Origin
Anchit, one of our co-founders, has had the same call enough times to predict it. An IT lead describes their environment, mentions the ERP, mentions that it has no REST API and no SCIM endpoint, and waits. The vendor says they'll check on support for that system. Nobody calls back.
The vendor call goes the same way every time.
You describe your environment. You mention the ERP, JD Edwards or SAP Business One or Infor or whichever one you inherited, and you say it has no REST API. No SCIM endpoint. No OAuth flow. It was implemented in 2009 by a consulting firm that doesn't exist anymore, and it runs the core of your operation. A hundred and eighty people log into it every day to do their jobs.
The vendor pauses. "Good question. Let me check on our support for that system and get back to you."
You've had this call three times. You knew the answer before you dialed. You made it anyway, because the problem is still sitting there.
Your company has 400 employees and 180 of them are in the ERP daily: purchasing, production scheduling, finance, operations. When someone joins, the ERP admin builds the account by hand. Username, role, module access, the specific transaction codes they're allowed to run. Twenty minutes of work, and it has to be someone who knows the system well enough not to guess.
When someone leaves, the process runs in reverse. You email the ERP admin. The admin logs in, finds the account, disables it.
Sometimes that happens the day the person leaves. More often it happens when the admin gets to it: after the backlog clears, after they're back from leave, after somebody reminds them. Until then the account is open in the system that controls purchasing approvals, production records and financial transactions.
That's the offboarding process for the system your business runs on. It works on the honor system and a to-do list.
The reason modern governance tools can't help isn't a feature gap. It's an assumption, made early and never revisited.
Every IGA tool built in the last decade was designed for the API economy. It reads account state through a SCIM endpoint or a REST call. It writes changes back the same way. The entire model assumes the application is willing to take instructions from another piece of software.
Your ERP isn't willing, because nobody built it to be. It comes from an era when software talked to people through screens instead of to other software through endpoints. There's no API to call. No webhook to register. There's a login page, a set of menus, and an admin who knows the path through them.
The industry looked at that and made a quiet decision. Smaller market, harder integration work, and the companies buying the product mostly don't run JD Edwards. So they built for the API-connected world and described it as full coverage.
That left a lot of manufacturing, industrial and operations companies with no path to automated governance. Not because those companies failed to modernize on schedule. Because the vendors picked a different market and didn't mention it.
Iden doesn't need the app to cooperate.
Where an application has an API, we use it. Where it doesn't, we operate the app the way your admin does, through a custom automation framework built for that specific system. The same login, the same menus, the same account management screen, the same transaction code assignments. Driven on a schedule and on a trigger instead of when someone finds the email.
So when a termination lands in the HRIS, nothing waits on you to remember the ERP. The account closes that day. The person who left on Friday doesn't still have purchasing rights on Monday.
The honest part: this is the hardest thing we build, and it's the work we spend the most time on per app. Some systems fight it. When one of them does, we tell you that instead of putting the logo on a slide and sorting it out later.
For fifteen years the people running identity in these environments have done it by hand, with careful processes and diligent emails, covering a gap the industry never quite admitted it had left them with.
So when a vendor tells you they'll check on support for your ERP, it's worth knowing what's actually being checked. Not whether it's possible. Whether anyone there wanted to do it.
We'd point it at your ERP and show you what comes back. No deck. Just the product.