SSO secures the front door but ignores local accounts and AI agents. Learn how attackers exploit these gaps and how Obsidian secures your identity estate.

Single sign-on solved a real problem. A decade ago the average employee had forty passwords, reused most of them, and kept the rest on a sticky note. Offboarding was just a checklist. The IdP collapsed that into one identity, one MFA challenge, one lifecycle. Conditional access at the door. Phishing-resistant auth that works when deployed properly. Whole detection programs got built on the login log, and zero trust as something you could actually do started here.
The IdP makes one decision: at login, is this the right person on an acceptable device? Then it mints a token and stops there. Whatever happens for the next eight hours or thirty days is between the identity and the application, and nobody goes back to ask.
Most of those weren't failed logins. They were valid sessions doing things the IdP never saw: a token stolen post-MFA and replayed from anywhere, a help-desk reset of the exact factor the IdP trusts, an AitM kit that proxied the whole login and walked off with a session. Once inside, the actor does what the real user could do. Export, share, escalate, authorize. The IdP isn't in the path anymore.
Then there's everything the IdP never governed to begin with, which turns out to be most of the estate: local accounts in Salesforce, Snowflake, GitHub, Workday that skip SSO entirely. Service accounts and API keys with no owner, no MFA, no expiry. OAuth grants that outlive password resets and offboarding. Application-level roles the IdP has no idea about; it knows you're an employee, not that you became a Salesforce sysadmin last week. Agents running on identities nobody onboarded as a person.
A control plane continuously decides what's allowed and reconfigures when conditions change. SSO decides once, at the edge, for the identities it knows about.
Frontier AI is exploiting every one of those gaps
For years those gaps were safe because finding them didn't scale. Knowing that a particular Snowflake service account had no IP restriction, or that a departed contractor's Workday local account still worked, or which of 400 OAuth grants had org-wide read, required someone to understand each application's permission model. That expertise was scarce, so attackers went after the front door, and defenders hardened the front door.
Frontier models supply that expertise at machine cost, on every target at once. An adversary can now enumerate the identities your IdP doesn't know about, read what each one unlocks, and chain the low-severity ones into a path. It doesn't need to beat your MFA. It needs one valid token the IdP never issued and a route from there.
And the estate keeps growing outside the directory. Every AI note-taker, meeting assistant, and marketplace agent an employee connects is an OAuth consent screen, and every consent screen is a standing grant that doesn't appear in the IdP, doesn't expire when interest fades, and doesn't disappear when the employee leaves. Adoption is integration. Scope granted is blast radius inherited. Your own agents authenticate once and act ten thousand times across apps, on delegated permissions, steerable by a paragraph of text in a shared doc. The IdP can tell you the token was issued. It can't tell you what the token did. The long tail is now the front line, and almost none of it lives in the inventory.
An engineering manager wires an AI assistant to GitHub, Slack, and Jira on her delegated OAuth grant. She leaves in June. Offboarding disables her IdP account, which is exactly what offboarding is for. The refresh tokens the assistant holds were issued by GitHub and Slack directly. They don't check with the IdP. The assistant keeps running. In September someone files an issue with an injection payload, and the assistant, doing as it's told, posts a private repo's config file into a public Slack channel. Authenticated the whole time as an employee who left three months ago. The IdP logs are spotless.
Swap in a local Salesforce admin without MFA who can authorize a new integration with org-wide read, and the pattern holds: the grant survives IdP suspension, and the IdP was never in a position to know.
The shift was economic, so the answer has to be: make the attacker's paths scarce and the defender's understanding cheap. Obsidian does that at the layer the IdP can't see, inside the applications, for every identity whether or not the directory knows it exists.
Discovery: Obsidian connects to your SaaS and AI estate by API and builds a single, normalized model of every identity, human and non-human, in the IdP and outside it: local accounts, service accounts, API keys, OAuth grants, agents, and the application-level roles each one holds across systems that share no schema. It's time-aware, so it separates what an identity actually used from what it was granted, and it's relationship-aware, so it traces the multi-hop paths between them instead of listing findings. The IdP is one input. Obsidian is the inventory.
Governance: Obsidian drives the estate toward least privilege continuously. It surfaces the admins without MFA the IdP never enforced on, the local accounts that survived offboarding, the dormant tokens, the over-scoped grants, and the users who can authorize new integrations, and it shows you the attack paths a frontier-capable adversary would chain them into. Remove one link and the path is dead. Third-party integrations are scored by vendor, scope, and usage so stale or risky access gets retired before anyone else finds it. The output is a blast radius that shrinks quarter over quarter.
Enforcement: Obsidian's streaming detections watch identity behavior post-authentication across every connected application, baselined per identity, so an agent whose owner left in June, or a local admin authorizing an org-wide integration, is caught at the moment the adversary is learning what it can reach. High-confidence detections trigger containment inside the application: revoke the grant, terminate the session, strip the scope, quarantine the agent. Narrowly and automatically, without waiting for a token to expire on its own. Obsidian watches the IdP itself, because admin changes, new federation trusts, and unusual support-desk actions are the highest-value signal you have and the first thing an attacker tries to quiet.