REGISTER REVISED SEPTEMBER 2026

Application inventory for identity governance: a short lesson

ILM Reference editors · Published 2026-04-28 · 2 minute read

TRACK: RUNNING THE PROGRAM · LESSON 8 OF 11

SUMMARYREV. 2026-09

An identity lifecycle program is only as complete as its application inventory. The inventory needs every application that holds accounts, including the ones nobody connected to the identity provider, with an owner, a user-store type and a provisioning method for each. Build it from several sources, because no single source lists everything.

§ 01

Why does the inventory come first?

Joiner, mover and leaver automation, access reviews and orphan clean-up all start from a list of applications. An application missing from that list gets no provisioning, no review and no leaver action, and its accounts stay active after people leave. The first item in a complete lifecycle program is 'an application inventory that includes apps nobody connected.'

§ 02

Where do applications come from?

Common inventory sources and what each one misses.
SourceWhat it findsWhat it misses
Identity provider application catalogApplications connected for sign-onApplications with their own login
IGA sources and connectorsApplications the IGA provisions or readsApplications nobody onboarded
Procurement and expense recordsPaid SaaS and licensed softwareFree tools, internal and legacy apps
Configuration management databaseRegistered internal systemsAnything never registered
Application owner self-registrationApps owners choose to declareApps whose owners do not know the process
Discovery toolsApplications found by observationDepends on what the tool can observe

Vendors approach the problem differently. Orchid Security states that it discovers SaaS, cloud, on-prem, legacy and custom-built applications automatically. C1 monitors shadow app signups and logins to decide whether to bring an app under governance. Lumos says identity analytics surfaces shadow IT. SailPoint Identity Security Cloud offers application owners a self-registration portal through its Application Management add-on.

§ 03

What should you record for each application?

  • Owner: the person who approves access and acts on leavers.
  • User store: federated to the identity provider, local accounts only, or both.
  • Provisioning method: SCIM, connector, API, file, or manual ticket.
  • Audit scope: whether the application is in scope for SOX, DORA or other requirements.
  • Account count and the date accounts were last reconciled.
  • Leaver action: disable or delete, and who performs it.

The user-store field matters most. An application that supports single sign-on but also keeps local accounts is partly connected: sign-on is governed, local accounts are not.

§ 04

How do you keep it current?

Treat the inventory as a register with a review date, not a one-time spreadsheet. Re-run the sources before each certification campaign, add new applications as they appear in procurement or discovery, and retire applications only after their accounts are removed. Mergers and acquisitions are the moment an inventory is least reliable, which is why Orchid lists M&A and growth events among its use cases.

Sources

Reviewed Sep 2026

NEXT LESSONREV. 2026-09

Next lesson: Account reconciliation

The step that turns an account list into a list of orphans, owners and exceptions.

Related

GUIDEREV. 2026-09
LESSONREV. 2026-09
COMPARISONREV. 2026-09