Integration leads in Melbourne and Sydney still pick identity platforms based on vendor roadmaps and existing SSO licences. They wire up service accounts and API gateways without mapping which jurisdictions will actually hold the records.
Data residency clauses surface in the final contract review. Suddenly the chosen identity provider cannot store session tokens or attribute stores inside approved regions, breaking every downstream authorisation call.
Trust boundaries that looked clean on the whiteboard now require separate identity domains per data zone. Each split adds latency, duplicate directories, and new exception paths that the original access model never priced.
Procurement signs off on the core platform before security architects see the residency matrix. The integration team then spends weeks retrofitting conditional access policies that should have shaped the initial federation design.
Partners in Singapore or India hit the same wall when their service accounts lose visibility into Australian-resident customer data. What started as a single identity fabric fractures into parallel realms with manual sync jobs holding the pieces together.
Go-live dates slip because the security team refuses to certify any flow that crosses the residency line without re-validated assertions. Delivery leads who treated identity as plumbing discover it now owns the critical path.
Next time the same teams run the same process on the next vendor package. They still approve the identity layer before the residency schedule is locked, repeating the exact pattern of rework and cost overrun.