TLDR: Orchid Security has launched an innovative application-centric approach to identity governance, utilizing its Identity-First Security Orchestration platform. This new method extracts identity data directly from application code, aiming to combat “identity dark matter” and significantly improve the speed and accuracy of identity management for enterprises and service providers. The company asserts this will lead to less fragmentation, faster onboarding, and enhanced visibility across the entire application landscape, addressing challenges posed by traditional manual processes and the rise of AI agents.
Orchid Security is transforming the landscape of identity governance with its pioneering application-centric strategy, as unveiled on September 22, 2025. The company’s new Identity-First Security Orchestration platform is designed to pull identity data directly from application code, fundamentally altering how enterprises manage user identities and access across their digital ecosystems. This innovative approach promises to deliver less fragmentation, accelerate onboarding processes, and eliminate blind spots within the application estate.
A core focus of Orchid’s initiative is to confront what it terms “identity dark matter”—the unmanaged applications and credentials that operate outside traditional governance tools. This issue is particularly pressing given that, according to Orchid’s latest snapshot, nearly half of the average enterprise estate is composed of such unmanaged elements. The problem is exacerbated by the emergence of AI agents, which are increasingly bypassing conventional joiner-mover-leaver identity models, creating new security challenges.
Roy Katmor, co-founder and CEO of Orchid Security, articulated the shortcomings of existing methods to ChannelE2E, stating, “Most IGA onboarding starts with questionnaires and interviews. App owners are asked to explain how identities work in their systems, even when they don’t have the full picture or access to the code. It’s slow, manual, and often incomplete despite best efforts. For enterprise customers, this process takes four weeks – at times, longer. We’re changing that paradigm. Instead of asking people, we ask the app. By analyzing the binaries, we see every identity, account, and access path as they actually exist. No guessing. No endless back-and-forth.”
This shift to an application-first model establishes an accurate baseline for governance, significantly reducing friction between application owners and security teams. It also dramatically speeds up the integration of applications into the Identity and Access Management (IAM) stack.
Beyond enterprise benefits, Orchid’s approach offers a distinct advantage for Managed Security Service Providers (MSSPs) and Global System Integrators (GSIs). The platform is positioned as an “Identity Control Plane,” providing these service providers with a unified view of both managed and unmanaged identities across their clients’ application estates, directly from the source. Katmor highlighted the expanded opportunities this creates: “Orchid acts as an Identity Control Plane, giving MSPs and GSIs a single view of both managed and unmanaged identities across the customer’s application estate, direct from the source. That visibility unlocks a range of new services beyond basic hosting and management of IAM tools, including continuous application security assessment, complex identity governance, audit readiness, incident response support, and identity risk management services.”
Also Read:
- New Open-Source Cybersecurity AI Framework Launched to Empower Security Teams
- IBM Unveils Five-Pillar Framework for Responsible Autonomous AI Governance
This enables service providers to delve deeper into the application estate, moving beyond superficial identity coverage to uncover hidden identity dark matter, thereby differentiating their managed identity practices in the market.


