Onboarding automation grants the initial access needed for work, while access certification validates whether that access should still exist later. They serve different points in the identity lifecycle, and one does not replace the other. Mature IAM programmes use both to keep access accurate from joiner to leaver.
Why onboarding automation and access certification solve different problems
Onboarding automation is designed to get a person, contractor, or system the right starting access quickly and consistently. It is a provisioning control: create accounts, assign roles, and establish the minimum access needed for day-one work. access certification is a governance control: review existing access later and decide whether it still matches the role, risk, and business need.
The difference matters because the two controls answer opposite questions. Onboarding asks, “What access should exist now?” Certification asks, “What access should still exist?” If you treat them as the same process, you either slow down joiner access or let stale entitlements survive indefinitely. A healthy identity programme uses both, with IAM and IGA Basics separating provisioning from review.
In practice, onboarding is typically event-driven and source-of-truth driven, often fed by HR or a sponsor model. Certification is time-bounded, evidence-driven, and usually triggered by schedule, risk tier, or control requirement. That is why onboarding belongs in lifecycle operations, while certification belongs in access governance and assurance.
How each control behaves across the identity lifecycle
Onboarding automation sits at the front of the lifecycle. It helps with joiner access, account creation, default entitlements, application access requests, and first-day productivity. Mature implementations also handle edge cases such as contractors, third-party users, and machine or service identities, because those populations still need controlled initial access. A useful lifecycle view is captured in Joiner-Mover-Leaver (JML) Guide and NHI Lifecycle Management Guide.
Access certification sits later in the cycle and is usually periodic or event-based. It checks whether access still matches current job duties, whether privilege has crept beyond need, and whether dormant or orphaned access should be removed. The control is more than a checklist, because reviewers need context such as entitlement sensitivity, last use, manager ownership, and role change history. Access Reviews and Certification Guide focuses on making that review meaningful rather than ceremonial.
The practical distinction is timing and intent. Onboarding grants, certification validates. Onboarding reduces friction for legitimate work, while certification reduces long-term exposure from access that no longer has a purpose. Both are part of lifecycle hygiene, but they control different failure points.
Why mature programmes use both, not one instead of the other
Automation without certification scales speed, but it also scales mistakes. If a role template is wrong, if access inheritance is too broad, or if a leaver path is incomplete, the error is repeated at scale. Certification catches what automation missed, especially where business reality has changed faster than the role model.
Certification without automation creates the opposite problem. Reviews may detect excessive access, but if the initial joiner flow is manual, slow, or inconsistent, teams often approve broad access as a shortcut to productivity. That increases privilege creep before the first review even happens. A strong operating model therefore uses onboarding to create controlled baseline access and certification to correct drift over time.
For recurring governance work, many teams pair certification with role design and periodic cleanup. If reviews repeatedly surface the same access exceptions, the issue is usually not the review itself. It is a broken role model, weak ownership, or poor lifecycle closure, which are better addressed upstream through IGA Buyer’s Guide style platform and process design.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Covers credential lifecycle and controlled access issuance during onboarding. |
| AC-2 — Account Management | Directly covers provisioning, review, and removal of accounts across the lifecycle. | |
| AC-6 — Least Privilege | Supports granting only the minimum initial access and reducing excessive standing access. | |
| Recommendation — Manage credential issuance and rotation so onboarding grants only controlled, auditable access. Automate account creation and removal, then review accounts regularly for continued need. Limit onboarding grants to the minimum required access and remove anything beyond least privilege. | ||
| CIS Controls v8 | CIS-5 — Account Management | Directly addresses account lifecycle, review, and removal of unnecessary access. |
| Recommendation — Centralise account lifecycle management and verify accounts are reviewed and removed when no longer needed. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Directly covers provisioning, review, and removal of access rights over time. |
| A.5.15 — Access control | Supports the policy distinction between granting access and validating continued need. | |
| Recommendation — Assign, review, and revoke access rights through defined lifecycle governance. Set access control rules that distinguish initial provisioning from periodic access review. | ||
Practitioner Guidance
What to verify: Confirm that onboarding has a clear source of authority, a defined birthright access set, and an approval path for exceptions. Then verify that certification reviewers can see role, business owner, last access, and risk context, otherwise the review becomes rubber-stamping.
Decision rule: Use onboarding automation when the question is “should this access be created now?” Use certification when the question is “should this access continue to exist?” If the same control is being asked to answer both questions, split the workflow.
What to measure: Track time-to-productivity for onboarding, exception rate for automatic grants, review completion quality, and the percentage of certified access that is actually removed. If reviews are completed but removals do not happen, the certification programme is not closing the loop.
Practitioner takeaway: The best IAM programmes do not choose between speed and control, they use onboarding automation to grant safe starting access and certification to keep that access justified as the organisation changes.
Related resources from NHI Mgmt Group
- What is the difference between rotating a secret and revoking access?
- What is the difference between runtime protection and NHI lifecycle management?
- What is the difference between rotation and deprovisioning for NHIs?
- What is the difference between access certification and continuous monitoring in ERP security?