Join our Newsletter — 33% off our NHI Course

How should teams design recertification campaigns when approve or reject is not enough?

Design the campaign around the decisions reviewers actually make, not around a forced binary. If a case needs deferral, exception handling, or extra validation, give it a separate state with one documented follow-up path so governance evidence stays accurate and operational work does not disappear into an approval that was never real.

Why recertification breaks when reviewers need more than yes or no

Recertification is not just a control that asks whether access stays or goes. In real campaigns, reviewers often need to defer a decision, ask for evidence, route a case to an owner, or mark it for exception handling. If the workflow only allows approve or reject, those outcomes get forced into the wrong bucket, which weakens governance evidence and creates hidden operational work.

The design goal is to model the reviewer’s actual decision, not a simplified reporting preference. That means the campaign should represent distinct states for approved, rejected, deferred, under review, exception requested, and any other outcome the process genuinely uses. The state model matters because the workflow history becomes the audit record, the execution record, and the follow-up queue at the same time.

When teams collapse everything into binary approval, they also lose context about why a decision was not final. A reviewer may need more information before deciding, or may be acknowledging a business exception that needs a different control owner. Treating that as approval hides risk; treating it as rejection can create false remediation work.

How to model decisions so governance evidence stays truthful

A good campaign starts by separating decision types from system actions. For example, a reviewer might approve continued access, reject it, defer it pending evidence, or escalate it for compensating control review. The campaign should preserve that distinction so the recorded outcome matches what actually happened, rather than what a binary form could conveniently store.

That separation is especially important where the access item has a follow-up obligation. A deferred item should not simply disappear from the campaign dashboard. It needs one documented path, one owner, and one next state so the case can be measured, aged, and closed without manual detective work later.

Teams should also distinguish between the reviewer’s decision and the enforcement action that follows. A decision to “needs validation” is not the same as a decision to keep access active. Likewise, an exception may justify temporary continuation, but only if the exception record is explicit enough to survive later review and re-approval.

For broader access governance patterns, Access Reviews and Certification Guide covers how campaigns can stay truthful when the review process needs more context than a binary choice can hold. The same logic appears in lifecycle programs, where NHI Lifecycle Management Guide ties review outcomes to provisioning, rotation, and offboarding states instead of letting unresolved cases vanish.

What good campaign design looks like in practice

Campaign design should answer three operational questions clearly: what is the reviewer allowed to decide, what happens to each outcome, and who owns the next step. If those answers are not encoded in the workflow, teams end up using comments, spreadsheets, or side channels to finish the review, which makes the official record unreliable.

Useful implementations usually include case states with explicit aging rules, follow-up tasks for exceptions, and evidence fields for anything that requires validation before final disposition. The important point is not adding complexity for its own sake, but making sure the workflow reflects the real governance process. That usually reduces friction because reviewers stop forcing nuanced cases into an unsuitable approval screen.

Teams should also think about reporting. A campaign that tracks deferred cases separately can show how much of the review load is waiting on evidence, how many items depend on exception approval, and where ownership is unclear. That visibility is more useful than a high approval rate that hides unresolved work.

Use the campaign to close the loop, not just to collect votes. A case that needs extra validation should have a documented path to final disposition, and the workflow should make it easy to see whether that path was completed. IAM and IGA Basics is a useful reference point for the broader governance model behind that design, and Joiner-Mover-Leaver (JML) Guide shows why unresolved states must still resolve into a downstream lifecycle action.

Risk and Threat Considerations

Binary campaigns create two practical risks: governance drift and silent backlog. Governance drift happens when a reviewer’s real intention is “defer until validated” but the system stores “approve,” which makes access look cleaner than it is. Silent backlog happens when unresolved cases sit outside the formal workflow, so no one can tell whether they are waiting on evidence, escalation, or closure.

Failure mechanism: Forced approve/reject choices push ambiguous decisions into the wrong state, which breaks auditability and can leave access active without the intended follow-up control.

Impact: Teams lose trustworthy recertification evidence, exception handling becomes opaque, and access that should have been revisited can remain in place longer than governance intended.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Recertification campaigns govern account status and access decisions.
AC-6 — Least Privilege Deferred or exception cases affect whether access remains appropriately limited.
AU-6 — Audit Record Review, Analysis, and Reporting Campaign state and follow-up paths must preserve trustworthy review evidence.
Recommendation — Track access reviews as governed account disposition actions, not just approvals. Use review outcomes to remove or constrain access that exceeds need. Retain review decisions and exception follow-ups in auditable records.
ISO/IEC 27001:2022 A.5.15 — Access control Review campaigns are an access control governance mechanism.
A.5.18 — Access rights Recertification validates whether access rights should continue, change, or end.
Recommendation — Define campaign states that accurately reflect access-control decisions. Revalidate access rights with explicit follow-up for unresolved cases.

Practitioner Guidance

What to prioritise: Design the state model before designing the campaign content. Decide which outcomes require deferral, exception approval, evidence collection, or escalation, and make those states first-class workflow objects rather than comments.

What to verify: Every non-binary outcome should have a named owner, a next action, and a closure condition. If a case can be paused, the system must still show where it is paused, why it is paused, and what evidence will move it forward.

Common mistake: Treating exceptions as a one-off reviewer note instead of a governed disposition. That shortcut makes the campaign look efficient while pushing the real work into manual follow-up and undermining the record you will later rely on.

Practitioner takeaway: The best recertification campaigns do not force certainty where none exists, they preserve uncertainty as a managed state until the team can resolve it cleanly.