Identity Dark Matter: Why IAM Is Losing Sight of Its Own Users
Enterprise identity has fragmented across SaaS sprawl, machine accounts, and agentic systems — leaving a growing slice of activity that centralized IAM cannot see or govern.

Enterprise identity is breaking under its own weight.
The centralized IAM stack — the IdP, the directory, the PAM vault — was built for a world of human employees logging into a finite set of apps. That world is gone. What replaced it is a sprawl of SaaS tenants, cloud workloads, service accounts, API keys, OAuth tokens, and now autonomous agents acting on behalf of users they were never provisioned against.
Practitioners have started calling the gap Identity Dark Matter: identity activity that exists, authenticates, and acts, but sits outside the visibility of the central IAM team.
It is not a small slice. In large organizations, machine identities now outnumber human ones by ratios commonly cited between 45:1 and 80:1. Each of those non-human identities tends to hold long-lived credentials, broad scopes, and no clear owner. When one is abused, the incident-response question is rarely what did it do — it is who was supposed to be watching it.
The fragmentation has structural causes.
Decentralized procurement means business units stand up SaaS apps without routing them through SSO. Developer teams mint service principals in Azure, IAM roles in AWS, and workload identities in GCP at a pace governance cannot match. Mergers carry in shadow directories. And the newest layer — agentic AI systems calling APIs on a user's behalf — collapses the distinction between human and machine identity entirely.
The attack surface follows the sprawl. Initial access brokers have spent the last two years selling exactly this kind of access: stale admin accounts in forgotten SaaS tenants, OAuth grants nobody revoked, CI/CD tokens scraped from public repos. Scattered Spider's intrusions at MGM and Caesars, the Snowflake customer compromises tied to UNC5537, and the Midnight Blizzard breach of Microsoft corporate tenants all share a common thread: the abused identity was technically known to the org, but not actively governed.
The emerging response is a category vendors are labeling Identity Visibility and Intelligence Platforms (IVIP). The pitch is straightforward. Pull identity telemetry from every IdP, SaaS app, cloud provider, PAM tool, and HRIS into one graph. Correlate human, machine, and agent identities to their actual entitlements and activity. Surface the orphaned accounts, the over-permissioned service principals, the standing access nobody uses.
Whether IVIP becomes a durable category or gets absorbed into ITDR and ISPM offerings is an open question. Microsoft, CrowdStrike, and Okta are all moving in adjacent directions.
What is not in question is the underlying problem. You cannot govern what you cannot see, and most enterprises cannot see most of their identities.
For defenders, the practical starting point is unglamorous: inventory non-human identities, kill standing access where workflows allow just-in-time, and instrument SaaS apps that sit outside SSO. The dark matter does not shrink on its own.


