Origin
Pranay, one of our founders, sat in on the tail end of a security audit at a 600-person company. Everything was clean until the auditor asked one question the team hadn't rehearsed. It took four days and a spreadsheet to answer, and the answer was still incomplete when they filed it.
The question was: can you show me the access state for your former employees across all systems.
All systems. Not the ones in Okta.
They had Okta fully deployed. SSO across every app that supported it, MFA enforced, access reviews run out of the dashboard on schedule. Everything the auditor had asked for up to that point had checked out.
Seventeen former employees had live accounts in applications Okta had never been connected to. Three of those had been open more than six months.
The IT director didn't blame Okta. He blamed himself, for assuming it covered more than it did. That's a generous reading and an accurate one, and it still left him with the finding, the open accounts, and a governance program with a hole he hadn't known to look for.
It happens often enough that it's a pattern, not a story.
A company buys Okta for authentication, which is the right reason to buy it. Okta is genuinely excellent at authentication. SSO works. MFA enrollment is smooth. The integrations for major platforms are well built and well maintained. For the thing it was designed to do, it's about as good as the category gets.
Then something shifts, somewhere between the sales process and the second year of the deployment. The question on the table stops being how do we handle authentication and becomes how do we handle identity. The two words sit close enough together that the distinction collapses. Authentication becomes identity. Identity becomes governance. Okta is already in the room, so it becomes the answer to a question adjacent to the one it answers.
That's not a sales team being slippery. For the apps Okta is connected to, reviews work, provisioning can be automated, offboarding closes accounts. The demo is accurate. The coverage inside it is real.
The gap doesn't appear until somebody asks about everything else.
Authentication and governance are adjacent categories, and the space between them is a design boundary that Okta drew deliberately.
Authentication answers one question at one moment: is this really you, and should you be let in right now. That's the login event, and Okta owns it.
Governance answers a different set of questions in the space between login events. Should this access still exist. Who approved it. Is it still right for the job this person does now, two role changes later. When they left, was every account actually closed, not just the ones that route through SSO but the ones in Veeva, in the analytics tool marketing adopted eight months ago, in the ERP that predates OAuth.
SSO answers whether it's really you. It has never once answered whether you should still have it.
The teams that feel burned aren't usually the ones who found Okta lacking. They're the ones who stopped shopping once it was in place, having reasonably concluded that authentication and SSO added up to identity coverage. They ran reviews in Okta. They reported SSO coverage to their boards. The reporting was accurate as far as it went.
What didn't get reported was the rest of the stack. Roughly a fifth of the average environment sits behind SSO. The other four fifths are tools on standard plans without SCIM, software with no API, apps a team adopted before IT was in the conversation. None of it is visible to a tool that governs what it's connected to.
That's not a gap in Okta. It's a gap in the category, and it gets attributed to the product because the product is the thing with a name on it.
Naming it correctly matters, because the wrong name produces the wrong fix.
Teams that blame Okta sometimes replace Okta, which changes nothing, because the replacement is also an authentication product. Or they buy a point tool for the specific finding that surfaced, which closes one hole and leaves the shape of the problem intact until the next audit finds the next one.
The teams that close it properly hold the two categories apart. Okta handles authentication and SSO for the apps it reaches. Governance handles the whole population: the apps behind SSO, the apps that will never be behind SSO, the service accounts, the tokens. Those are complementary jobs. Iden runs the second one on top of the first, and we assume Okta is staying.
The seventeen accounts got closed. The finding got remediated. The review process got extended to applications outside SSO, which took a while, because nothing in the existing tooling could see them.
They kept Okta. Of course they did.
They just stopped expecting it to do the job it was never built for.
We'd show you where Okta's coverage ends in your environment, app by app. No deck. Just the product.