New applications are integrated with the central identity system before deployment
Connecting each new application to the identity provider before staff start using it means access control applies from day one instead of being retrofitted later.
Connecting a new application to the identity provider as a routine step of adoption means it inherits the account lifecycle from day one, matching A.5.16's full-lifecycle scope.
This process control connects every new application to the central identity provider before deployment, a concrete security step A.5.8 expects projects to complete.