What is identity observability?
ILM Reference editors · Last reviewed September 2026
Identity observability is continuous visibility into how identities actually authenticate and use access across applications, including local accounts and authentication paths that do not pass through the identity provider. It differs from reporting on what the IGA has provisioned: it shows what is happening, not only what was intended.
How is it different from IGA reporting?
IGA reports describe the access the IGA granted in the systems it connects. Observability looks at the applications themselves: which accounts exist, how they log in, and what they can do, whether or not the IGA created them. The gap between the two is where orphan accounts and bypassed controls sit.
What does it look for?
- Accounts that exist in an app but not in the IGA.
- Authentication paths that bypass the IdP.
- Hardcoded or shared credentials.
- Access that grew after a role change.
Which tools describe it?
Orchid Security describes identity activity inside applications that IAM does not log, including shadow authentication paths and local user activity. Veza and Lumos describe continuous access-graph views across integrated systems. Terminology varies by vendor; compare what each one actually inspects.
Sources
Reviewed Sep 2026