By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: SaviyntPublished October 2, 2024

TL;DR: Certification campaigns have driven 5+ million revocations across more than 80,000 reviews, while customers still face 500,000-item campaigns and a 25% annual increase in integrations, according to Saviynt. The governance issue is no longer whether certification exists, but whether review quality can survive scale, missing context, and manual fatigue.


At a glance

What this is: This is a vendor analysis of intelligent certifications in IGA, with the key finding that scale, missing entitlement context, and reviewer fatigue are making manual access review unreliable.

Why it matters: For IAM, IGA, and PAM teams, the problem is not just review volume but whether certification decisions can still enforce least privilege across human and non-human identities.

By the numbers:

  • Organizations are experiencing an average 25% annual increase in the number of integrations, according to Saviynt.
  • Market analysis cited in the post says 60% of data breaches are due to internal identity threats.

👉 Read Saviynt's blog on intelligent certifications and access review


Context

Access certification is the governance control that asks whether an identity still needs the access it already has. In practice, that control breaks down when reviewers are faced with huge campaign volumes, incomplete entitlement data, and too many approvals that must be made quickly to keep compliance moving.

The article sits squarely in the IGA and access review problem space. Its underlying point is that scale alone is not the issue. The real governance gap is that manual certification processes were built for smaller, more legible identity estates, not for environments where human and non-human access both expand faster than review capacity.

For teams trying to reduce privilege creep, the relevance is broader than certification tooling. If owners, descriptions, and context are missing, then access review becomes a documentation exercise instead of an actual control. That is why lifecycle governance and entitlement hygiene matter as much as the certification workflow itself.


Key questions

Q: How should organisations reduce certification fatigue in large IGA campaigns?

A: Break campaigns into smaller risk-based review sets, prioritise privileged and unusual access, and improve entitlement context before asking humans to decide. Certification fatigue is usually a design problem, not a reviewer problem. If managers are asked to judge thousands of items without clear ownership or purpose, rubber stamping becomes the default outcome.

Q: Why do missing entitlement descriptions weaken access certification?

A: Because certifiers cannot judge whether access is still justified if they do not know what the entitlement does or who owns it. Missing descriptions turn certification into guesswork. That weakens least privilege enforcement, increases false approvals, and makes the review outcome hard to defend in audit or incident investigations.

Q: How do risk scores help with access reviews?

A: Risk scores help by highlighting outliers so reviewers can focus on access that is unusual, conflicting, or poorly justified. They should not replace governance judgment. The best use is prioritisation, where low-confidence or high-impact access rises to the top and routine items are handled with lighter touch controls.

Q: When should teams rely on certification automation instead of manual review?

A: Only when the access pattern is well understood, the metadata is complete, and the approval threshold is explicit and auditable. Automation is not a substitute for governance maturity. If the programme cannot explain why an item was approved, it should not be approved automatically.


Technical breakdown

Why certification fatigue breaks access review quality

Certification fatigue happens when reviewers are asked to assess too many items with too little context. Once campaigns reach hundreds of thousands of entitlements, managers and certifiers start using shortcuts, which increases rubber stamping and weakens least privilege enforcement. The technical issue is not just human attention span. It is that review decisions depend on metadata quality, ownership clarity, and the reviewer’s ability to judge whether access is still justified. When those inputs are missing, the workflow still completes but the governance signal degrades.

Practical implication: reduce campaign volume, improve entitlement metadata, and route high-risk items for deeper review instead of bulk approval.

How trust scoring changes certification decisions

Trust scoring is a decision-support layer that combines multiple risk signals into a weighted recommendation. In this article, the model uses factors such as peer access, segregation of duties violations, prior certifications, and out-of-band access to identify outliers. The governance value is not automation for its own sake. It is prioritisation, so certifiers can focus on unusual or high-impact access rather than treating every line item as equally risky. That matters because access review quality falls sharply when every decision is forced through the same manual path.

Practical implication: tune decision support to surface outliers first, and treat low-confidence access as the default queue for human review.

Why LLM-assisted certification still needs policy boundaries

The blog says future copilots will use LLMs to help certifiers interact with campaign data and reduce SME dependency. That is useful only if the governance model remains deterministic about what the system may recommend, auto-approve, or enrich. In identity governance, LLM assistance can improve context retrieval, but it cannot be allowed to blur accountability for access decisions. The practical technical question is whether the certification system can separate explanation from authority, especially when metadata enrichment and automated approval thresholds are added.

Practical implication: keep approval thresholds and enrichment rules auditable, and never let language assistance become an implicit governance override.



NHI Mgmt Group analysis

Certification at scale becomes a control-quality problem, not a workflow problem. Once campaigns reach hundreds of thousands of review items, the main risk is not that certification stops running. It is that certifiers no longer have enough context to make meaningful decisions, so the process turns into compliance theatre. The implications are clearest in mixed human and NHI estates, where access review must account for service accounts, API keys, and human roles at the same time.

Missing entitlement context is a governance failure, not a data-cleanup issue. When ownership and entitlement descriptions are absent, reviewers cannot evaluate necessity, business purpose, or privilege scope. That failure mode matters because certification depends on legibility before it depends on speed. If the governance record is incomplete, least privilege cannot be certified with confidence, and the programme silently shifts from control to assumption.

Rubber stamping is the predictable outcome of unmanaged review burden. The article correctly identifies that hasty certification decisions emerge when reviewers face too many items and too little signal. This is where IGA programmes need to treat reviewer load as a security risk variable, not an operational inconvenience. The practitioner conclusion is simple: if reviewers cannot reasonably understand the access, they will approve it.

Intelligent certification only helps when it improves decision quality rather than disguising scale. Weighted trust scoring, risk signals, and metadata enrichment can reduce friction, but they do not solve weak ownership models or poor entitlement hygiene. The broader market signal is that IGA is moving toward decision augmentation, yet the programme still lives or dies on the quality of its identity data and certification design.

From our research:

What this signals

Certification quality will increasingly be judged by metadata completeness, not by campaign completion rates. As identity estates grow, teams that cannot reliably map ownership and entitlement purpose will see certification lose force as a governance control. The practical shift is toward treating identity data quality as a prerequisite for any meaningful review programme, especially where NHI and human access intersect.

Certification fatigue is an early warning sign of privilege creep and control decay. If reviewers are overwhelmed, they will approve access that should have been challenged, and the programme will look compliant while missing real risk. That makes reviewer load, outlier volume, and missing context worth tracking alongside classic IAM metrics.

The next step for mature programmes is to connect certification outcomes to lifecycle controls, including offboarding and entitlement hygiene. When review decisions are fed back into identity data quality, the organisation stops repeating the same access defects campaign after campaign.


For practitioners

  • Triage certification campaigns by risk tier Split campaigns so high-risk entitlements, privileged access, and out-of-band access receive deeper review than routine low-risk items. This keeps reviewers from treating every decision as a checkbox exercise and reduces the probability of rubber stamping at scale.
  • Fix ownership and entitlement metadata before expanding automation Do not add scoring or copilot logic to campaigns that still lack owners, role descriptions, or entitlement context. Enrichment only helps when the underlying identity record is complete enough for the reviewer to make a defensible decision.
  • Measure reviewer load as a security control Track items per campaign, number of missing descriptions, and the share of outlier access that gets recertified without challenge. If those metrics worsen together, the certification process is losing control value and needs redesign, not another reminder campaign.
  • Separate recommendation from approval authority If an intelligence engine suggests revocation or approval, keep the final authority and its policy thresholds auditable. This is especially important when LLM-assisted workflows are introduced into access certification.

Key takeaways

  • Access certification fails when scale outruns context, because reviewers cannot make meaningful least-privilege decisions on incomplete data.
  • The article’s evidence shows that intelligent scoring helps prioritise review, but it does not fix missing ownership, poor descriptions, or privilege sprawl.
  • For IGA teams, the real control objective is decision quality, which depends on identity data hygiene, reviewer load management, and auditable approval thresholds.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Certification fatigue and overprivileged access map to NHI governance failures.
NIST CSF 2.0PR.AC-4Access permissions and review quality sit inside the protect function.
NIST SP 800-53 Rev 5AC-6Least privilege is the core control challenged by overprovisioned access.
NIST Zero Trust (SP 800-207)Zero trust requires continuous verification of access, not stale approvals.

Apply AC-6 to reduce standing access and ensure certification removes unnecessary entitlements.


Key terms

  • Certification Fatigue: The point at which access reviewers are asked to approve so many permissions that they stop evaluating them carefully. It usually appears when the entitlement list is long, the context is thin, and the reviewer lacks clear signals about which access rights are unusual. That turns governance into routine approval.
  • Trust Scoring: Trust scoring is a risk-ranking method that assigns a relative confidence or exposure level to an identity, request, or entitlement. In identity governance, it helps prioritise review work and automation decisions. It must be explainable, otherwise it becomes a black box that weakens auditability.
  • Rubber Stamping: A review pattern where approvers accept most entitlements with little real evaluation. It usually appears when decision context is weak, entitlement volume is high, and the perceived cost of removal is higher than the cost of approval. The control fails because the process rewards completion, not judgment.
  • Entitlement metadata: Entitlement metadata is the descriptive information that explains what an access entitlement does, who owns it, and why it exists. Without it, reviewers cannot judge whether access is still necessary, which makes certification and audit outcomes far weaker.

What's in the full article

Saviynt's full blog covers the operational detail this post intentionally leaves for the source:

  • The specific trust-signal categories used to score certification items and identify outliers.
  • The planned copilot workflow for assisting certifiers with recommendations and threshold-based approvals.
  • The metadata enrichment approach for entitlement and role descriptions that the source says is coming next.
  • Examples of how the scoring model can be tuned to match local governance policy.

👉 The full Saviynt post covers trust scoring, copilot-assisted certification, and metadata enrichment details.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org