Join our Newsletter — 33% off our NHI Course

What is the difference between lifecycle automation and access certification in IGA?

Lifecycle automation changes access when the source event changes, such as a hire, move, or departure. Access certification checks whether the access that already exists still needs to stay in place. Both are necessary, but they solve different problems: one prevents drift at the source, the other removes drift that has already accumulated.

Why Lifecycle Automation and Access Certification Solve Different IGA Problems

lifecycle automation is the operational control that changes access when an authoritative source changes, usually through joiner, mover, and leaver events. It is meant to keep entitlements aligned as people, roles, applications, or machines change. access certification is a governance control that reviews what already exists and confirms whether it should stay, which means it is periodic, corrective, and often exception-driven.

The practical difference is timing and trigger. Lifecycle automation reacts to source-of-truth events and prevents new drift from accumulating. Certification reacts to accumulated state and removes access that should no longer remain. In a healthy IGA program, automation handles routine entitlement hygiene while certification addresses residual risk, edge cases, and access that was created outside the normal path.

That split matters because the two controls answer different questions. Lifecycle automation asks, “Should this identity have this access now that something changed?” Certification asks, “Does this access still have a valid business reason?” One is designed for continual change management, the other for attestation and review. For a broader view of how the lifecycle side works, see Joiner-Mover-Leaver (JML) Guide and IAM and IGA Basics.

Where the Controls Fit in an IGA Operating Model

Lifecycle automation is strongest when the source event is trusted and the entitlement rule is deterministic. If HR, a directory, or another authoritative source says an identity has changed, the access state should update with minimal delay and minimal manual interpretation. That is what keeps joiner, mover, and leaver activity from creating orphaned, stale, or excessive access in the first place. The control works best when the rule is explicit and the rollback path is reliable.

Access certification fits when access already exists and must be validated against current need, segregation rules, or risk tolerance. It is especially useful for older entitlements, privileged access, inherited access, and access that spans multiple systems where lifecycle feeds are incomplete. Certification is slower, but it gives governance teams a chance to challenge standing access, require owner signoff, and remove drift that automation did not catch.

In practice, the two controls should be complementary rather than competing. Automation should reduce the number of items that certification needs to review, and certification should provide a backstop for anything the lifecycle logic missed or could not safely decide. Strong IGA programs usually treat certification as the exception-and-assurance layer and lifecycle automation as the default access maintenance layer. That design is also why Access Reviews and Certification Guide and IGA Buyer’s Guide are useful complements to lifecycle design.

Why the Difference Matters for Drift, Audit, and Privilege Control

Organisations often fail when they expect certification to do the work of lifecycle automation, or vice versa. If access only gets reviewed periodically, drift can persist for months. If automation exists without review, bad source data or bad rules can propagate access mistakes at scale. The real test is whether a control prevents drift at the point of change or only discovers it later.

This is also why ownership and role design matter. Lifecycle automation depends on clean source data and predictable rules, while certification depends on clear ownership, understandable entitlements, and reviewers who can make a defensible decision. When those foundations are weak, lifecycle automation can overgrant at machine speed and certification can degrade into rubber stamping. For role and entitlement structure, Role Mining and Role Design Guide and NHI Ownership and Accountability Guide show how ownership and model quality shape review quality.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Lifecycle automation and access certification both govern account and entitlement upkeep.
Recommendation — Automate account changes and review standing access on a set cadence.
NIST SP 800-53 Rev 5 AC-2 — Account Management Lifecycle automation operationalises account changes and certification validates continued account need.
AC-6 — Least Privilege Certification removes access that no longer has business need, supporting least privilege.
AU-6 — Audit Review, Analysis, and Reporting Certification depends on review evidence and decision traceability for auditability.
Recommendation — Enforce account lifecycle updates and periodically review account necessity. Remove unnecessary access during reviews to keep privilege minimized. Retain review evidence that shows access decisions were made and acted on.
ISO/IEC 27001:2022 A.5.18 — Access rights The topic is about provisioning and reviewing whether access should remain assigned.
Recommendation — Assign, review, and remove access rights according to current need.

Practitioner Guidance

What to prioritize: Treat lifecycle automation as the primary control for joiner, mover, and leaver hygiene, then use certification to clean up exceptions, inherited access, and access that cannot be fully driven from source events. If you reverse that order, review volume grows faster than governance value.

What to verify: Confirm that automated changes are tied to a real authoritative source, that revocations actually complete, and that certification campaigns can produce evidence of action taken, not just signoff. The control is only effective if the access state changes in the target system, not merely in the IGA console.

Common mistake: Teams often rely on certification to compensate for poor deprovisioning. That creates recurring manual work and leaves old access alive between review cycles. Lifecycle automation should remove most routine drift before reviewers ever see it.

Practitioner takeaway: Use lifecycle automation to keep access aligned continuously, and use certification to govern the residual access that automation cannot safely decide. If both controls are healthy, drift stays small; if either one is missing, the other will be forced to cover its blind spots.