Five Steps to Enabling an Agentic WorkforceGet the White Paper →

What is access certification? Access reviews explained

Access certification is the periodic attestation process in which managers and application owners confirm that assigned entitlements remain appropriate, creating an audit trail when access is approved, rejected, or revoked.

Access reviews are the operational campaigns that execute certification: scoping entitlements, routing tasks, tracking completion, and driving remediation when attestation fails.

Most organizations run some form of review before audits. The difference between checkbox theater and risk reduction is design: scoped campaigns, risk-based prioritization, and enforced revocation when managers say "no."

GuideSeptember 20267 min read

Key Takeaways

Access certification is the periodic attestation process in which managers and application owners confirm that assigned entitlements remain appropriate, creating an audit trail when access is approved, rejected, or revoked.

Access reviews are the operational campaigns that execute certification: scoping entitlements, routing tasks, tracking completion, and driving remediation when attestation fails.

Most organizations run some form of review before audits. The difference between checkbox theater and risk reduction is design: scoped campaigns, risk-based prioritization, and enforced revocation when managers say "no."

For the broader IGA program, see Identity Governance & Administration (IGA): The Complete Guide.

  • Access certification is attestation that standing entitlements should still exist; access reviews are the campaigns that collect those attestations.
  • Managers who approve everything produce audit evidence without risk reduction; scope high-privilege roles first.
  • Micro-certification targets sensitive entitlements on shorter cycles instead of certifying every account annually.
  • Failed attestation requires automated remediation SLAs; reviews without revocation are governance theater.
  • Periodic certification complements continuous ISPM posture; they solve different time horizons.

What is access certification?

Access certification is a governance control in which designated reviewers (typically managers or application owners) formally attest that a user's entitlements remain valid for business need and policy compliance.

Certification produces evidence: who reviewed, what they approved or rejected, and when remediation occurred. Depending on the organization's regulatory obligations and control framework, auditors may require this evidence as part of an access-control review.

Certification is not the same as authentication logging. IAM records that a user signed in. Certification records that a manager confirmed the user should still hold admin rights to Salesforce export.

Decision rule: If you cannot produce reviewer identity and decision timestamp for an entitlement, you cannot certify it for compliance purposes.

What are access reviews?

Access reviews are structured campaigns that operationalize access certification across a defined population of users, roles, or entitlements within a time window.

A typical review cycle includes:

  • Scope definition: which apps, roles, or entitlement types enter the campaign
  • Reviewer assignment: direct manager, application owner, or entitlement owner
  • Task delivery: email, ticketing integration, or IGA work queue
  • Decision capture: approve, revoke, or reassign for each line item
  • Remediation tracking: automated or manual revocation when access is rejected
  • Reporting: completion rates, overdue tasks, and exceptions for GRC dashboards

Access reviews fail when treated as annual spreadsheet dumps. Effective programs prioritize high-risk entitlements and shorten cycles for sensitive access.

Link workforce changes to reviews via Identity Lifecycle Management: Joiner–Mover–Leaver. Lifecycle handles HR events; reviews handle standing access that persists between events.

Why access certification matters

Three reasons drive access certification beyond checkbox compliance.

Orphaned and excessive privilege. Orphaned accounts and stale admin roles accumulate when projects end but entitlements do not. Reviews surface access nobody actively uses.

Audit and regulatory proof. External auditors ask for evidence that access is periodically validated. Certification campaigns generate reviewer attestations tied to specific entitlements and dates.

Manager accountability. Entitlement sprawl is a business problem, not only a security problem. Reviews force line managers to own access decisions for their teams instead of delegating blind approval to IT.

Risk without certificationWhat reviews change
Standing admin after role changeManager attestation catches stale scope
Contractor access past contract endOwner review flags non-employees
SoD violations in role bundlesApplication owner rejects toxic combos
Unknown SaaS entitlementsApp-owner campaigns inventory shadow access

Certify admin and financial entitlements before broad population reviews. Risk-ranked scope beats all-user annual campaigns.

How access certification campaigns work

Campaign design determines whether reviews reduce risk or consume calendar time.

  1. 1.Define scope and risk tier. Prioritize global administrators, financial approvers, customer-data export roles, and other high-risk entitlements. Broader workforce access can follow a cadence and sampling approach based on the organization's risk and compliance requirements.
  2. 2.Select reviewer model. Direct manager attestation works for workforce access. Application owners certify app-specific roles IdP reviews cannot see. High-risk entitlements may require dual approval.
  3. 3.Present context, not raw tables. Reviewers need role description, last login or usage signal, SoD flags, and peer comparison. Raw group membership lists produce rubber-stamp approvals.
  4. 4.Set deadlines and escalations. Overdue tasks escalate to skip-level managers or GRC. Campaigns without escalation die in inbox backlog.
  5. 5.Automate remediation. Rejected entitlements trigger revocation workflows in target systems. Manual follow-up can slow remediation and make it harder to verify that rejected access was actually removed.
  6. 6.Report and iterate. Track completion rate, revocation rate, and recurring offenders. A consistently low revocation rate alongside near-universal approval may indicate that the campaign scope is too broad or reviewers lack sufficient context.

For identity governance and administration (IGA) platform selection, see Best IGA Software & Solutions [2026].

Access certification vs access recertification vs micro-certification

Vendors and auditors use overlapping terms. Operational clarity prevents mismatched expectations.

TermMeaningTypical cadence
Access certificationUmbrella process of attesting entitlementsBased on risk and control requirements
Access recertificationRe-attesting the same entitlement population on a recurring scheduleRecurring schedule based on risk
Micro-certificationNarrow, high-frequency attestation of sensitive entitlements onlyMore frequent reviews of selected high-risk access

Access recertification emphasizes recurrence: the same population is reviewed again on a defined schedule. Micro-certification emphasizes narrower scope and more frequent review of selected high-risk entitlements.

Decision rule: Use micro-certification for selected high-risk entitlements. Set broader recertification schedules according to access risk, applicable controls, and the organization's ability to complete remediation.

Continuous posture tools (ISPM) detect misconfiguration drift between certification cycles. They do not replace manager attestation for business-justified access.

Access certification best practices

  1. 1.Risk-rank before you scale. Start with privileged, financial, and regulated-data entitlements. Expand scope only when remediation SLAs hold.
  2. 2.Give reviewers business context. Role purpose, usage signals, and SoD warnings beat cryptic group names.
  3. 3.Shorten cycles for sensitive access. Review administrative, financial, and other high-risk entitlements more frequently than lower-risk access, based on policy and control requirements.
  4. 4.Automate revocation where possible. Connect rejected attestations to provisioning workflows so access removal can be completed and verified promptly.
  5. 5.Measure outcomes, not just completion. Near-universal approval with little or no revocation may indicate that the campaign is too broad or reviewers lack useful context.
  6. 6.Include non-human identities where owners exist. Service accounts and integration principals need application-owner attestation paths. See NHI security for machine identity context.
  7. 7.Pair periodic reviews with lifecycle automation. Joiner-mover-leaver reduces access gaps when identity status changes; certification addresses standing access between those events.

What percentage of your last campaign produced revocations, not just approvals?

NewCore turns access reviews into action

Access certification fails when reviewers cannot see the full identity environment. An IdP export may capture workforce accounts and groups, but miss entitlements held by service accounts, integrations, and AI agents across SaaS, infrastructure, PAM, and AI systems.

NewCore brings human, machine, and agent access into one identity inventory. Identity Explorer maps identities, accounts, entitlements, owners, applications, and access paths, helping teams scope reviews around actual exposure instead of incomplete system exports.

Visibility is only the first step. Lifecycle governance connects review decisions and identity events to remediation workflows, helping teams right-size or revoke access when an attestation fails or an identity reaches the end of its lifecycle.

Because a completed review is not the same as a reduced risk. Access reviews should remove unnecessary privilege, not simply document that someone looked at it.

FAQ

What is access certification?

Access certification is the process through which authorized reviewers attest that entitlements remain appropriate, creating an audit trail of approvals, rejections, and resulting revocations.

What are access reviews?

Access reviews are the operational campaigns that deliver certification tasks to reviewers, track completion, and drive remediation within a defined scope and timeframe.

What is micro-certification?

Micro-certification is a focused access review that examines selected high-risk entitlements more frequently than broader certification campaigns.

How is access certification different from ISPM?

Access certification uses reviewer attestation to confirm that access remains justified. ISPM provides ongoing discovery and assessment of identity misconfigurations and posture drift. The two practices complement each other.

What is access recertification?

Access recertification is recurring certification of the same entitlement populations on a scheduled cycle, ensuring standing access is revalidated over time.

See NewCorein action.

NewCore is the next-gen IdP for humans and AI agents, built to close the identity gaps this guide covers.

Get new research in your inbox.

White papers and playbooks, sent the moment they're published.