Because evidence and review are different functions. Automated logs show what happened, but access reviews determine whether the current permission set is still justified. Without periodic certification, automation can confirm drift faster than the organisation can correct it.
Why automated evidence does not replace access certification
Automated evidence and access reviews answer different control questions. Logs, tickets and system reports can show whether access was used, when it changed and whether a control generated evidence. An access review asks a separate question: whether each entitlement is still appropriate for the current role, business need and risk posture. That distinction is why automated evidence strengthens the review, but does not eliminate it.
Automation is strongest at scale and traceability. It can collect proof consistently, reduce manual effort, and surface anomalies such as inactive accounts or stale entitlements. But evidence collection is backward-looking. It tells you what the system recorded, not whether a grant has become excessive, whether a role has drifted, or whether a permission remains justified after a transfer, project end or vendor change.
For that reason, access reviews remain the governance step that converts raw evidence into an access decision. They are the point where an owner, manager or control team confirms that the current access model still matches reality. In practice, that means looking at entitlement scope, privileged access, dormant access and exceptions, not just checking that a feed or report exists.
How automated evidence and reviews work together
In a well-run programme, automation should feed the review cycle, not replace it. Access Reviews and Certification Guide explains the practical design pattern: reduce noise, enrich the reviewer’s context and make revocation easier. The evidence layer should pre-populate the certification campaign with identity, role, system and usage data so reviewers spend time on decisions, not data gathering.
The most useful automated inputs are the ones that make review decisions sharper: last-used timestamps, account ownership, joiner-mover-leaver events, privilege level, cross-environment access and outstanding exceptions. IAM and IGA Basics frames this as an identity governance problem, where review and entitlement management are separate but linked control layers. Automation improves the quality of the evidence set; governance decides what to do with it.
The same logic applies to non-human access. When a service account, integration or agent holds standing access, the review is still needed even if its activity is fully logged. Privileged Access Management Guide shows why privileged and machine access need periodic validation, especially where vaulting, just-in-time access or break-glass design does not remove the need to confirm ownership and scope.
What fails when teams confuse evidence with approval
The main failure mode is rubber-stamping. If a programme treats evidence completeness as proof of entitlement validity, reviewers will approve access that is merely documented, not justified. That creates review fatigue, lets privilege creep accumulate and reduces the certification process to an audit artifact instead of a control.
Another failure mode is stale context. Automated evidence may accurately report that an account has been active, but not that the access was inherited, duplicated during a migration, or no longer needed after an organisational change. That is why lifecycle controls matter as much as the review itself. NHI Lifecycle Management Guide is useful here because it ties provisioning, rotation, offboarding and visibility into one control loop. When lifecycle discipline is weak, reviews become the last chance to catch excessive access.
There is also a separation-of-duties issue. Automated evidence may show that a system allowed a permission set, but it cannot decide whether that combination should exist. Segregation of Duties (SoD) Guide is relevant because certification is often where toxic combinations are found, justified or escalated. If the review process is weak, conflicting access can persist even while evidence continues to look healthy.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access reviews validate whether accounts and entitlements remain justified. |
| AC-6 — Least Privilege | Certification is the mechanism that prevents privilege creep beyond business need. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | Automated evidence supports review, but audit data still needs analysis for access decisions. | |
| Recommendation — Review accounts periodically and remove unnecessary access promptly. Limit access to the minimum permissions needed for current duties. Analyze audit data to identify and act on suspicious or excessive access. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | The subject is about reviewing whether access rights remain appropriate over time. |
| A.8.2 — Privileged access rights | Privileged access requires separate, stricter review than automated evidence alone provides. | |
| Recommendation — Periodically review and adjust access rights to match current need. Review privileged access rights more frequently and revoke excess promptly. | ||
| CIS Controls v8 | CIS-5 — Account Management | Access reviews are an account-management safeguard that evidence automation cannot replace. |
| Recommendation — Maintain a process to review, approve, and remove unnecessary access. | ||
Practitioner Guidance
What to prioritise: Treat automated evidence as an input to the certification decision, not as the decision itself. The control objective is to prove that every retained entitlement still has an owner, a business purpose and an acceptable risk profile.
What to verify: Each review cycle should be able to answer three questions cleanly: who owns the access, why is it still needed, and what evidence supports removal or retention. If reviewers cannot answer those questions from the campaign data, the programme still depends too heavily on manual memory or scattered systems.
Common mistake: Equating “logged and visible” with “approved and necessary.” Automated reporting can make excess access easier to spot, but it can also make teams more confident than they should be if they stop short of actual certification and remediation.
What good looks like: Evidence is automatically assembled, reviewers see only the relevant exceptions, and revocation happens quickly when access is no longer justified. The review process then becomes a genuine governance checkpoint instead of a periodic checkbox exercise.
Practitioner takeaway: If evidence can prove activity, it can support review, but it cannot decide entitlement necessity. Keep automation focused on high-quality inputs and fast remediation, while the certification step remains the explicit approval boundary.