Ask where your organization’s perimeter is and you will get different answers from different teams. The network team points at the firewall. The facilities team points at the front door. The cloud team explains that the perimeter is dead. All three answers miss the structural change that has already happened: the perimeter did not disappear, it moved into the identity layer.
One directory, many doors
Consider what a single corporate identity now unlocks. The same account that opens email typically federates into cloud platforms, code repositories, HR systems, and finance tools. In a growing number of organizations, it also opens doors: badge platforms, visitor-management systems, and building automation increasingly authenticate against the same directory, or against a physical-access system provisioned and deprovisioned by it.
That consolidation was rational. Managing one identity is cheaper and more auditable than managing five. But it also means the blast radius of a compromised identity is no longer confined to one domain. An attacker who controls an account does not just read email. Depending on entitlements, they can reach the cloud consoles that run operations, the remote-access paths vendors use, and in converged environments, the systems that decide whether a door opens.
The accounts nobody watches
Human identities are only part of the surface. Service accounts, machine identities, API keys, and integration credentials now outnumber people in most enterprises, and they age badly. They are created for a project and never retired. They hold standing privilege because rotating them is inconvenient. They authenticate building controllers, camera platforms, and industrial systems to the network, often with credentials that predate the current security team.
These identities rarely appear in the access reviews that satisfy auditors, because access reviews were designed around people. Yet in converged environments they are frequently the most direct path between the digital and physical estate: the integration account that lets the badge system talk to the directory is, functionally, a key to both.
Where the model breaks
Most organizations still govern these dependencies in fragments. IT owns the directory. Facilities owns the badge platform. A vendor owns the building-management system. Procurement owns the third-party access agreement. Each does its job. Nobody owns the path that runs through all four.
Attackers do not respect that division of labor; they specialize in it. The practical question for leadership is not whether each system is individually defended, but whether anyone in the organization can name the paths that connect them, and whether anyone has the authority to close the ones that should not exist.
What leadership should ask
Three questions expose most of the gap. First: which identities, human or machine, can affect both digital systems and physical environments, and who reviews them? Second: when someone leaves, or a vendor contract ends, how many systems must independently deprovision them, and how would you know if one failed? Third: if your identity provider were compromised this afternoon, what could the attacker physically reach by morning?
If those questions cannot be answered from existing reporting, the issue is not a missing tool. It is that identity has become a control plane without becoming anyone’s responsibility. Treating it as one system, with one owner, one review discipline, and one map of what it touches, is the highest-leverage security decision most converged enterprises have available to them.