That hybrid access layer is the silent killer for cloud-native teams. I've seen two cases in the last year where teams locked themselves out of the vendor console, and their AWS root credentials were useless. The SASE vendor's support had to manually restore a rule set from a backup, which took hours.
I don't know of any vendor that truly integrates your cloud provider's root as a policy reset. The closest I've seen is some allow you to configure an emergency IP-based bypass rule that can be toggled via an API call, which you could theoretically trigger from an AWS Lambda with the right IAM permissions. But that's still a custom integration you have to build and test yourself.
Even if they offered it, you'd have to trust that the vendor's "break-glass" API endpoint itself is resilient to your misconfigured global policies, which creates a circular dependency.
Logs don't lie.
The contractor cost is a real pain point, especially when you're trying to stay lean. I haven't seen a separate SKU for clientless-only access either - you're basically paying for a full identity seat.
It forces some ugly workarounds. I've seen teams share a single "contractor" user account just to avoid buying five seats for a two-week project, which completely defeats the purpose of individual ZTNA. Others just eat the cost and treat it as a tax on flexibility.
That hidden cleanup effort for old AWS security groups is another good catch. It's not just a one-time project. Every time you decommission a resource or change access, you have to remember to go prune those groups, or you end up with a huge list of obsolete rules. The SASE tool won't do that for you.
Try everything, keep what works.
You've nailed the hidden cleanup cost. I've been there, chasing down permissive security groups we'd forgotten about for months after the SASE went live. The real issue is, even if you clean them up, your AWS CloudTrail logs are now full of "SecurityGroupIngress" events from the SASE appliance's IPs, not the original user source. Makes forensic tracing during an incident a two-step process, which defeats the "single pane" promise.
On logging, that's a deal-breaker for any regulated startup. If you can't reconstruct the full session - source IP, user, requested resource, and every hop - you're going to fail an audit. Aggregated summaries are fine for dashboards, useless for compliance.
Sleep is for the weak
That "phase them out gradually" plan is where everyone trips up. It creates a hybrid mess that's impossible to debug.
You either commit and cut over in a weekend, or you don't do it at all. Anything in-between means every connection issue is a coin toss between AWS security groups and the SASE policy.
Simplicity is the ultimate sophistication