Join our Newsletter — 33% off our NHI Course

How should organisations scale access certification across tens of thousands of users without overwhelming reviewers?

Organisations should standardise campaign design, automate routine decisions where policy allows, and reserve human review for exceptions and high-risk access. At enterprise scale, access certification only works when identities, entitlements, and ownership are structured consistently. Without that discipline, reviewers face alert fatigue, inconsistent outcomes, and slow remediation that weakens governance rather than improving it.

Why This Matters for Security Teams

At enterprise scale, access certification stops being a spreadsheet exercise and becomes a governance control over thousands of decisions that can be inconsistent, delayed, or simply ignored. The real risk is not just reviewer fatigue; it is that excessive or stale access remains in place long enough to become the path of least resistance for misuse, lateral movement, or compliance failure. NHI Management Group notes that 97% of NHIs carry excessive privileges, which is why access review discipline matters even when the immediate question is about human users in bulk.

Standards bodies frame this as a least-privilege and access-recertification problem, but the operational issue is scale. A review campaign that asks humans to validate every entitlement equally will eventually produce rubber-stamping, exception overload, and remediation backlog. Current guidance from the OWASP Non-Human Identity Top 10 and NIST SP 800-53 Rev 5 Security and Privacy Controls points toward stronger ownership, periodic review, and least privilege, but the practical challenge is making that review model usable at volume. In practice, many security teams discover access review failures only after audit findings or incident response expose how little of the entitlements were actually being challenged.

How It Works in Practice

Scaling certification requires turning review from a manual inspection task into a structured decision workflow. The first step is to reduce the number of decisions a reviewer must make. Group users by business function, application owner, data sensitivity, and entitlement risk so that reviewers approve or reject access in coherent batches instead of one entitlement at a time. That structure should be backed by authoritative identity data, because bad ownership metadata makes every later control noisy.

Automation should handle routine approvals where policy is clear, while humans focus on exceptions: privileged roles, sensitive data access, Segregation of Duties conflicts, and orphaned or high-risk accounts. This is consistent with the broader NHI governance approach described in the Ultimate Guide to NHIs, which emphasises lifecycle discipline and visibility over ad hoc review. For large campaigns, useful mechanics include:

  • pre-populated reviewer context showing last login, entitlement age, business justification, and owner
  • risk-based sorting so the highest-impact access is reviewed first
  • auto-remediation for no-response cases after a defined grace period
  • delegated review chains for teams that own large application estates
  • clear policy for inherited access, service-linked accounts, and contractor access

Human reviewers should not be asked to infer whether an entitlement is legitimate from a raw permission string. The job is to validate whether access still matches current business need, not to rediscover the IAM model from scratch. NHI Management Group’s research on the Ultimate Guide to NHIs — Key Challenges and Risks shows how poor visibility and weak lifecycle control create exactly the sort of scale problem that overwhelms certification programs. These controls tend to break down when entitlement ownership is ambiguous across federated business units because reviewers cannot confidently decide whether access should stay or go.

Common Variations and Edge Cases

Tighter certification often increases operational overhead, requiring organisations to balance stronger assurance against reviewer capacity and user disruption. That tradeoff is most visible in environments with thousands of entitlements per user, shared platform teams, or nested group-based access where one approval can cascade into many downstream permissions. In those cases, the standard answer of “review everything” is not realistic, and current guidance suggests focusing on control points that actually change risk.

There is no universal standard for this yet, but best practice is evolving toward tiered certification. Low-risk access can be recertified less frequently or through automated policy checks, while privileged, sensitive, or anomalous access receives direct human review. This reduces noise without eliminating accountability. Organisations should also treat dormant accounts, inherited entitlements, and temporary project access as special cases because they tend to generate false confidence if they are bundled into normal campaigns. For a broader risk lens, the 52 NHI Breaches Analysis is a useful reminder that weak identity governance rarely stays contained to one class of account.

Where organisations struggle most is not the review itself but the cleanup. If approvals are collected without timely deprovisioning, certification becomes ceremonial. That is why access review, entitlement expiration, and ownership correction must be treated as one workflow, not three separate ones. High-growth environments with frequent reorgs, mergers, or external workforce churn are the hardest to stabilise because the review baseline shifts faster than the campaign cadence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC-4 Access permissions must be reviewed and adjusted at scale.
OWASP Non-Human Identity Top 10 NHI-01 Certification depends on knowing which identities and entitlements exist.
CSA MAESTRO Large-scale access review needs policy-driven automation and ownership clarity.
NIST AI RMF Risk governance principles apply to deciding what needs human review.

Align review workflows to risk tiers, ownership, and exception handling instead of manual one-by-one approval.