Application inventory for identity governance: a short lesson
ILM Reference editors · Published 2026-04-28 · 2 minute read
TRACK: RUNNING THE PROGRAM · LESSON 8 OF 11
An identity lifecycle program is only as complete as its application inventory. The inventory needs every application that holds accounts, including the ones nobody connected to the identity provider, with an owner, a user-store type and a provisioning method for each. Build it from several sources, because no single source lists everything.
Why does the inventory come first?
Joiner, mover and leaver automation, access reviews and orphan clean-up all start from a list of applications. An application missing from that list gets no provisioning, no review and no leaver action, and its accounts stay active after people leave. The first item in a complete lifecycle program is 'an application inventory that includes apps nobody connected.'
Where do applications come from?
| Source | What it finds | What it misses |
|---|---|---|
| Identity provider application catalog | Applications connected for sign-on | Applications with their own login |
| IGA sources and connectors | Applications the IGA provisions or reads | Applications nobody onboarded |
| Procurement and expense records | Paid SaaS and licensed software | Free tools, internal and legacy apps |
| Configuration management database | Registered internal systems | Anything never registered |
| Application owner self-registration | Apps owners choose to declare | Apps whose owners do not know the process |
| Discovery tools | Applications found by observation | Depends on what the tool can observe |
Vendors approach the problem differently. Orchid Security states that it discovers SaaS, cloud, on-prem, legacy and custom-built applications automatically. C1 monitors shadow app signups and logins to decide whether to bring an app under governance. Lumos says identity analytics surfaces shadow IT. SailPoint Identity Security Cloud offers application owners a self-registration portal through its Application Management add-on.
What should you record for each application?
- Owner: the person who approves access and acts on leavers.
- User store: federated to the identity provider, local accounts only, or both.
- Provisioning method: SCIM, connector, API, file, or manual ticket.
- Audit scope: whether the application is in scope for SOX, DORA or other requirements.
- Account count and the date accounts were last reconciled.
- Leaver action: disable or delete, and who performs it.
The user-store field matters most. An application that supports single sign-on but also keeps local accounts is partly connected: sign-on is governed, local accounts are not.
How do you keep it current?
Treat the inventory as a register with a review date, not a one-time spreadsheet. Re-run the sources before each certification campaign, add new applications as they appear in procurement or discovery, and retire applications only after their accounts are removed. Mergers and acquisitions are the moment an inventory is least reliable, which is why Orchid lists M&A and growth events among its use cases.
Sources
Reviewed Sep 2026
Next lesson: Account reconciliation
The step that turns an account list into a list of orphans, owners and exceptions.