Skip to main content
Category: Governance & Compliance

Certification Campaign

Also known as: Access Certification Campaign, Access Review Campaign
Simply put

A certification campaign is an organized, scheduled review in which designated reviewers confirm that people have the right access to systems and data, and flag or remove access that is no longer appropriate. It is typically time-bound, with a set deadline by which reviewers must complete their decisions. The goal is to keep user access rights accurate and to catch access that shouldn't exist.

Formal definition

A certification campaign is an IGA process that orchestrates access reviews across a defined population of identities, entitlements, roles, or accounts, routing them to designated certifiers who attest to, approve, or revoke the reviewed access. Campaigns are typically time-bound with a configurable deadline (for example, some platforms default to two weeks after creation, per SailPoint documentation), and a single campaign may aggregate multiple individual certifications covering each subject's current permissions. As an IGA lifecycle and attestation concern, certification campaigns support periodic access recertification and can feed downstream remediation (such as deprovisioning) and audit evidence; they are distinct from runtime access enforcement mechanisms (PDP/PEP/PIP, token validation) that make real-time authorization decisions. Specific capabilities, review scoping, escalation behavior, and remediation workflows vary by vendor and deployment configuration.

Why it matters

Access rights tend to accumulate over time. As people change roles, join projects, or take on temporary responsibilities, they gain entitlements that are rarely removed automatically, producing the condition often called privilege creep. Certification campaigns exist to counteract this drift by forcing a periodic, deliberate review in which designated certifiers confirm that each subject's access is still appropriate and revoke what is not. Without such reviews, organizations lose confidence that the access they have granted still matches what people actually need.

Certification campaigns are also central to demonstrating governance to auditors. Because a campaign is time-bound with a defined deadline and produces a record of who reviewed what and what decision they made, it generates audit evidence that access was examined and attested to on a scheduled basis. This attestation trail supports segregation-of-duties objectives and access recertification obligations that many compliance frameworks expect, though the specific controls a campaign satisfies depend on the framework and how the organization scopes its reviews.

The value of a campaign depends heavily on execution. Reviews that are rubber-stamped, routed to certifiers who lack context about the access they are approving, or left incomplete past their deadline can produce a paper trail without genuinely improving access hygiene. The mechanism reduces risk only when reviewers make informed decisions and when revocations actually flow through to remediation.

Who it's relevant to

Identity Governance Leads
Governance leads design campaign scope, cadence, and reviewer assignments, deciding which identities, entitlements, or roles are reviewed and how often. They balance review coverage against reviewer fatigue and are responsible for ensuring campaigns close on time and that revocations are followed through to remediation.
Compliance and Audit Officers
Compliance officers rely on the attestation records a campaign produces as evidence that access was reviewed on a scheduled basis. The time-bound structure and per-item decision trail help demonstrate periodic recertification and support segregation-of-duties objectives, though which specific control requirements are satisfied depends on the applicable framework.
IAM Engineers and Administrators
Engineers configure the campaign platform, including deadlines, escalation rules, review scoping, and the remediation workflows that carry revoke decisions through to deprovisioning. They must understand that this IGA process is separate from runtime enforcement and integrate campaign outcomes with provisioning systems and target directories accordingly.
Business Managers and Application Owners as Certifiers
Managers and resource owners are frequently the designated certifiers who must attest to, approve, or revoke access within the deadline. The accuracy of a campaign depends on their having enough context to make informed decisions rather than approving access by default.

Inside Certification Campaign

Campaign Scope Definition
The set of entitlements, users, roles, or accounts targeted for review in a given cycle. Scope is typically bounded by criteria such as application, organizational unit, risk level, or privileged access, and is an IGA (identity governance and administration) concern rather than a runtime enforcement activity.
Reviewers and Assignment Logic
The designated approvers responsible for attesting to access, commonly line managers, application owners, role owners, or resource owners. Assignment logic maps each item under review to the appropriate reviewer, and in most deployments supports reassignment or delegation.
Review Items and Decisions
The individual access grants presented for attestation, each requiring a decision such as approve, revoke, or (depending on configuration) delegate. Decisions capture whether the reviewed access remains appropriate.
Remediation Workflow
The process that acts on revoke decisions, typically by triggering deprovisioning or an access-removal request. Note that revocation within a certification campaign is a governance decision; the actual removal depends on downstream provisioning integration and does not by itself constitute real-time enforcement.
Timeline and Cadence
The schedule governing the campaign, including start and due dates and recurrence (for example periodic recertification). Cadence is frequently driven by compliance requirements and internal policy.
Segregation of Duties (SoD) Context
Information surfaced to reviewers about toxic combinations or policy conflicts, allowing certification decisions to account for SoD violations. This is a distinct IGA concern layered into the review rather than a runtime access-control check.
Audit Trail and Evidence
The recorded history of who reviewed what, when, and with what decision. This attestation record typically serves as evidence for compliance and audit purposes.

Common questions

Answers to the questions practitioners most commonly ask about Certification Campaign.

Is a certification campaign the same as provisioning or de-provisioning access?
No. A certification campaign is an identity governance and administration (IGA) review process in which designated reviewers attest to whether existing access is still appropriate. It is distinct from provisioning and de-provisioning, which are the acts of granting or removing access. A campaign can produce revocation decisions, but the actual removal of access is typically handled by a downstream provisioning or fulfillment process, not by the certification itself. Certification is a review and attestation activity; provisioning is a lifecycle change activity.
Does completing a certification campaign enforce access decisions in real time?
No. Certification campaigns are an IGA lifecycle concern, not a runtime enforcement mechanism. When a reviewer marks access for revocation, that decision generally becomes a remediation task that must be fulfilled by a separate process, which may take time depending on integration and configuration. Runtime enforcement of what a principal may do at the moment of access is handled by policy enforcement and decision components (such as a PEP and PDP), which operate independently of the periodic review cycle.
How do you decide the scope of a certification campaign?
Scope is typically defined by the risk and compliance objectives driving the review. Common scoping dimensions include specific applications or systems, particular entitlement or role sets, user populations (such as a department or all privileged users), or access flagged by risk criteria. In many deployments, high-risk or privileged access is certified more frequently and with narrower scope, while broad periodic reviews cover a wider population on a longer cadence. Narrower, risk-targeted scoping tends to reduce reviewer fatigue and improve decision quality.
Who should be assigned as reviewers in a certification campaign?
Reviewer assignment depends on the campaign's purpose. Manager-based reviews route each user's access to their line manager, while application-owner or entitlement-owner reviews route access to the person accountable for a specific system or entitlement. Depending on configuration, some campaigns use a combination, or escalate to a secondary reviewer when the primary does not respond. Choosing reviewers who have genuine knowledge of why the access is needed generally improves outcomes over routing everything to a single role that lacks context.
How can segregation of duties (SoD) be addressed within a certification campaign?
Certification campaigns can surface SoD concerns by highlighting combinations of access that violate defined policies, so that reviewers see toxic-combination context during their attestation. However, SoD policy definition and detection are typically maintained as a separate governance function; the campaign consumes those results rather than defining them. Whether flagged conflicts are shown inline, block an approval, or simply generate a follow-up depends on the platform and configuration.
What happens to revocation decisions after a campaign closes?
Revocation decisions generally become remediation or fulfillment tasks handed off to a provisioning process, which may be automated through connectors or completed manually depending on the target system's integration. The time between a decision and actual access removal varies by deployment. Many organizations track closure of these remediation tasks as a separate metric from campaign completion, since a certified decision is not effective until the corresponding access change has actually been applied and, where required, verified.

Common misconceptions

A certification campaign enforces access decisions in real time.
Certification is an IGA lifecycle activity, not runtime enforcement. A revoke decision generates a remediation or deprovisioning action; whether and when access is actually removed depends on downstream provisioning integration and configuration, and is separate from PDP/PEP token-validation enforcement at access time.
Completing a campaign means all reviewed access is verified as correct.
A campaign records reviewer attestations, which reflect reviewer judgment at a point in time. The quality of the outcome depends on reviewer diligence and the context provided; rubber-stamping or bulk approvals can leave inappropriate access in place despite a completed campaign.
Certification campaigns and provisioning are the same governance function.
Provisioning grants or removes access, while certification periodically reviews whether existing access is still appropriate. They are related IGA capabilities but distinct concerns; a campaign typically depends on provisioning to execute remediation but does not itself perform the grant.

Best practices

Scope campaigns by risk, prioritizing privileged, sensitive, or high-impact entitlements rather than attempting to review all access at once, so reviewer attention is focused where it matters most.
Assign review items to the reviewer with the most relevant context (for example application or role owner for entitlement meaning, manager for business justification) and support delegation or reassignment when the default reviewer lacks knowledge.
Surface decision-supporting context such as SoD conflicts, last login or usage data where available, and access descriptions to reduce blind approvals.
Verify that revoke decisions flow into a remediation or deprovisioning workflow and confirm closure, since a certification decision does not remove access on its own.
Set a clear cadence and due dates aligned to compliance and internal policy, and track completion to prevent stalled or incomplete campaigns.
Retain a complete audit trail of reviewers, decisions, timestamps, and remediation outcomes to serve as attestation evidence for auditors.
Promotional banner for the Pentest Readiness checklist download