Certification Campaign
A certification campaign is an organized, scheduled review in which designated reviewers confirm that people have the right access to systems and data, and flag or remove access that is no longer appropriate. It is typically time-bound, with a set deadline by which reviewers must complete their decisions. The goal is to keep user access rights accurate and to catch access that shouldn't exist.
A certification campaign is an IGA process that orchestrates access reviews across a defined population of identities, entitlements, roles, or accounts, routing them to designated certifiers who attest to, approve, or revoke the reviewed access. Campaigns are typically time-bound with a configurable deadline (for example, some platforms default to two weeks after creation, per SailPoint documentation), and a single campaign may aggregate multiple individual certifications covering each subject's current permissions. As an IGA lifecycle and attestation concern, certification campaigns support periodic access recertification and can feed downstream remediation (such as deprovisioning) and audit evidence; they are distinct from runtime access enforcement mechanisms (PDP/PEP/PIP, token validation) that make real-time authorization decisions. Specific capabilities, review scoping, escalation behavior, and remediation workflows vary by vendor and deployment configuration.
Why it matters
Access rights tend to accumulate over time. As people change roles, join projects, or take on temporary responsibilities, they gain entitlements that are rarely removed automatically, producing the condition often called privilege creep. Certification campaigns exist to counteract this drift by forcing a periodic, deliberate review in which designated certifiers confirm that each subject's access is still appropriate and revoke what is not. Without such reviews, organizations lose confidence that the access they have granted still matches what people actually need.
Certification campaigns are also central to demonstrating governance to auditors. Because a campaign is time-bound with a defined deadline and produces a record of who reviewed what and what decision they made, it generates audit evidence that access was examined and attested to on a scheduled basis. This attestation trail supports segregation-of-duties objectives and access recertification obligations that many compliance frameworks expect, though the specific controls a campaign satisfies depend on the framework and how the organization scopes its reviews.
The value of a campaign depends heavily on execution. Reviews that are rubber-stamped, routed to certifiers who lack context about the access they are approving, or left incomplete past their deadline can produce a paper trail without genuinely improving access hygiene. The mechanism reduces risk only when reviewers make informed decisions and when revocations actually flow through to remediation.
Who it's relevant to
Inside Certification Campaign
Common questions
Answers to the questions practitioners most commonly ask about Certification Campaign.
