Enterprises do not have a problem proving that access reviews happened. They have a harder problem proving that access remained appropriate between reviews.
If you are a CISO or IAM leader, the question is no longer whether your organization runs quarterly or annual certification campaigns. The question is whether your identity governance can identify inappropriate access when an employee changes roles, accumulates privileges, stops using an application, develops an SoD conflict, or otherwise changes risk — without waiting months for the next campaign.
That is the practical evolution of the access review and certification process. Access reviews remain an essential governance control. But the stronger model combines periodic certification with identity context, risk, lifecycle events, and targeted reviews so that certification becomes a security decision rather than a compliance checkbox.
Access reviews answer a simple question that becomes difficult at scale
At its core, a human identity access review asks:
Does this person still need this access to perform their current responsibilities?
The concept is straightforward. The implementation is not.
An employee may join Finance, move into Procurement, temporarily support a transformation project, receive elevated application access, join multiple groups, and later move into a management role. Every legitimate business event can add or change access.
The problem is that access is much easier to add than to remove.
Over time, employees can accumulate applications, roles, group memberships, and entitlements that were once justified but are no longer required. Microsoft similarly identifies excessive access and employees changing teams or leaving as reasons organizations need regular Microsoft Entra access reviews. Microsoft Learn
A mature access review therefore needs to evaluate more than the existence of an account. It should correlate the identity with its current role, department, manager, applications, entitlements, risk, and business context.
That relationship starts with the identity lifecycle. Joiner, mover, and leaver events should not operate independently from access certification. They provide some of the most important signals for deciding whether access remains appropriate.
The quarterly review creates a governance gap
Consider a simple example.
A quarterly access review is completed on January 1. On January 15, an employee moves from Finance to Procurement. The new Procurement access is provisioned correctly, but two Finance entitlements remain.
If the organization relies exclusively on quarterly certification, those entitlements may remain until April.
Nothing necessarily failed in the quarterly campaign. The campaign may have been completed on time, every reviewer may have responded, and the organization may have excellent audit evidence.
The problem is that the identity changed before the governance process looked again.
NIST's least-privilege guidance requires organizations to review assigned privileges at an organization-defined frequency and reassign or remove privileges where necessary. NIST Publications Periodic reviews therefore remain important.
But from a security perspective, the more useful question is:
How long can inappropriate access remain before the organization detects it?
That is why access governance increasingly needs both periodic and event-driven controls.
More frequent campaigns do not necessarily mean better governance
The obvious response might be to replace quarterly reviews with monthly, weekly, or even continuous campaigns.
That can create another problem: certification fatigue.
Imagine a manager responsible for 40 employees. Each employee has access to 15 applications, with multiple entitlements inside several of those applications.
The manager could face hundreds of individual decisions.
If the review only shows:
Employee: Rahul Sharma
Entitlement: FIN_APPR_L2
Decision: Approve / Revoke
the manager may have little basis for making an informed decision.
The organization has technically presented access for review, but it has not necessarily enabled meaningful certification.
A stronger review would provide context:
Employee: Rahul Sharma
Entitlement: Finance Payment Approver – Level 2
Department: Procurement
Previous Department: Finance
Granted: 14 months ago
Last Used: 97 days ago
Identity Risk: High
SoD Conflict: Yes
Recommendation: Review for revocation
The access is the same.
The quality of the governance decision is completely different.
This is why modern certification should focus less on how many reviews are conducted and more on whether the reviewer has enough information to make the right decision.
The right certifier matters as much as the review itself
One of the weaknesses of traditional certification campaigns is the assumption that one type of reviewer understands every access decision.
That is rarely true.
A manager understands what the employee does.
An application owner understands what the application provides.
An entitlement owner understands what a particular permission allows.
A security or compliance owner understands the risk and control implications.
Microsoft Entra reflects this distinction by supporting different reviewer models depending on the resource, including specified reviewers, managers, group owners, and self-review. Microsoft Learn SailPoint similarly describes certifications in which designated people such as managers or system owners determine whether access remains appropriate. SailPoint Documentation
The correct question is therefore not simply:
Who is the employee's manager?
It is:
Who has enough business and technical context to certify this particular access?
For low-risk application access, the employee's manager may be sufficient. For privileged financial access, the organization may require the manager followed by the application or entitlement owner. For particularly sensitive access, security or compliance may become another level of certification.
This is where multi-level certification becomes valuable: the depth of review can increase with the sensitivity and risk of the access being reviewed.
Access reviews should be risk-driven, not calendar-driven
Not every entitlement deserves the same governance treatment.
Access to an internal collaboration application should not necessarily receive the same review frequency and certification workflow as access that permits someone to modify production infrastructure or approve a high-value financial transaction.
A risk-based model could look like this:
|
Access condition |
Governance response |
|
Low-risk standard access |
Periodic certification |
|
Medium-risk access |
More frequent certification |
|
High-risk entitlement |
Targeted or multi-level review |
|
Privileged access |
Privileged access certification |
|
New SoD conflict |
Immediate review |
|
Department or role change |
Event-driven review |
|
Dormant access |
Review for removal |
|
Temporary access |
Expiry or targeted certification |
This is the distinction between campaign-centric governance and risk-centric governance.
The campaign remains important. But the calendar should not be the only reason an access decision gets revisited.
Identity lifecycle events should trigger governance decisions
Access certification becomes considerably stronger when it is connected to identity risk and lifecycle governance.
Consider a department change.
A traditional lifecycle process may provision access associated with the employee's new department. A stronger governance process should simultaneously ask:
What access did the employee acquire because of the previous role, and should it continue?
The same principle applies to other events:
- manager change
- department change
- designation or role change
- privileged entitlement assignment
- new SoD conflict
- contractor extension
- long period of inactivity
- application ownership change
- unusual change in identity risk
These events do not always justify automatic revocation.
They justify re-evaluation.
That distinction matters because access governance should support the business rather than blindly remove permissions based on a rule.
Certification is more than Approve or Revoke
A well-designed certification campaign involves several responsibilities.
The certifier decides whether access should continue.
A reassigner may redirect a review when the originally assigned reviewer is not the appropriate person to make the decision.
An actioner ensures that the certification decision is actually implemented when remediation cannot be performed automatically.
These roles should not be treated as interchangeable.
Suppose a manager determines that an employee should no longer have access to a legacy financial application. The manager understands the business requirement and selects Revoke.
But the manager may neither have permission nor technical knowledge to remove the account from that application.
The governance decision and the remediation action are therefore separate events.
SailPoint's certification workflow makes a similar distinction: certifiers review and approve or revoke access, after which revoked access is remediated. Its IdentityIQ documentation also supports capabilities such as reassignment or delegation of access reviews. SailPoint Documentation
A defensible workflow should therefore preserve the complete chain:
Access identified → Certifier assigned → Decision made → Reassignment where required → Remediation initiated → Access removed → Evidence retained
That chain becomes particularly important during audits.
Audit evidence should explain the decision, not just prove the campaign happened
A completed campaign is evidence.
It is not necessarily sufficient evidence.
A mature certification record should be able to demonstrate:
- what identity was reviewed
- what access was reviewed
- who was responsible for the decision
- what contextual information was available
- whether the review was reassigned
- what decision was made
- why the decision was made
- when the decision occurred
- whether revocation was required
- who or what performed the remediation
- whether remediation completed successfully
This turns access certification from an administrative exercise into a defensible control.
The objective of audit-ready identity governance should therefore not be to produce a spreadsheet showing thousands of green check marks. It should be to reconstruct the governance decision when an auditor asks:
Why did this user have this access on this date, who approved its continuation, and what evidence supported that decision?
Periodic certification and continuous governance should coexist
Quarterly campaigns should not disappear.
They remain useful for organization-wide certification, regulatory requirements, privileged access reviews, application-owner attestations, and formal audit evidence. Microsoft Entra, for example, supports recurring reviews at frequencies including weekly, monthly, quarterly, and annually, as well as review scenarios around applications, groups, access packages, and privileged roles. Microsoft Learn
The stronger architecture adds another layer.
Periodic certification asks:
Should this access continue at this scheduled point in time?
Event-driven certification asks:
Something important changed. Should this access still continue?
Risk-driven certification asks:
Something about this identity or entitlement has become risky. Does it require human review?
Continuous access governance asks:
Based on everything we currently know about this identity, is this access still appropriate?
These models complement one another.
The goal is not to run campaigns continuously. It is to evaluate access continuously and invoke human certification when human judgment adds value.
Human access reviews are only the starting point
The same governance principle increasingly extends beyond employees.
Modern enterprises contain contractors, administrators, service accounts, machine identities, API identities, workloads, and AI agents.
The fundamental governance question therefore evolves.
Traditional access review:
Does this employee still need this application?
Entitlement-level review:
Does this identity still need this permission?
Modern access governance:
Should this human or non-human identity still have this capability, given its current purpose, ownership, behavior, and risk?
That evolution becomes especially important as organizations expand identity governance beyond human identities.
A service account cannot meaningfully certify itself. An AI agent's manager is not necessarily a traditional people manager. A machine identity may need an application owner or technical sponsor. A secret may need to be reviewed in the context of both the identity that owns it and the workloads consuming it.
The access review model therefore needs to evolve alongside the identity landscape.
What good human access governance should change operationally
The desired outcome is not simply a higher campaign-completion percentage.
It is fewer inappropriate entitlements, shorter periods of excessive access, better reviewer decisions, faster remediation, and stronger evidence.
That means organizations should expect to:
- connect certification with joiner-mover-leaver events
- provide reviewers with business and risk context
- select certifiers based on what is being reviewed
- introduce additional certification levels for sensitive access
- use targeted reviews when risk changes
- distinguish certification decisions from remediation actions
- track reassignment without losing accountability
- automate revocation where appropriate
- retain evidence from decision through remediation
- measure how long inappropriate access survives, not just campaign completion rates
That is a much stronger measure of identity governance maturity.
https://youtube.com/shorts/ksKEwQhxcRc?feature=share
FAQ
Are quarterly access reviews still necessary?
Yes. Quarterly or other periodic reviews remain useful for formal certification, regulatory requirements, and broad access validation. The limitation arises when they are the only mechanism used to identify inappropriate access.
Should organizations move to continuous access reviews?
Not necessarily continuous human reviews. Continuously assessing identity and access risk is more practical. Human review can then be triggered when risk, ownership, role, usage, or another meaningful condition changes.
Who should certify employee access?
It depends on the entitlement. A manager may understand business need, while an application or entitlement owner may better understand what the permission actually allows. Higher-risk access may justify multiple levels of certification.
What is the difference between a certifier and an actioner?
The certifier decides whether access should continue. The actioner implements the resulting remediation when it cannot be performed automatically. Separating the two creates clearer accountability and audit evidence.
Why would an access review need reassignment?
The assigned reviewer may lack sufficient knowledge, may have changed roles, may be unavailable, or may not be the appropriate owner for the entitlement. Reassignment allows the decision to move to the right person while preserving the audit trail.
Does an access review end when the certifier selects Revoke?
No. A revoke decision should result in actual remediation. Governance is complete only when the decision is implemented and the outcome can be demonstrated.
The practical goal is therefore not to eliminate quarterly access reviews. It is to stop treating the quarterly campaign as the entire control.
A modern IGA platform should combine lifecycle context, entitlement information, identity risk, appropriate certifiers, multi-level workflows, reassignment, remediation, and defensible evidence so that access can be challenged when it becomes questionable — not simply when the calendar says it is time.
That is the standard modern access certification should meet.