Diagram of an access certification campaign showing review, approval and revocation steps
← Back to blog

User Access Reviews: Why Access Certification Fails and How to Fix It

There is a familiar moment in most access certification campaigns. A manager receives 400 entitlements to review, recognizes perhaps thirty of them, and approves everything in under fifteen minutes. The campaign completes. The evidence goes to the auditor. Nothing about the organization’s actual access risk has changed.

The control was performed. It was not exercised. And because the evidence looks identical either way, this can continue for years before anyone notices.

What an access certification is supposed to do

A user access review asks a specific question: does this person still need this access, and can someone who understands the work confirm it?

That framing matters, because it identifies the two ways reviews fail. Either the reviewer does not understand what they are approving, or the review does not result in anything being removed. Both produce clean paperwork.

The regulatory pressure is real — SOX, PCI DSS, HIPAA and most cyber-insurance questionnaires all expect periodic access certification. But the reason to do it properly is more practical. Access accumulates. People change roles and keep what they had. Projects end and their access does not. Without periodic removal, entitlements only ever grow.

The four things that make reviews work

Reviewers who recognize what they are looking at. This is the single biggest determinant. “Reviewer” defaults to line manager, but a line manager often cannot assess application entitlements. Application owners usually can. Splitting campaigns by who genuinely has context — managers for coarse business roles, application owners for technical entitlements — changes outcomes more than any tooling decision.

Entitlements described in business language. A reviewer presented with FIN_GL_JE_POST_02 will approve it. Presented with “post journal entries to the general ledger”, they may not. Translating technical entitlements into plain descriptions is unglamorous work and it is most of the value.

Scope small enough to be real. A campaign covering every entitlement in the estate guarantees rubber-stamping. Risk-based scoping — privileged access, segregation-of-duties conflicts, sensitive data, anything changed since last review — produces smaller campaigns that reviewers actually complete.

Revocation that happens automatically. If a reviewer clicks “revoke” and that generates a ticket someone processes later, a meaningful share never gets processed. The loop has to close in the platform. Reviews that do not remove access are theater.

How the IGA platforms handle certification

Certification is the core of identity governance, and it is where these platforms genuinely differ. We implement across all of them.

Platform Certification approach Best suited to
SailPoint The most mature campaign engine — risk-based scoping, delegation, role mining, extensive audit evidence Large enterprises with complex application landscapes and heavy audit load
Saviynt Cloud-native governance with analytics-driven review and converged application access governance Cloud-first organizations modernizing governance without an on-premises footprint
Microsoft Entra ID Governance Access reviews for Entra groups, roles and applications, often already licensed Microsoft-centric estates proving the control before wider investment
Okta Identity Governance Review workflows tied closely to Okta’s access management and app catalog Organizations already standardized on Okta for workforce access

The pattern here mirrors privileged access: the strongest platform is the one that matches your estate and your capacity to run it. A tier-one governance platform that nobody operates produces worse outcomes than a modest one that runs every quarter.

Running your first campaign

If you are starting from spreadsheets, resist the urge to certify everything.

  1. Pick one high-risk scope. Privileged accounts, or access to one regulated application. Something where removal is obviously valuable.
  2. Identify the right reviewers before the tooling. If you cannot name who understands each entitlement, the campaign will not work regardless of platform.
  3. Translate the entitlements. Plain-language descriptions for everything in scope. This is the work that determines whether reviewers engage.
  4. Close the revocation loop. Confirm that a revoke decision actually removes access, end to end, before the campaign runs.
  5. Measure the revocation rate. A campaign that removes nothing is not a pass — it is a signal that reviewers are not engaging. A healthy first campaign in an environment that has never certified typically removes a meaningful share of what it reviews.

That last metric is the honest test. Auditors increasingly ask not just whether reviews happened, but what changed as a result.

Where this connects

Access certification does not stand alone. It depends on knowing what entitlements exist and what they mean, which is why it usually surfaces gaps in joiner-mover-leaver automation and role design at the same time. Sectors with layered external access — financial services with vendor and broker access, healthcare with clinical rotations and locums — tend to feel this first, because their access changes faster than annual review cycles can track.

It also has the same blind spot as most identity controls: certification campaigns are built around people, and service accounts rarely have an owner willing to attest to them. In most environments they are the largest population of uncertified access.

If your reviews are running but nothing is being removed, that is a diagnosable problem. It is the kind of thing our identity governance work starts by measuring, and what a free identity audit is built to surface.

Ready to close the credential gap?

As a Keeper partner, AppliedIAM deploys and runs Keeper across password management, dark web monitoring, secrets, and privileged access.

Talk to us about Keeper →
← Back to blog