As reported by BleepingComputer, tenfold has expanded its free Community Edition IGA platform with shared content access reviews and centralized event auditing for organizations under 150 users. While the announcement itself is product-focused, it surfaces a structural problem Shield53 has flagged repeatedly: the identity governance gap between manual administration and enterprise-grade tooling.

Key Takeaway: As reported by BleepingComputer, tenfold has expanded its free Community Edition IGA platform with shared content access reviews and centralized event auditing for organizations under 150 users.

The Mid-Market Identity Blind Spot

Most IGA platforms are built for Fortune 500 environments with dedicated identity teams, complex HR-driven provisioning, and six-figure licensing budgets. Organizations in the 50–500 user range are left with a broken choice: tolerate manual access management or stretch an enterprise platform they cannot operate. The result is predictable — stale accounts, accumulated privilege, orphaned access to SaaS apps, and no audit trail when something goes wrong.

This matters because identity remains the dominant attack vector. CrowdStrike, Mandiant, and Verizon's DBIR consistently show that stolen credentials and privilege abuse drive the majority of breaches. An organization that cannot answer "who has access to what, and why?" is operating without a foundational security control — not a nice-to-have governance feature.

Manual governance doesn't scale past a few dozen users. The risk surface grows linearly with headcount; your ability to track it manually does not.

Shared Content Governance Is Underappreciated Risk

The addition of shared content access reviews targets a genuinely underserved area. Microsoft 365, Google Workspace, and similar platforms make external sharing frictionless — which is exactly why it becomes a liability. Files shared with a vendor eighteen months ago, broadly shared links, and inherited permissions on nested folders accumulate invisibly. Threat actors and insider risk both exploit this. Regular review of shared content is not a productivity concern; it is a data loss prevention control that most SMBs completely lack.

Auditing Without Alerting Is Only Half the Story

Centralized event auditing is a meaningful addition, but defenders should recognize its limitations. Audit logs are investigative tools — they help you reconstruct what happened after an incident. They do not proactively detect anomalous behavior. Without correlation rules, alerting on suspicious patterns (impossible travel, mass access changes, privilege escalation), audit data sits unused until a breach forces someone to look. If you deploy any IGA platform with auditing, pair it with active monitoring or risk accepting that the logs exist for forensics only.

Shield53 Recommendations

Auditing Without Alerting Is Only Half the Story
Assess your current state first. If you cannot produce a report of who has access to your finance shared drive or M365 environment within one business day, you have a governance gap that needs addressing — regardless of which tool you choose.
Prioritize access reviews over provisioning automation if resources are constrained. De-provisioning and privilege right-sizing reduce risk faster than onboarding speed improvements.
Enable and review shared link settings in Microsoft 365 and Google Workspace admin centers — specifically anonymous links and link expiry — independent of any IGA tool.
Forward identity audit logs to your SIEM or a free tier like Microsoft Sentinel's first 5GB/month if available. Untested audit trails provide false assurance.
Evaluate free and low-cost IGA options — tenfold CE, open-source tools like Keycloak for basic federation, or Microsoft Entra ID Governance features included in existing licensing — before assuming enterprise pricing is the only path.
Document your identity lifecycle: onboarding, role changes, terminations. If this process lives only in an admin's head, it is a single point of failure for both security and operations.

The broader industry implication is straightforward: vendors that lower the IGA barrier for smaller organizations force incumbents to justify their pricing and complexity. That pressure benefits defenders. But tooling alone never closed an identity gap — process discipline does. Evaluate solutions, including this one, against your actual workflow rather than feature checklists.