6 min read

You Can't Govern
What You Can't Connect

Published On: July 27, 2026
Contents
Contents
keyboard_arrow_down

An IGA maturity model that grades the thing every other model ignores — application connectivity

Your IGA program isn't immature because it lacks features. It's immature because it can't reach your applications — and almost no maturity model on the market grades that directly.

We've spent fifteen years scoring identity programs on capabilities: do you have a governance platform, roles, certifications, a joiner-mover-leaver workflow? Check the boxes, climb the ladder. But you can own every one of those capabilities and still be governing a fraction of your estate, because the platform only governs what it can connect to. The maturity ladder we've been climbing measures the tool. It should be measuring the reach.

The gap the numbers keep pointing at

Start with how few programs are actually mature. SailPoint's 2025 Horizons of Identity Security — a survey of 375 IAM decision-makers — puts 63% of organizations in the lowest two of five maturity stages, and only about 10% in the top two (SailPoint, 2025). Most programs are stuck near the bottom.

Now look at why. Omdia found that at organizations averaging roughly 1,100 applications, only about 54% are adequately integrated with IGA — leaving nearly half the estate outside formal governance, largely because those apps don't speak SAML, OIDC, or SCIM and building connectors is slow and costly (Omdia, via Dark Reading). Different studies put the ungoverned share anywhere from a large minority to a clear majority; the exact number is soft, but the direction never wavers. And it shows up in the failure rate: Gartner reports that over half of IGA deployments are "distressed" — missing their functional, budget, or timing commitments (via CyberArk). The most-cited reason isn't a missing feature. It's that teams are "stuck working manually on some applications" after all the investment.

That's the tell. The bottleneck isn't governance capability. It's connectivity.

Three words that aren't the same thing

Here's the distinction the industry blurs, and the one your maturity model has to make explicit. Between an app existing and an app being managed, there are three separate states:

  • Inventory — you know the application exists. Discovery, an SSO catalog, a CMDB row.
  • Governance — the application is under policy. It has an owner, a certification schedule, an audit expectation.
  • Connectivity — you can actually read and write identity state in it. Pull the accounts, push a deprovision, reconcile entitlements.

Most programs quietly conflate the second and the third. Picture a single application: it has a named owner, it's on the quarterly access review, and it has no API, no SCIM, no connector. Every quarter a reviewer ticks a box next to a list of users — a list someone exported by hand months ago. You can attest to that app all day and change nothing inside it. You've inventoried it and governed it on paper, with zero connectivity underneath. That's not governance. That's attestation theater: you're certifying a spreadsheet someone typed, not the live state of the system. Governance without connectivity is a policy you can't execute. The whole reason the coverage numbers matter is that connectivity is the gate that turns inventory and governance from paper into reality.

The maturity model, graded on reach

So grade the reach. Here's the ladder, with each rung gated not by which features you own but by how much of your application estate you can actually govern.

Level
Name
What it means
Estate under real governance
1
Manual
Lifecycle, reviews, and audit run on spreadsheets and tickets. No roles, no automation.
Ad hoc
2
Automated
Point automation exists — HR-to-AD provisioning, scripts — but no downstream lifecycle or audit controls.
Directory only
3
Governed
You have an IGA platform, core JML, and your handful of critical apps connected. The rest is still manual.
~Core apps (often ~20%)
4
Connected
A real application-onboarding program and tooling exists; coverage is climbing deliberately, not by heroics.
Expanding
5
Complete
Near-full connectivity to your target applications — full lifecycle, visibility, and automation across the environment.
~90%
6
Actionable
Every identity, app, and entitlement is automated and visible, and the program derives intelligence — proactive risk, impact, and compliance across the stack.
Full + intelligence

Two things about this ladder. First, most programs that believe they're "mature" are sitting at Level 3 — platform bought, core apps wired, and a long tail of applications managed by emailing app owners. On a feature checklist they score well. On reach, they've barely started.

Second, that top rung isn't aspirational hand-waving anymore — it has a name. Gartner introduced IVIP — Identity Visibility and Intelligence Platform — on its 2025 Hype Cycle for Digital Identity, defined as the layer that gathers and visualizes identity data across every IAM domain, explicitly complementary to IGA rather than a replacement for it (Gartner, via Veza). Alongside Identity Security Posture Management, IVIP is where "Actionable" lives. But notice the dependency: you can't derive trustworthy intelligence over a 54%-covered estate. Buy the IVIP layer on top of half your applications and you've automated a partial picture. Connectivity is the on-ramp to the categories everyone is now rushing to buy.

Don't re-buy the ceiling

Which brings me to the move most programs make when they realize they're stuck at Level 3: they go shopping for a new IGA platform. Resist it.

The connector gap is architectural to the connector model itself, not to any one vendor's brand. Rip out Platform A, stand up Platform B, and the same applications still lack SAML, OIDC, and SCIM — so you inherit the same ceiling, having paid to re-cross it. And re-crossing is expensive: professional services run well over half of total IGA spend, and the industry's own war stories describe one-year implementations spiraling into two or three (Oleria). SailPoint's data makes the same point from the other side — organizations that clean up their data before migrating are 1.6× more likely to scale effectively (SailPoint, 2025). The lever is the foundation, not the logo.

To be fair, replacement is sometimes the right call. A platform that's genuinely end-of-life, unsupported, or unable to handle your architecture should go. But "we're only governing a third of our apps" is not evidence the platform is wrong — it's evidence the coverage layer is missing. Fix connectivity and data first; then decide whether the platform is actually your constraint. Nine times out of ten, it wasn't.

This is the premise StackBob is built on: extend the IGA you already own to the applications it can't reach — the ones without SCIM, APIs, or connectors — using No-Code Autonomous Provisioning (NCAP™) rather than replacing your stack. IGA platforms govern the apps they can connect to. Something has to govern the rest. The point isn't the tool, though; it's the reframe. Every program hits the connector wall. Maturity is what you do when you get there — climb it, or re-buy it.

The stake

For a decade we've graded identity programs on the capabilities they've purchased. In 2026, grade them on the estate they can actually reach. Inventory tells you what exists. Governance tells you what should be controlled. Only connectivity tells you what you can prove — to an auditor, to a regulator, to yourself.

Score your program on that axis honestly, and most of you will land at Level 3 and call it Level 5. That gap between what you've bought and what you can reach is the real maturity problem. Close the connectivity gap, and the rest of the ladder — visibility, automation, actionable intelligence — is finally standing on something real.

Governing a third of your apps? Let's close the gap.

Talk to the team
arrow_forward