Role redesign should usually come first when the role model is messy, duplicated, or poorly mapped to business responsibilities. Certification automation helps with evidence and cadence, but it cannot validate a broken access taxonomy. If the governance model is unclear, automating reviews only makes the noise faster.
Why role redesign usually has to happen before certification automation
When roles are duplicated, overlapping, or tied too loosely to real business responsibilities, the first problem is structural, not procedural. role redesign clarifies what access should exist, who should own it, and which entitlements belong together. That foundation matters because certification automation only scales review activity; it does not fix a weak role taxonomy or a noisy entitlement model.
In practice, teams often discover that access reviews are reporting symptoms of role design problems such as role explosion, entitlement sprawl, or mismatched birthright access. A cleaner role model reduces false positives before reviewers ever see them, which is why role engineering and access certification should be treated as different layers of control rather than interchangeable initiatives. The role model is the control logic; certification is the control cadence.
Role redesign also creates the conditions for meaningful ownership. If a manager cannot tell which access bundle maps to which job function, automated certification becomes a churn loop: reviewers approve what they do not understand, and exception handling grows faster than remediation. A better-designed role model makes later automation more trustworthy because the underlying decisions are already legible.
What certification automation is good at, and where it stops helping
Certification automation is valuable when the organisation already has a reasonably stable access model. It helps standardise evidence collection, set review cadence, route decisions to the right approver, and close the loop on removals. That makes it a force multiplier for access governance, especially where review volume is high or repetitive.
Its limit is important: automation can accelerate governance operations, but it cannot validate whether a role is the right abstraction. If the entitlement catalogue is built on outdated titles, merged responsibilities, or local team conventions, automated campaigns simply move bad structure through the pipeline faster. The result is often faster approvals, not better governance.
This is why mature teams separate “can we run reviews consistently?” from “are we reviewing the right things?” The first is an automation question. The second is a role design and ownership question. If the second is unresolved, the automation programme may still be useful, but it should not be the first investment.
How to sequence the work without stalling governance progress
The practical sequence is usually to redesign the highest-risk role clusters first, then automate certification around that improved model. Start with roles that have obvious duplication, excessive privilege, or unclear business ownership, because those are the places where review outcomes are least reliable. Once the core role structure is cleaner, automation can be used to enforce cadence and evidence capture at scale.
Where the access model is already mostly sound, automation may come first for operational reasons, but only as a limited step. In that case, keep the first automation wave narrow and use it to expose structural defects, not to “solve” them. The point is to avoid locking bad role semantics into a high-speed certification engine.
For teams using Role Mining and Role Design Guide, the useful judgement is that role redesign should precede broad automation whenever the model itself is the source of review noise. And where the organisation needs a governance baseline for reviews, Access Reviews and Certification Guide is the better companion once the structure is stable enough to review meaningfully.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Role redesign and certification both address excessive access and privilege creep. |
| NHI-01 — Improper Offboarding | Certification automation often supports timely access removal and leaver cleanup. | |
| NHI-07 — Long-Lived Secrets | Governance weakness often persists when access persists too long without review. | |
| Recommendation — Redesign roles to remove excess privilege before automating review campaigns. Use automated certification to accelerate removal of stale or unowned access. Pair review cadence with removal of long-lived access paths and credentials. | ||
| CIS Controls v8 | CIS-5 — Account Management | The question concerns how to manage roles, access reviews, and entitlement decisions. |
| CIS-6 — Access Control Management | Role redesign is an access-control design issue, not just a review-automation issue. | |
| Recommendation — Prioritise account and access governance design before scaling automated certification. Define access control structure clearly before automating recertification workflows. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Role governance and certification both depend on accountable account lifecycle management. |
| AC-6 — Least Privilege | Role redesign is needed to align access with job responsibility and reduce excess privilege. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | Certification automation improves evidence collection and review traceability. | |
| Recommendation — Establish clear account ownership and review responsibility before automating recertification. Remove excess access from roles before scaling certification automation. Automate review evidence and escalation paths once the role model is defensible. | ||
Practitioner Guidance
What to prioritise: Fix the role model first if reviewers are consistently debating whether access bundles make sense, because that is a sign the taxonomy is doing too much work. Automate certification after the structure is understandable enough that an approver can make a real decision from the review record.
What to verify: Before expanding automation, verify that every high-volume role has a clear business owner, a defensible entitlement grouping, and a predictable remediation path when access is removed. If reviewers cannot name the business purpose of a role, automation will not improve the quality of the decision.
Common mistake: Treating certification tool rollout as a governance fix. The tool can shorten the cycle, but if the role architecture is broken, you only get faster noise and more rubber-stamping.
Practitioner takeaway: Use role redesign to reduce uncertainty, then use certification automation to scale disciplined decisions; if you reverse that order, you usually automate confusion rather than governance.
Related resources from NHI Mgmt Group
- Should organisations prioritise external exposure or internal credential governance first?
- Should organisations prioritise compliance certification or access evidence first?
- Should organisations prioritise access review or lifecycle automation first?
- Should organisations prioritise transaction governance or access certification first?