By NHI Mgmt Group Editorial TeamBased on Veza: “The Power of Multi-Level User Access Reviews” (October 24, 2025)

TL;DR: Sequential, dual-party recertification creates more defensible decisions for high-privilege entitlements, sensitive applications, and audit-heavy environments, according to Veza’s explanation of multi-level access reviews, because separate reviewers can validate business need and access risk more reliably than a single approver. That matters because access review quality, not review volume, is what determines whether recertification actually controls blast radius.


At a glance

What this is: This is an analysis of sequential multi-level access reviews and the finding that dual-party recertification produces more defensible approvals than a single reviewer in high-risk access decisions.

Why it matters: It matters because IAM, IGA, and PAM teams need recertification evidence that stands up to audit scrutiny when entitlements, applications, or blast radius are material.


Context

Multi-level access review is a sequential recertification model where one reviewer approves first and a second reviewer sees only what passed the earlier stage. In access governance, that distinction matters because a single reviewer often lacks both the business context and the risk context needed to make a defensible decision on privileged or sensitive access.

The problem is not review volume, but review quality. When managers, application owners, and entitlement owners each see a different part of the picture, a true second level can reduce rubber-stamping and create evidence that recertification decisions were independently challenged before approval.


Key questions

Q: What breaks when access recertification is handled by one reviewer only?

A: Single-reviewer recertification often collapses business justification and risk validation into one judgment, which increases the chance of rubber-stamping. The reviewer may not know enough about role need, privilege sensitivity, or segregation-of-duties constraints to make a defensible decision, especially in high-volume campaigns.

Q: Why do sequential access reviews produce stronger audit evidence?

A: Sequential review records separate judgments at each stage, so the audit trail shows who validated business need and who validated access risk. That makes the final approval easier to defend than a single signature or a shared approval pool.

Q: How do organisations know if access certification is actually working?

A: Look for shrinking numbers of standing privileges, faster revocation after review decisions, and fewer orphaned or overprivileged accounts over time. If campaigns finish but access sprawl remains unchanged, the programme is producing documentation rather than governance. Working certification changes the entitlement baseline, not just the audit record.

Q: When should teams use multi-level review instead of a single approver?

A: Use multi-level review when access has high blast radius, when segregation of duties applies, or when auditors expect documented dual control. Those conditions indicate that one reviewer is unlikely to have enough context to make a reliable recertification decision.


Technical breakdown

Why sequential review is not the same as multiple reviewers

A multi-level review is a gated workflow, not a shared task list. In a normal multi-review assignment, the first person to act can close the item, which creates a “first decision wins” pattern. In a true dual-party control, the first approver locks the first decision, and the second approver reviews only the items that survived level one. That architecture matters because it preserves reviewer independence and produces a clearer evidentiary trail for audits and segregation of duties checks. Practical implication: distinguish workflow convenience from control design when you configure access recertification.

Practical implication: configure recertification so the second reviewer is a true control, not a duplicate voter on the same line item.

How dual-party recertification changes accountability and audit evidence

Sequential review changes the evidence model. The manager can validate job-based need, while the application owner or entitlement owner can assess risk, resource fit, and whether the access still belongs in scope. Because each level records its own decision, the resulting audit trail shows who reviewed what, in what order, and on what basis. That is materially different from a single approval chain or an unstructured approval swarm. Practical implication: if auditors expect demonstrable dual control, the workflow must capture stage-specific decisions and not just a final approval state.

Practical implication: retain level-by-level approval records so auditors can see the reasoning behind both decisions.

Why high-privilege and in-scope access benefit most from multi-level review

The strongest use case is not ordinary entitlement hygiene, but access where blast radius is high. High-privilege entitlements, sensitive applications, and systems with segregation of duties requirements are the places where one person’s view is often incomplete. A second reviewer reduces the chance that a single approver rubber-stamps access that is technically valid but operationally risky. This is also where recertification becomes a governance control rather than a paperwork exercise. Practical implication: reserve dual-party review for the access classes where an approval error would have the largest operational or compliance impact.

Practical implication: apply multi-level review to the access classes where an approval mistake would have the highest blast radius.


NHI Mgmt Group analysis

Multi-level recertification is an access governance control, not a workflow preference. The core value is not convenience but decision quality under uncertainty. When the manager and the resource owner validate different aspects of access, the programme gets a more defensible answer than either party can provide alone. For IAM and IGA teams, that means the control should be designed around evidence quality, not reviewer count.

Rubber-stamping is the failure mode multi-level review is trying to contain. When a single reviewer is handed too many line items, especially in complex environments, approvals become habitual rather than reasoned. Sequential gating reduces that pressure by pushing later reviewers only the rows that survive initial scrutiny. Practitioners should treat that as a control on decision fatigue, not just a process tweak.

Auditability improves when approval authority is intentionally split. A true dual-party model makes it easier to show who accepted the business need and who validated the access risk. That matters for sensitive applications, privileged entitlements, and SoD-heavy environments where auditors expect traceable accountability. The operational lesson is to map approval roles to distinct knowledge domains, not duplicate the same judgment twice.

Defensible recertification depends on control design, not reviewer multiplication. Adding more names to the same approval step does not create stronger governance if the first decision closes the item. True sequence, independent review, and stage-specific evidence are what change the control posture. Teams should measure whether their recertification process produces separate judgments or merely more approvers.

Access review quality is the real audit gap. The article points to a broader programme problem: too many organisations optimise for completion rates instead of challenge quality. A recertification control that cannot prove independent scrutiny does not materially reduce entitlement risk, even if every review is technically completed. Practitioners should judge the control by the strength of its evidence trail, not its throughput.

From our research library:

What this signals

Multi-level recertification should be treated as a control-strength decision, not a workflow preference. The important question is whether the process creates separate judgments about need and risk. If it does not, the organisation has added steps without adding governance value, which is exactly how audit gaps persist in mature-looking programmes.

Dual-party review is most useful where entitlement errors have a large blast radius. That includes privileged access, sensitive applications, and environments with segregation of duties pressure. In those cases, the governance objective is not faster completion, but a better evidentiary basis for saying the access was truly justified.

Audit readiness depends on the quality of the approval trail. If reviewers share one decision point, the process may still complete, but it will be harder to prove that access was independently assessed. Teams should look for stage-specific accountability as the marker of a defensible recertification design.


For practitioners

  • Design true sequential approvals Separate the first and second review stages so the later reviewer only sees items that passed the earlier decision, preserving independence between approvers.
  • Map reviewers to distinct judgment domains Use managers for job-based justification and application or entitlement owners for access risk, resource fit, and blast-radius assessment.
  • Reserve dual control for high-risk access Apply multi-level review to privileged entitlements, sensitive applications, and SoD-sensitive systems where one approval is not enough to prove defensibility.
  • Preserve stage-level audit evidence Retain the decisions, timestamps, and reviewer identities for each level so audit teams can reconstruct how the final approval was reached.

Key takeaways

  • The article shows that access review quality matters more than the number of reviewers assigned to a recertification task.
  • Sequential dual-party review reduces the risk that privileged or sensitive access is approved without independent challenge.
  • The control gains value when it produces a clear, stage-by-stage audit trail and maps approval authority to different knowledge domains.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingRecertification is part of lifecycle governance, and the article focuses on maintaining valid access over time.
NHI-05 — Overprivileged NHIThe article targets high-privilege access where excessive entitlement scope drives audit risk.
Recommendation — Use NHI-01 to ensure access that no longer passes review is removed from the entitlement estate. Apply NHI-05 to recertify privileged access with stricter approval and evidence requirements.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe control directly covers permissions and authorisations subject to recertification.
Recommendation — Align recertification workflows to PR.AA-05 so permissions are reviewed with documented accountability.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeDual review supports least-privilege decisions for sensitive access by reducing unjustified retention.
Recommendation — Apply AC-6 to remove access that cannot be justified through independent review.
CIS Controls v8CIS-5 — Account ManagementAccount lifecycle and review are central to the article's recertification model.
Recommendation — Use CIS-5 to formalize account review responsibility and decision evidence for recertification.

Key terms

  • Multi-level access review: A certification process that sends access decisions through more than one reviewer before action is taken. It is used to add governance context in complex environments, but it only improves control if the final decision is enforced in live systems rather than archived in a report.
  • Dual Control: A governance pattern that requires two independent authorised people to approve a sensitive action before it is released. In finance, it reduces the chance that a single compromised identity can move money or alter payment instructions on its own.
  • Rubber Stamping: A review pattern where approvers accept most entitlements with little real evaluation. It usually appears when decision context is weak, entitlement volume is high, and the perceived cost of removal is higher than the cost of approval. The control fails because the process rewards completion, not judgment.
  • Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org