Most IT teams put real, disciplined effort into managing identity at the network level Active Directory governs who can log into a workstation, join the domain, or access shared drives. But walk that same discipline over to the business applications running the actual company the CRM, the analytics platform, the finance and HR tools and it’s common to find something much looser: shared logins, former employees still holding access months after departure, and permissions nobody’s reviewed since the account was created.
That gap matters more than it might seem, because identity has become the primary attack surface. Roughly 80% of breaches now trace back to compromised credentials, not sophisticated technical exploits which means identity management, done properly, is genuinely the first and last line of defense, not just a network administration task (source).
Active Directory was built for a world of workstations, file shares, and on-premises servers. Modern SMBs run a very different footprint: small businesses under 200 employees average around 44 SaaS applications, many of them adopted by individual teams without IT ever formally approving or even knowing about them. That sprawl creates exactly the kind of invisible risk that a well-managed AD environment doesn’t have because AD was never designed to govern access to a CRM, a marketing platform, or a finance tool in the first place.
The offboarding data makes this concrete. In a recent industry survey, more than a third of former employees still had access to company email and work files on personal devices after leaving a gap that almost never shows up in Active Directory audits, because AD offboarding and business-app offboarding are frequently two entirely separate processes, and only one of them tends to get done consistently.
Business app accounts outlive employment. A departing employee’s domain account gets disabled promptly in most organizations but their CRM login, their analytics dashboard access, their shared reporting tool credentials often don’t get revisited at the same time, because no single system connects “this person left” to “revoke access everywhere.”
Shared and generic logins proliferate in business apps. It’s far more common to find a shared “sales@” login into a CRM or a generic admin account into an analytics platform than it is to find shared domain credentials because AD has enforced individual accounts for years, while business apps often haven’t been held to the same standard.
Permission creep goes unnoticed. An employee who moves from sales to operations typically gets a new set of domain group memberships through a formal process. The same employee’s CRM role, analytics access level, and app-specific permissions frequently just… stay whatever they were originally set to, accumulating access they no longer need.
Nobody owns the “who has access to what” question for business apps. IT owns AD. But CRM, analytics, and finance-tool access frequently sits with whichever department manager set it up originally meaning nobody’s actually reviewing it on a recurring basis the way AD group memberships typically are.
The identity governance problem is compounding, not staying flat. A meaningful share of employees now use AI tools and GenAI accounts signed up with personal emails rather than corporate identity unsanctioned but genuinely useful tools that create yet another layer of access nobody in IT has visibility into. And it’s not just human identities: modern integrations and automated workflows increasingly act as their own identities with real data access, extending the governance problem beyond people entirely.
For an SMB, the practical implication is straightforward: identity governance that stops at the AD boundary was already leaving significant risk on the table before AI tools entered the picture, and it’s leaving considerably more now.
1. Inventory what’s actually connected to your identity. Before fixing anything, get an honest list of which business apps CRM, analytics, finance, HR exist, who has access to each, and how that access was originally granted. Most SMBs are surprised by what surfaces here; shadow IT tends to be more extensive than assumed.
2. Centralize authentication where the platform supports it. Where business applications support single sign-on tied back to your existing identity provider, using it turns “did we remember to revoke this person’s CRM access” into a single, automatic action tied to the same offboarding step that already disables their domain account.
3. Automate offboarding across systems, not just AD. This is the highest-leverage fix for the most common gap described above. A workflow that triggers access revocation across connected business apps not just the network the moment an employee’s status changes closes the exact hole that manual, department-by-department offboarding leaves open.
4. Build role-based access into the business applications themselves. Just as AD uses group policies to standardize access by role, CRM and analytics platforms with proper role and permission structures configured deliberately rather than left at whatever was convenient at setup prevent the slow permission creep that accumulates when access changes are handled ad hoc.
5. Review business-app access on a recurring schedule, not just at onboarding/offboarding. A periodic access review quarterly is reasonable for most SMBs catches the permission creep and stale accounts that offboarding processes alone won’t, especially for employees who’ve changed roles internally rather than left the company.
| Finding | Data point |
|---|---|
| Breaches tied to compromised credentials | ~80% |
| Average SaaS apps at small businesses (under 200 employees) | 44 |
| Organizations managing two or more identity providers | 75% |
| Former employees retaining access to company email/files after departure | 1 in 3+ |
| Employees who created GenAI accounts using personal emails | 72% |
Extending identity discipline from the network into business applications is exactly the kind of configuration work that pays off disproportionately relative to its cost it’s rarely a large project, but it closes a gap that’s otherwise invisible until an audit, a breach, or a departing employee’s continued access surfaces it. [Internal link placeholder: link to a relevant ZillTech service page e.g., Zoho user access/role automation or CRM security configuration. Please confirm the exact page URL.]
Isn’t this really an IT security problem, not a business application problem? It’s both, and that’s precisely the issue most organizations treat it as purely an IT/network problem, which is why business-app access frequently falls outside the same governance rigor applied to Active Directory.
Do we need a full identity governance platform to fix this? Not necessarily, especially for a smaller SMB. The highest-impact first steps centralizing SSO where supported, automating cross-system offboarding, and running periodic access reviews deliver most of the risk reduction without requiring a dedicated IAM platform from day one.
How do we even know what SaaS apps are connected to our identity right now? An honest inventory is the necessary first step, and it typically surfaces more shadow IT than expected. Reviewing SSO logs, expense reports for software subscriptions, and simply asking department leads what tools their teams actually use all contribute to a more complete picture than IT’s official app list alone.
Is this more urgent now because of AI tools specifically? Yes, meaningfully. AI and GenAI tools are being adopted faster and more informally than typical SaaS apps were, often through personal accounts entirely outside any identity governance which means the gap between “what IT thinks is connected to our identity” and “what actually is” is widening faster than it used to.
Active Directory does its job well but for most SMBs, it’s governing a shrinking share of where actual business data lives and where actual risk sits. Closing the gap between network identity discipline and business application access isn’t a large transformation project; it’s a deliberate extension of practices IT teams already know how to run, applied to the systems that increasingly matter most.