IDYSSEUSIDENTITY FIRST
PlatformCompanyResourcesRequest a Demo
All insights
FROM THE FOUNDER

The 80/20 Problem: Why Most Enterprises Can't See Their Own Identities

Robert Yu
Robert Yu
Founder & CEO · 5 min read

For over a decade, Identity Governance and Administration (IGA) platforms have relied on a connector-centric onboarding model. The leading vendors depend on proprietary connector frameworks that demand long implementation cycles — often months of professional services and custom engineering for each system brought online.

The deeper problem isn't just the time. These frameworks are built around the vendor's internal data model rather than the reality of the source system, which makes them inherently brittle. When a source changes, the connector breaks, and you're back in the queue for more professional services.

That creates a persistent economic barrier. The cost and effort to build a single connector frequently outweigh the perceived value of the visibility it returns. So enterprises quietly make a rational decision: they onboard the handful of systems that justify the expense, and they leave the rest alone. The result is that most organizations achieve identity visibility across only a narrow fraction of their estate — often less than 20% — while the majority of systems go unmonitored.

A 20% view isn't a minor gap. It produces three serious problems.

The CISO is flying blind on risk. You cannot state your identity assurance level, or the risk tied to it, for systems you can't see. "We govern identity" quietly becomes "we govern identity for the systems that were cheap enough to connect" — and the unmonitored 80% is exactly where unmanaged access accumulates.

Audits become a manual tax. Because the data was never unified, every Quarterly Access Review (QAR) turns into a scavenger hunt. Teams spend hundreds of hours pulling reports from each disparate system by hand, reconciling formats, and assembling evidence that should already exist. The cost recurs every quarter, forever.

Shadow accounts go undetected — and spread. Accounts that no governance system is watching, whether created by mistake or with intent, stay invisible. Worse, they propagate: synchronization carries them into still more systems, so the blind spot doesn't just persist, it grows.

None of this happens because security teams aren't trying. It happens because the connector-centric model makes full visibility economically irrational. When seeing a system costs months and a custom build, "see everything" was never a real option.

That's the assumption worth challenging. If onboarding a source took minutes instead of months — and didn't require custom code or a brittle, vendor-specific connector — the 20% ceiling disappears, and the economics flip. Complete visibility stops being a luxury reserved for your most critical systems and becomes the default.

That's the problem we built Idysseus to solve.

See it on your own data.
Request a Demo
5-day hands-on POC · $100 · your data stays in your environment
IDYSSEUS© 2026 Idysseus. All rights reserved.Privacy · Terms