By NHI Mgmt Group Editorial TeamBased on Netwrix: “What's New in Netwrix Identity Manager 7.0” (June 2, 2026)

TL;DR: Access review bottlenecks are reduced by certification campaigns that add multiple reviewers, clearer workflows, improved decision tracking, and expanded language support, according to Netwrix. The governance value lies in shortening review friction without weakening accountability, which matters for IAM teams running human and non-human lifecycle controls.


At a glance

What this is: Netwrix Identity Manager 7.0 updates certification campaigns with multiple reviewers, clearer workflows, stronger decision tracking, and expanded language support.

Why it matters: This matters because access review programmes fail when reviewers cannot complete decisions quickly and consistently, and IAM teams need governance processes that scale without weakening accountability.


Context

Access review campaigns are a governance control, not just an administrative task. They only work when reviewers can reach decisions quickly, understand what they are certifying, and trace those decisions later for audit and remediation.

For IAM and IGA teams, the core problem is reviewer friction: bottlenecks, unclear status, and weak decision visibility can make certification programmes slow enough that they lose operational value. Netwrix's article positions version 7.0 as a workflow improvement aimed at that failure mode.


Key questions

Q: How should IAM teams reduce bottlenecks in access review campaigns?

A: IAM teams should distribute certification workload across multiple reviewers when campaigns regularly stall, but they must keep final ownership and escalation rules explicit. The goal is to shorten approval queues without making accountability ambiguous. If reviewer assignment is unclear, faster completion can still produce weak governance evidence.

Q: Why do access review campaigns lose governance value when workflows are unclear?

A: They lose value because reviewers spend time interpreting state instead of making decisions, which increases delay and weakens evidence quality. A certification control only supports audit and remediation when item status, ownership, and completion state are visible enough to trust.

Q: What do IAM teams get wrong about certification campaign design?

A: They often treat certification as a policy exercise and overlook the operational design of the review path. If the workflow creates reviewer confusion, language barriers, or hidden queues, the programme may still exist but fail to deliver timely, defensible outcomes.

Q: How do organisations know whether access reviews are working?

A: Access reviews are working when they lead to timely removals, reduced exception volume, and role definitions that stop accumulating unused rights. If the same accounts keep reappearing with the same excess access, the review process is only producing paperwork. Evidence of change is the real success signal.


Background and context

Certification campaign bottlenecks in access reviews

Access review campaigns slow down when too much decision work is concentrated in a single reviewer path. In practice, that means items queue up, context gets lost, and managers or application owners defer decisions until the campaign becomes a backlogged event rather than a governance process. Multiple reviewers change the workflow shape by distributing review load across more than one accountable participant, which can reduce time-to-decision when the certification design supports it. The real control issue is not review volume alone, but reviewer throughput and clarity of action.

Practical implication: design certification campaigns so decision load is distributed before backlog becomes a governance failure.

Decision tracking and workflow visibility in IGA

Decision tracking is the difference between a completed review and a defensible review. Clearer workflow indicators let administrators and reviewers see what has been acted on, what still needs attention, and where a campaign is stalled. That matters because access certification must support later audit, remediation, and evidence collection, not just decision capture. In IGA programmes, poor visibility often turns workflow state into guesswork, which weakens both operational management and assurance. Better tracking does not change the policy objective, but it makes the control usable at scale.

Practical implication: treat workflow visibility as an assurance requirement, not a user-interface preference.

Language support and lifecycle expectations for global governance

Expanded native language support matters because certification campaigns fail when reviewers cannot act confidently in the language they use for daily work. That is especially relevant in distributed organisations where access review quality depends on consistent interpretation of approval prompts, action indicators, and remediation steps. The article also references updated version lifecycle and upgrade expectations, which signals that workflow improvements sit inside broader platform governance, not in isolation. For practitioners, usability and supportability are part of the control surface because they affect whether governance can be executed reliably across regions and teams.

Practical implication: include localisation and version lifecycle planning in access review operating models.


NHI Mgmt Group analysis

Access review friction is a governance failure mode, not a cosmetic workflow issue. When certification campaigns slow down, the underlying problem is usually decision concentration, unclear ownership, or poor workflow state visibility. Those failures matter because access review only proves value when it completes on time and produces traceable outcomes. The practical takeaway is that campaign design should be judged by decision throughput and evidence quality, not by whether reviews are merely available.

Clearer campaign workflows improve the usability of IGA controls without changing the control objective. That distinction matters because many access review programmes are structurally sound but operationally hard to execute. If reviewers cannot understand status, action indicators, or responsibility boundaries, the control loses effectiveness even when policy is correct. Practitioners should evaluate workflow clarity as part of control reliability, not as a separate user-experience concern.

Multiple reviewers are most valuable when they reduce bottlenecks without diluting accountability. Distributed review paths can shorten certification cycles, but only if ownership is still explicit at the item level. Otherwise, shared review becomes shared ambiguity. The governance model should preserve named responsibility while making throughput more scalable, especially in large IAM and IGA programmes.

Language support belongs inside identity governance planning, not outside it. Certification controls only work consistently when reviewers can understand the action they are taking in their operating language. That is especially relevant for multinational teams running the same review process across regions. Practitioners should treat localisation as a control enablement requirement, because poor comprehension creates review errors just as readily as a bad workflow does.

Access review improvement signals a broader shift toward operationally usable governance. The market is moving away from governance features that exist only for compliance evidence and toward controls that teams can actually complete at scale. That does not weaken assurance. It raises the bar by making completion, traceability, and reviewer clarity part of the control design itself.

What this signals

Certification workflow usability is becoming a governance control in its own right. Teams that rely on access reviews for audit evidence now need to assess whether the campaign experience helps or hinders completion. When reviewers cannot move quickly through items, the control may be formally present but operationally weak.

Identity governance programmes should be measured by completion quality, not just policy coverage. The practical question is whether reviewers can make timely, traceable decisions at scale. If not, the programme may need workflow redesign before it needs more policy.


For practitioners

  • Strengthen reviewer routing Map certification items to more than one reviewer only where shared accountability is explicit and decision paths remain auditable. Use this to reduce queueing without creating ambiguous ownership.
  • Measure campaign completion quality Track decision latency, pending-item ageing, and the percentage of campaigns completed without manual follow-up. Those signals show whether the workflow is genuinely reducing friction or only moving it elsewhere.
  • Review workflow state visibility Check whether administrators can see item status, reviewer actions, and unresolved decisions without hunting across screens. If the workflow cannot be understood quickly, campaign management will remain fragile.
  • Localise reviewer experience Confirm that approval prompts, action indicators, and workflow labels are understandable in the languages used by the reviewers who actually complete campaigns.

Key takeaways

  • Certification campaigns fail when reviewer friction creates queues, ambiguity, and delayed decisions that weaken the value of access reviews.
  • Netwrix's article points to workflow clarity, decision tracking, and multiple reviewers as the main levers for improving governance execution.
  • IAM and IGA teams should assess access review controls by throughput, traceability, and reviewer usability, not by whether the campaign exists on paper.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsCertification campaigns govern who should keep access and who should be removed.
Recommendation — Use PR.AA-05 to keep access review outcomes tied to entitlement decisions and remediation.
CIS Controls v8CIS-5 — Account ManagementAccess review workflows directly support account and entitlement governance.
Recommendation — Apply CIS-5 to ensure certification results drive timely account and access removal.
NIST SP 800-53 Rev 5AC-2 — Account ManagementCampaigns are part of account lifecycle governance and periodic review.
Recommendation — Use AC-2 to align certification campaigns with account review and removal processes.

Key terms

  • Certification Campaign: A certification campaign is a structured access review in which owners confirm whether an identity still needs its permissions. For NHIs, the review must include purpose, actual usage, privilege scope, and ownership because role-based human review logic does not map cleanly to automation.
  • Reviewer Bottleneck: A reviewer bottleneck occurs when too few approvers are responsible for too many certification items, causing delays or incomplete decisions. In identity governance, bottlenecks weaken the control because access can remain active while the campaign stalls.
  • Decision Tracking: Decision tracking is the ability to record who made each access review decision, when it was made, and what happened next. It turns certification from a checkbox exercise into evidence that can support audit, governance oversight, and remediation accountability.
  • Workflow-level Visibility: Workflow-level visibility is the ability to reconstruct how data moves across a sequence of actions rather than inspecting isolated events. It matters when an AI agent reads, transforms, and forwards data in separate steps, because single-event monitoring often misses the full policy violation.

Deepen your knowledge

Identity lifecycle management, secrets management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org