Blog · Strategy · 16 August 2026
SSO covers your apps.
Who covers everything else?
Rolling out single sign-on feels like finishing credential security. It is closer to half. The systems that hurt most when leaked, banking, registrars, infrastructure roots, legacy admin panels, mostly cannot ride SSO at all. Here is how to govern the long tail your identity provider cannot see.
The long tail SSO cannot reach
SSO works where the application speaks SAML or OIDC and someone wired it up. Outside that circle live the credentials with the worst blast radius per leak:
- Banking and payment portals, which rarely support federation and often forbid individual accounts.
- The meta-accounts above your identity provider: domain registrar, DNS host, the cloud account your IdP runs in. Lose these and SSO itself is the attacker's tool.
- Legacy and appliance admin panels: firewalls, printers, on-prem tools with one shared admin login.
- Break-glass accounts, deliberately excluded from SSO so you can get in when SSO is down.
- Machine secrets: API keys, tokens, service accounts, the population growing fastest in the AI-agent era.
- Everything a team signed up for with a shared email and never told IT about.
These end up in chat threads, spreadsheets, and personal vaults precisely because the official system has no place for them. That is not a user failure; it is a coverage gap.
Govern the tail with the same three rules
- One inventory. Every non-SSO credential lives in a shared vault with a named owner. If it is not in the vault, it does not officially exist, and the audit for it is nobody's job.
- Access mirrors need, and leaves with the person. Vault roles per team, tied to the same directory identity your SSO uses, so offboarding cuts both worlds at once.
- Every reveal is an event. Reading the bank password should require fresh authentication and land in an append-only log, the same discipline SSO gives your apps, applied to the credentials SSO cannot touch.
The pairing, not the rivalry
This is why a credential vault is the companion to SSO rather than its competitor. Your identity provider governs authentication where federation exists; the vault governs possession where it does not, and rides the same identities so there is still exactly one joiner-leaver process. Keyvaci is built as that companion: sign-in through your Entra ID, vaults for everything Entra ID cannot federate, and a zero-knowledge design so the vault itself never becomes the new single point of leakage.
Close the gap your IdP can see but not fix
14 days, every feature, no credit card. Sign in with company SSO or a plain email address.