Join our Newsletter — 33% off our NHI Course

How do user-based reviews compare with application-based and group-based certifications?

User-based reviews answer a person-shaped question, while application-based and group-based certifications answer system-shaped questions. Use application or group reviews for continuous hygiene across an app or group population. Use user-based reviews for defined, often time-boxed populations such as a project team, contractor cohort, or security-flagged user when you need one review to show everything that person can access.

Why This Matters for Security Teams

User-based reviews, application-based certifications, and group-based certifications are often treated as interchangeable access recertification tasks, but they answer different governance questions. A user review asks whether one person should still hold a bundle of access across systems. An application review asks whether the application’s current entitlement model still reflects business need. A group review checks whether a shared access cohort, such as a role or team, is still valid.

That distinction matters because most access drift shows up in systems, not in isolated users. When teams use the wrong certification type, they either miss systemic excess access or create review fatigue by forcing managers to validate technical entitlements they cannot judge. Current guidance from the NIST Cybersecurity Framework 2.0 supports governance that is proportional to asset and access risk, rather than one-size-fits-all review cycles.

In NHI environments, the same problem applies to service accounts, API keys, and workloads: the review must match the identity shape. NHIMG notes that only 5.7% of organisations have full visibility into their service accounts in the Ultimate Guide to NHIs — What are Non-Human Identities, which is why review type selection often determines whether excess access is found at all. In practice, many security teams discover review failure only after an audit or incident has already exposed the mismatch.

How It Works in Practice

In operational terms, user-based reviews work best when the question is, “Does this individual still need all of these access rights?” They are useful for contractors, project staff, privileged administrators, and people in time-boxed cohorts where one reviewer can validate the whole picture. Application-based certifications are different: they ask application owners to attest to the entitlements, roles, and interfaces exposed by the system. Group-based certifications sit between the two and are best when a shared access construct, such as an AD group or job role, is the thing actually granting access.

  • User-based reviews are strongest for people-centric decisions, especially when access is temporary or sensitive.
  • Application-based reviews are strongest for entitlement hygiene, ownership clarity, and technical drift inside an app.
  • Group-based reviews are strongest when access is inherited through shared cohorts rather than direct assignments.

Practitioners should map the review target to the source of authority. If a user inherits access through multiple groups, a user review may show the symptoms but not the cause. If an application has hundreds of entitlements, a user review will miss the structural problem. Where identity governance is tied to broader access control objectives, the NIST CSF access governance outcomes are easier to satisfy when certification scope aligns to the control plane being reviewed. The Sisense breach illustrates how weak entitlement oversight can turn a single exposure point into broader access risk.

For NHI and agent-like workloads, the same logic applies to service accounts and tool-linked identities: certification must target the workload, its secrets, and its inherited group paths, not just the human owner. These controls tend to break down when access is highly inherited across nested groups and applications because reviewers cannot reliably trace effective permissions end to end.

Common Variations and Edge Cases

Tighter certification scope often increases review effort, requiring organisations to balance better signal against reviewer fatigue. That tradeoff becomes more pronounced in large enterprises with nested groups, federated applications, and mixed human and non-human access models.

There is no universal standard for when to prefer user, application, or group certification, but current guidance suggests using the smallest review unit that still lets the reviewer make a meaningful decision. A user review is a poor fit for deeply technical entitlements that only an application owner can interpret. A group review is a poor fit when the true risk sits in a user’s accumulation of access across multiple systems. Application reviews can also miss toxic combinations if entitlement inheritance is spread across external directories or partner-managed roles.

For NHI governance, the same edge cases appear with service accounts that belong to shared tool groups, CI/CD identities, and automation accounts that span multiple systems. In those cases, practitioners should combine application- and group-based certifications with workload inventory and secret ownership checks, rather than relying on a single attestation model. That is especially important when an identity can act without a human sitting in the loop, because the effective access path may change faster than a quarterly review can detect.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA Access governance and identity verification fit review scope decisions.
OWASP Non-Human Identity Top 10 NHI-02 Identity lifecycle visibility is needed to review service accounts and group inheritance.
NIST SP 800-63 Identity assurance concepts help distinguish person-shaped from system-shaped reviews.
NIST Zero Trust (SP 800-207) PR.AC-4 Least-privilege and continuous verification support effective access recertification.
NIST AI RMF GOV-1 Governance should define who owns attestation for autonomous or workload identities.

Review access by effective privilege path, then remove inherited permissions that are no longer needed.