The images in this article were generated with artificial intelligence. How we publish
Organizations have climbed to a point where identity is no longer a single centralized problem: it has been atomized in thousands of applications, local accounts, machine identities and self-employed agents. This invisible set of activity and access, which can operate outside the radar of the IAM and security equipment, deserves its own name: Dark Matter Identity. Studies and audits of the sector indicate that a substantial fraction - about half in some analyses - of business identity activity can escape central visibility, making that hidden volume a critical operational and compliance risk.
The root of the problem is both technical and organizational. Technically, there are authentication and authorisation routes in inherited applications, ad hoc integrations and service accounts that do not go through central on-boarding. Organisatively, fragmented property - product equipment, application owners, SREs and third parties - creates silos that hinder global vision. The result is a gap between what the CISUS believe they control and the access that really exist: the favorite ground of the sophisticated attackers.

In the face of this challenge, industry is proposing a new operational paradigm: Identity Visibility and Intelligence (IPP) designed as an independent monitoring layer above traditional access and governance controls. Gartner and other analysts have formalized this approach as part of the broader identity framework, raising the need for continuous observability that unifies scattered signals and transforms them into actionable intelligence ( Gartner on IAM).
A credible IVI cannot be limited to accumulating additional account repositories: it must perform three simultaneous functions. First, continuous discovery of human and non-human identities in each relevant system, including applications that never went through formal processes of IAM. Second, act as a identity data platform that standardizes and correlates directories, application records and infrastructure to provide a single source of evidence. Third, deliver Intelligence by advanced analysis and models that turn scattered signals into specific safety decisions.
From the operational point of view, this implies capabilities that have traditionally not been native to IAM tools: automated remediation that closes position deviations as soon as they are detected, real-time signal exchange to allow immediate responses and intention models that help distinguish normal operating behaviors from really risky patterns. In short, the transition is not only towards better visibility, but also towards an understanding and intervention on the perimeter of identity.
Some companies are addressing this need from within the application estate, complementing or even exceeding the API integration dependence with central systems. An approach that has won traction combines dynamic instrumentation and binary analysis to identify authentication logic and authorization embedded in applications, which makes visible what leaves no trace in corporate directories. This method helps to discover custom applications, misdocumented commercial packages and legacy systems that otherwise would remain invisible.
The unification of telemetry that owns applications with IAM logs generates a data layer based on evidence about how identities really behave. In practical audits, this allows for the detection of specific patterns: applications that retain external or consumer domain accounts, excessive access to third parties, and a significant percentage of orphan accounts in legal environments. This evidence shifts the security of assumption to real risk-based verification and prioritization.
The advancement of autonomous IA agents adds a new dimension of complexity: identities that act in a programmatic way and that, without specific controls, can operate with dangerous permits. The governance of these agents requires ensuring the human attribution of actions, recording the chain of custody of each operation, applying contextual guards that assess sensitivity and privileges, and adopting minimum privilege principles based on fair-to-time access, together with automatic mediation mechanisms when risky behaviour is detected.
To turn this vision into practice, security leaders must reorient metrics and administrative contracts. Instead of counting controls deployed (such as IGA licences), it is more effective to measure results: for example, the reduction of the percentage of inactive rights in a specific tax period or to accept Protection-Level Agreements (PLAs) which commit to revoke critical access within defined time limits after the departure of an employee. Invisibility costs audit time and risk; continuous observability converts months of preparation into minutes by automated evidence.

In terms of practical steps, priority should be given to the creation of mixed structures that link operations, application owners, IAM and GRC to break silos; to start audits by machine identities, which are often the most opaque and dangerous; to deploy code-free remediation to close position drift as soon as it is detected; and to use unified telemetry during high-impact events such as acquisitions, to evaluate the identity position before integrating new assets. These measures are applicable both to emerging technologies and to already deployed controls, but require results-oriented organizational and metric commitment.
Uncertainty about who has what access and why it is no longer just a compliance problem: it is an active source of risk that can amplify any incident. The response is not more directories or more manual inventories, but o which combines continuous discovery, behavior data and automatic responses. To obtain a practical guide on these emerging trends and suppliers that seek to resolve it from the application layer, market resources and suppliers can be consulted. Orchid Security and the strategic approach analyses published by the main analysts in the sector.
In short, the call to action for cybersecurity teams is clear: identify the dark matter of their identities, measure results rather than inventories and build an intelligence layer that closes the gap between policy and real behavior. Without that layer, the main door may be closed, but the attackers are already looking for the keys that hang in the dark.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...