" lives. But notice the dependency: you can't derive trustworthy intelligence over a 54%-covered estate. Buy the IVIP layer on top of half your applications and you've automated a partial picture. Connectivity is the on-ramp to the categories everyone is now rushing to buy.
Don't re-buy the ceiling
Which brings me to the move most programs make when they realize they're stuck at Level 3: they go shopping for a new IGA platform. Resist it.
The connector gap is architectural to the connector model itself, not to any one vendor's brand. Rip out Platform A, stand up Platform B, and the same applications still lack SAML, OIDC, and SCIM — so you inherit the same ceiling, having paid to re-cross it. And re-crossing is expensive: professional services run well over half of total IGA spend, and the industry's own war stories describe one-year implementations spiraling into two or three (Oleria). SailPoint's data makes the same point from the other side — organizations that clean up their data before migrating are 1.6× more likely to scale effectively (SailPoint, 2025). The lever is the foundation, not the logo.
To be fair, replacement is sometimes the right call. A platform that's genuinely end-of-life, unsupported, or unable to handle your architecture should go. But "we're only governing a third of our apps" is not evidence the platform is wrong — it's evidence the coverage layer is missing. Fix connectivity and data first; then decide whether the platform is actually your constraint. Nine times out of ten, it wasn't.
This is the premise StackBob is built on: extend the IGA you already own to the applications it can't reach — the ones without SCIM, APIs, or connectors — using No-Code Autonomous Provisioning (NCAP™) rather than replacing your stack. IGA platforms govern the apps they can connect to. Something has to govern the rest. The point isn't the tool, though; it's the reframe. Every program hits the connector wall. Maturity is what you do when you get there — climb it, or re-buy it.
The stake
For a decade we've graded identity programs on the capabilities they've purchased. In 2026, grade them on the estate they can actually reach. Inventory tells you what exists. Governance tells you what should be controlled. Only connectivity tells you what you can prove — to an auditor, to a regulator, to yourself.
Score your program on that axis honestly, and most of you will land at Level 3 and call it Level 5. That gap between what you've bought and what you can reach is the real maturity problem. Close the connectivity gap, and the rest of the ladder — visibility, automation, actionable intelligence — is finally standing on something real.