Recertification Campaign
A recertification campaign is an organized review in which the right people periodically confirm whether users still need the access they currently have. Managers or resource owners look at each person's permissions and decide to keep or remove them, and those decisions are tracked until the review is complete. It is a governance activity used to keep access rights accurate over time, not a real-time control that grants or blocks access as it happens.
A recertification campaign is a time-bound, structured access review process within identity governance and administration (IGA) in which designated reviewers (typically managers or resource owners) attest whether an identity should retain its assigned access rights and permissions. Campaigns are typically driven by a recertification rule defining the reviewer, scope, and cadence, and may cover a broad set of identities or a defined set of critical resources; per the evidence, the scope can include both users and non-human/AI-agent identities depending on the platform. Each review yields keep or revoke decisions that are tracked through completion, with revocations feeding downstream remediation such as deprovisioning. This is an IGA lifecycle and attestation concern focused on periodic validation of standing access, and it is distinct from runtime enforcement mechanisms (for example PDP/PEP evaluation or token validation) that make access decisions at the moment of a request. Specific workflow behavior, remediation automation, and supported identity types vary by vendor and deployment configuration.
Why it matters
Access rights tend to accumulate over time as people change roles, join projects, or take on temporary responsibilities that are never fully unwound. Without a periodic mechanism to validate standing access, organizations drift toward over-entitlement, where identities retain permissions they no longer need. Recertification campaigns provide the structured, time-bound mechanism to catch and correct this drift by requiring the right reviewers to explicitly confirm whether each identity should keep its access.
Because these campaigns produce documented keep-or-revoke decisions tracked through completion, they also serve as evidence for compliance and audit purposes. Regulators and auditors frequently expect organizations to demonstrate that access to sensitive systems is reviewed on a defined cadence and that inappropriate access is remediated. A well-run campaign creates that audit trail and supports enforcement of governance objectives such as least privilege and segregation of duties, though the campaign itself does not enforce access in real time.
It is important to keep the scope of recertification realistic. A campaign validates standing access as of the review; it is a periodic governance activity, not a runtime control. Access granted or changed between campaign cycles is only caught at the next review unless other controls apply. The value of a campaign therefore depends heavily on cadence, reviewer diligence, and the reliability of downstream remediation, all of which vary by deployment.
Who it's relevant to
Inside Recertification Campaign
Common questions
Answers to the questions practitioners most commonly ask about Recertification Campaign.