Summary
Identity is becoming the security control plane for SaaS, cloud and AI, and the market is repricing it accordingly. But IAM can only govern the applications it already knows about, and most of the modern identity estate never reached the identity provider: user-led SaaS, OAuth grants, service accounts and now AI agents.
- Discovery is layer zero. NIST’s zero-trust guidance catalogs identities and assets before access policy is written, and the identity vendors are moving upstream to the same conclusion.
- It has to be continuous. SaaS is not a static inventory: another application, agent or OAuth grant appears every day.
- A dedicated SaaS discovery platform, Grip Security in the ALPS Portfolio, finds the unfederated estate and hands IAM a prioritized queue, making the identity investment complete rather than competing with it.
Situation
The identity estate has outgrown the identity provider
The enterprise identity estate has outgrown the systems built to manage it. An employee signs up for a SaaS tool with a corporate email. A department connects an AI service to Google Drive. A developer authorizes an OAuth integration. Each one creates a corporate identity in a system the identity provider has never heard of, and none of them needed anyone’s approval.
Meanwhile the market keeps repricing identity security upward: when Okta reported a quarter led by identity governance rather than authentication, the stock moved roughly 27% in a day. Investors are betting that identity is becoming the control plane for SaaS, cloud and AI.
Complication
IAM can only govern what it already knows about
Traditional IAM assumes the organization knows which applications it wants to manage. Integrate the app with Okta or Entra, provision users, enforce SSO and MFA, review access. For the applications it knows about, IAM is extraordinarily powerful.
IAM governs known identities in known systems extremely well. It does not tell you every system in which corporate identities exist.
You cannot enforce MFA on an account you do not know exists, revoke access to an application nobody logged, or review access against an incomplete list. And AI makes the blind spot bigger: agents, OAuth grants and machine identities now hold delegated access to enterprise data while behaving nothing like employee accounts. The breach data says these unmanaged accounts are not a hygiene problem — they are the pattern.
Resolution
Discovery is layer zero
The workable architecture starts one step earlier than most programs assume:
This is not a vendor’s framing. NIST’s zero-trust guidance puts cataloging identities and assets ahead of writing access policy, and the identity vendors themselves are moving upstream — listen to the ordering when Okta’s CEO describes the AI opportunity:
discover agents, secure their connections, govern their actions, and respond when something goes wrong.
Discovery comes first because everything downstream depends on knowing what exists. And because the estate changes every day — another app, another agent, another OAuth grant — discovery has to run continuously, not as a one-time census.
Value Proposition
What SaaS discovery is worth to the enterprise
A dedicated SaaS discovery platform closes the loop. It sees the estate from the identity side, which is why it finds what the identity provider structurally cannot, then hands IAM a risk-ranked queue of what to bring under governance next.
Who should have access to this application?
- Provision and de-provision users
- Enforce SSO, MFA and least privilege
- Run access reviews and lifecycle controls
What do we actually have, and who has identities in it?
- Find user-led and unfederated SaaS
- Surface OAuth grants, tokens and AI agents
- Show which relationships sit outside IAM today
The second question logically precedes the first. Answering it gives you a credible denominator for SSO and MFA coverage, access reviews that hold up to audit, and offboarding that actually finishes — and it makes the IAM investment complete rather than competing with it.
The leading SaaS discovery platform in the ALPS Portfolio is Grip Security: it finds the SaaS that never reached your identity provider, ranks the risk, and prioritizes what to bring into SSO next, with a direct Okta integration. The first question worth putting to your team is not who should have access — it is what percentage of the SaaS estate your identity provider can currently see. The answer is almost always lower than the executive team expects.
Because the identity platform can only govern what it can see. And before identity can be governed, it has to be discovered.
