Okay, I know I'm probably going to start a fight with this one, but I've seen this pattern at three different startups now, including my last gig.
We'd get Okta, and suddenly we're implementing it for *everything* before we even ask a simple question: "Do we *need* universal directory for this app? Does this internal tool *really* need SAML?" The sales process often pushes the full suite (SSO, Universal Directory, MFA, Lifecycle Management), and companies, especially those scaling fast, buy into the vision of a fully integrated identity layer from day one.
The reality I've witnessed? A lot of features go underused. We ended up with:
* **Universal Directory** syncing to apps that only needed basic SSO.
* **Advanced Lifecycle workflows** that were overkill for our sub-100 person team (a simple SCIM sync would've sufficed).
* **Heavy custom SAML apps** for internal tools where a simpler, cheaper OIDC provider could have worked.
The result? A bloated identity bill and a complex setup that new engineers dreaded touching. The irony is, Okta is fantastic for what it does, but its power can be a trap. You start paying for a "just in case" architecture.
I'm curious if others have seen this. Have you successfully used a lighter, more modular approach (maybe a mix of simpler providers) before scaling into Okta? Or am I totally off base here? Let's discuss!
— Cassie
This resonates with the concept of "overfitting" in machine learning. You're buying a model complex enough to handle a 10,000-person enterprise when you're a 100-person startup. The penalty isn't just the financial cost, it's the technical debt and cognitive load of maintaining that complex configuration.
Your point about the sales process driving the "full suite" vision is key. There's a strong tendency to architect for a hypothetical future scale rather than documented current needs. I've seen this lead to teams using Okta as a glorified password manager for a handful of SaaS apps, which is a staggering waste of resources.
A useful exercise is to map every feature you're licensing to a specific, active use case with a quantified benefit. If you can't, it's likely "just in case" architecture, as you said.
prove it with data
The "technical debt and cognitive load" part is spot on, but I'd argue it's worse than that. That overspecified Okta config becomes the single point of failure for half your onboarding and offboarding. So when you inevitably have a junior ops person misconfigure a group rule because the UI is bewildering, it doesn't just cost you time, it locks people out of actual work. You're paying to make your break-glass scenarios more complex.
Your mapping exercise is the correct, boring, adult thing to do. Nobody does it. They see the shiny "scale" button on the sales deck and panic-buy the whole shelf.
Anecdotes aren't data.