Blog

IGA Is Only as Complete as the Identities It Can See

August 23, 2026

7 min read

Posted by
Tal Herman
Chief Product Officer
On this page
Getting your Trinity Audio player ready...

Today, Orchid officially joins the SailPoint Technology Alliance Partner ecosystem.

And yes, partnerships are nice. Logos next to each other are nice too.

But this one matters because it attacks a very old identity problem:

You cannot govern an identity you don’t know exists.

IGA has become incredibly good at governing identities once they are known and connected. Lifecycle management. Certifications. Policies. Risk. Access requests. Automation.

The challenging part is everything sitting outside that governed universe.

  • Local accounts buried inside applications.
  • Service accounts nobody remembers creating.
  • Privileged identities living outside the IdP.
  • API credentials and machine identities.
  • Accounts inherited through acquisitions.

And increasingly, AI agents operating with identities, credentials and permissions of their own.

That is the gap we care about at Orchid.

IGA Always had a Coverage Problem

For years, the identity industry has focused heavily on making governance better and smarter.

The future of identity governance starts by illuminating everything we’ve historically left in the dark.

But governance can only operate on what it can see.

If an application has never been onboarded, the identities inside it may never make it into the governance layer at all.

That creates a pretty fundamental problem.

You can have excellent governance over 70% of your identity estate and still have absolutely no idea what is happening in the other 30%.

And unfortunately, attackers do not grade on coverage percentages.

This is where Orchid and SailPoint fit together.

SailPoint provides the governance engine.

Orchid discovers what exists at the application layer and uncovers the identities, accounts, permissions, authentication methods and access relationships that would otherwise remain outside traditional identity controls.

The goal is simple:

Expand the universe that IGA can actually govern.

From Application Discovery to Identity Governance

Applications are where identity gets real.

  1. They contain accounts.
  2. They implement authentication.
  3. They assign roles and permissions.
  4. They store credentials.
  5. They expose APIs.

And sometimes they quietly maintain their own version of identity that nobody in the central IAM team knows about.

Orchid starts there.

We discover applications and analyze how identity actually works inside them.

That means identifying the accounts, roles, authentication patterns and access paths associated with those applications, and then providing the context needed to bring them into governance.

Instead of asking an application owner to reconstruct years of identity decisions through a questionnaire and a few archaeology sessions, we can derive much of that information directly from the application itself.

Very scientific term for this: less guessing.

For SailPoint customers, that means accelerating one of the hardest parts of any IGA program: moving applications and their identities from unknown or unmanaged into the governed environment.

And the Identity Problem Is Getting Bigger

This becomes even more important when we look at where identity is going.

The enterprise identity estate is no longer just employees.

It is employees, contractors, partners, service accounts, workloads, machine identities and AI agents.

And those identities interact with thousands of applications, APIs and services.

AI makes this particularly interesting.

An agent may authenticate using a service account, inherit a user’s permissions, hold API credentials or interact with applications through access paths the security team never modeled.

From the agent’s perspective, these are simply tools available to complete a task.

From an identity perspective, they are access.

And access that cannot be seen cannot be governed.

That is why visibility into the application and identity layer is becoming foundational to IGA.

Better Governance Starts With Better Truth

I have spent enough years in identity to know that most organizations do not need another dashboard telling them they have an identity problem.

They need better ground truth.

  1. What applications actually exist?
  2. What identities exist inside them?
  3. How are those identities authenticating?
  4. What can they access?
  5. Which ones are privileged?
  6. Which ones are active?
  7. And which ones are completely outside the systems that are supposed to govern them?

That is the opportunity behind the Orchid and SailPoint partnership.

Not to create another identity silo.

To connect the application reality with the governance layer.

Discover more identities.
Understand their access.
Bring them under governance.

Because ultimately, IGA is only as complete as the identities it can see.

Till next time,

Tal