How Your HRIS, IdP, IGA and PAM Never See Accounts

Steve Goldberg
Steve Goldberg
Senior Solutions Engineer
August 27, 2026
4 min read
hydden-never-see-accounts-hero.png

Your HRIS says Alice left on Tuesday. IGA disabled her directory account on Thursday and the last access review came back clean. This morning she can still SSH to the jump host with a local account that was never in the vault.

None of those systems are wrong. The HRIS is correctly reporting the termination date it was given. The IdP removed the account's federated authentication. IGA is correctly reporting that the leaver job ran for every application it has a connector to. PAM is correctly reporting that it has no credential for Alice on that host, because nobody ever put one in the vault. And yet the jump host is reporting that the local login still authenticates.

That's four accurate systems, and a live SSH login on a terminated employee that no single system can see.

A source of truth and a record are different

Every system in your environment is built to be authoritative about its own data. HR owns whether Alice still works here. IGA owns the directory account and the applications it can reach. PAM owns what is already in the vault.

Most teams try to make the biggest system the referee. That usually means giving your IdP or IGA the job of holding the whole story. But the IdP only know federated accounts and both PAM and IGA can only report on the applications it has connectors for. So a clean leaver job and a clean access review are dependent on what they're connected to. Asking these individual control if it is right means asking it to grade its own work with its own view of what exists.

The disagreement becomes the finding

Today a gap like Alice's gets discovered by accident, usually months later, by someone running an audit or investigating something unrelated. Access that outlives the person is not a new problem. Using credentials that were issued legitimately and never revoked is catalogued in MITRE ATT&CK as Valid Accounts, one of the most common ways standing access persists. The control that would catch it is a comparison across systems.

When one place holds what every system asserted and when, the disagreement itself becomes a finding you can remediate or route to someone. A clean IGA review is a review of IGA's connector catalog and collection abilities. Meanwhile, if there's no collection, Alices local account on the jump host stays invisible until that same review is checked against the record. The disagreement is a finding you can resolve the day it appears.

Where that leaves the record

Hydden holds the record of what all your sources of truth said, and it is the only place they can be caught disagreeing.

Your systems stay authoritative for their own domains. What a system of record adds is the history of identity changes that spans across all your systems and apps, including your identity security stack. The finding goes back into IGA and PAM, so they disable and vault against a complete set of accounts. If the underlying question is whether your identity data in your existing controls are trustworthy enough to act on, How Do You Know Your Identity Data Is Right? works through how to test it.

To see it against your own systems, schedule a demo.

Frequently asked questions

What is the difference between a source of truth and a system of record?

A source of truth is the authority for a specific fact. HR is the authority on employment status, the IdP is the authority on federated login, IGA is the authority on the accounts and applications it governs, PAM is the authority on what sits in the vault. A system of record holds what every one of those authorities asserted and when, across all of them and over time, including systems they do not reach. Teams that treat the two as synonyms usually believe they already have a record when what they have is several authorities that have never been compared.

Why do the HRIS, IdP, IGA, PAM and the jump host disagree about a terminated employee?

Because each one is reporting a different event accurately. The HRIS reports the termination date it was given, the IdP reports that federated login was removed, IGA reports that the leaver workflow ran for the applications it can see, PAM reports that it has no credential on that host, and the jump host reports that the local account still authenticates. The disagreement lives in the sequence, and no single system holds the sequence.

Can't we just fix this with better deprovisioning or a more complete vault?

Automation helps with the accounts the process already knows about. It does not help with the local Unix account, the SSH key or the mainframe user that was never connected to that person in IGA, and never onboarded to PAM, because neither workflow has a way to know they exist. Complete deprovisioning and complete vaulting both depend on complete correlation first.

How do you catch this kind of gap without another console to check?

By treating the disagreement between systems as a finding rather than as data quality work. When one record holds every system's assertion, a mismatch between the HRIS, the directory and a host IGA and PAM cannot see can be routed the day it appears, into the ticketing or governance tooling a team already uses.

Share
Steve Goldberg

Steve Goldberg

Senior Solutions Engineer

Senior Solutions Engineer at Hydden. Focused on connecting enterprise security teams with the identity visibility they need.

Stay Ahead of Identity Security Threats

Get the latest insights on identity governance, zero trust, and cybersecurity delivered to your inbox.

© 2026 Hydden Inc. All rights reserved.Privacy PolicyTerms of Service