Join our Newsletter — 33% off our NHI Course

Should organisations prioritise automation or access certification first?

Automation should come first for routine lifecycle changes because certification cannot correct access that should never have been granted or removed late. Reviews still matter, but they work best as a validation layer after provisioning logic has been tightened. The stronger programme sequence is automated issuance and removal, then periodic certification.

Why automation should come before access certification

access certification is a control for validating what exists; it is not a substitute for getting joiner, mover, leaver, role change, and entitlement removal right in the first place. When automation is weak, reviews become a slow cleanup exercise and often miss drift, stale entitlements, and late revocation. Automated lifecycle handling is the control that reduces the amount of bad access that ever reaches review.

That sequencing is why identity programmes usually start with provisioning, deprovisioning, and controlled change flow, then use certification to catch exceptions, outliers, and ownership gaps. A review process without reliable upstream automation tends to produce rubber-stamping, reviewer fatigue, and inconsistent remediation. Tighten the system that creates and removes access first, then use certification to confirm the result.

This is also where role design and entitlement hygiene matter. If the underlying access model is noisy, certification only tells you that the noise exists. IAM and IGA Basics is the right starting point for understanding why lifecycle automation and governance are complementary but not equal in priority.

Where certification still adds value after automation

Certification remains important once automated provisioning and removal are working because it provides governance over business ownership, exception handling, and entitlement accuracy. It is especially useful for access that is inherited, manually granted, cross-functional, or hard to automate cleanly. In practice, it becomes the backstop that tests whether the automated workflow matches actual business need.

Reviews are also the place to find access that automation does not naturally solve, such as dormant entitlements, role creep, inherited permissions, or accounts with unclear owners. A good certification cycle should close the loop by turning findings into remediation, not just sign-off. Access Reviews and Certification Guide explains how to make that review process remove access rather than merely record it.

For organisations with machine, service, or agent credentials in scope, the same logic applies to non-human accounts: automate the lifecycle first, then certify the residual access model. NHI Lifecycle Management Guide is useful because it ties provisioning, rotation, and offboarding to the governance layer that certification later validates.

What a mature sequence looks like in practice

The strongest programme sequence is usually: standardise access requests and role assignment, automate joiner-mover-leaver flows, make revocation reliable, then run certification on a narrower and cleaner entitlement set. That order reduces the number of false positives in review and makes remediation faster when a reviewer does flag something.

  • Automate the highest-volume lifecycle events first, especially onboarding, transfer, and offboarding.
  • Make removal as dependable as issuance, because delayed revocation creates avoidable exposure.
  • Use certification to validate ownership, exceptions, and high-risk entitlements rather than to compensate for broken provisioning.
  • Measure whether reviews are shrinking the entitlement set over time, not just being completed on schedule.

Joiner-Mover-Leaver (JML) Guide supports that sequence by showing how to automate the lifecycle controls that should be stable before you rely on review campaigns.

Risk and Threat Considerations

When certification is treated as the primary control, organisations often leave excessive access in place for too long and discover it only at the next review cycle. That creates a wider attack surface, more privilege creep, and more opportunity for misuse or compromise to persist unnoticed.

Failure mechanism: Manual reviews run too late to prevent bad provisioning, while weak lifecycle controls allow stale, inherited, or overprivileged access to accumulate between certification cycles.

Impact: The organisation retains unnecessary exposure, especially where access can be abused for lateral movement, unauthorised actions, or business process misuse before the next review removes it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CSA Cloud Controls Matrix IAM — Identity and Access Management Access certification and lifecycle automation are IAM governance concerns in cloud environments.
Recommendation — Automate provisioning and certification workflows to keep cloud entitlements current and reviewable.
CIS Controls v8 CIS-5 — Account Management The question is about prioritising automated account lifecycle control versus periodic review.
Recommendation — Automate account provisioning and deprovisioning before relying on periodic review.
NIST SP 800-53 Rev 5 AC-2 — Account Management AC-2 covers account lifecycle controls that should precede periodic access review.
AC-6 — Least Privilege Reducing standing access requires least-privilege enforcement before certification can be effective.
IA-5 — Authenticator Management Lifecycle controls extend to credentials and tokens that must be issued and revoked promptly.
Recommendation — Implement automated account management before using certification as a validation layer. Enforce least privilege in provisioning so reviews verify, not repair, access. Automate credential lifecycle handling before scheduling certification of access.

Practitioner Guidance

What to prioritise: Fix the lifecycle control path first, starting with automated joiner, mover, and leaver handling, because that is what prevents repeat defects from reappearing in every certification cycle.

What to verify: Review whether revocation is actually timely, whether role changes trigger removal as well as assignment, and whether certification findings flow into real remediation rather than a closed ticket with no access change.

Common mistake: Treating certification as the primary safety net for poor provisioning. That usually creates a governance ritual, not a control improvement.

Practitioner takeaway: If the access model is still noisy, certification will only document the noise; automate issuance and removal first, then use certification to police the exceptions that remain.