Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Intelligent certifications: what changes for access review teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15984
Topic starter  

TL;DR: Certification campaigns have driven 5+ million revocations across more than 80,000 reviews, while customers still face 500,000-item campaigns and a 25% annual increase in integrations, according to Saviynt. The governance issue is no longer whether certification exists, but whether review quality can survive scale, missing context, and manual fatigue.

NHIMG editorial — based on content published by Saviynt: Simplifying Certifications with Intelligence

By the numbers:

  • Organizations are experiencing an average 25% annual increase in the number of integrations, according to Saviynt.

Questions worth separating out

Q: How should organisations reduce certification fatigue in large IGA campaigns?

A: Break campaigns into smaller risk-based review sets, prioritise privileged and unusual access, and improve entitlement context before asking humans to decide.

Q: Why do missing entitlement descriptions weaken access certification?

A: Because certifiers cannot judge whether access is still justified if they do not know what the entitlement does or who owns it.

Q: How do risk scores help with access reviews?

A: Risk scores help by highlighting outliers so reviewers can focus on access that is unusual, conflicting, or poorly justified.

Practitioner guidance

  • Triage certification campaigns by risk tier Split campaigns so high-risk entitlements, privileged access, and out-of-band access receive deeper review than routine low-risk items.
  • Fix ownership and entitlement metadata before expanding automation Do not add scoring or copilot logic to campaigns that still lack owners, role descriptions, or entitlement context.
  • Measure reviewer load as a security control Track items per campaign, number of missing descriptions, and the share of outlier access that gets recertified without challenge.

What's in the full article

Saviynt's full blog covers the operational detail this post intentionally leaves for the source:

  • The specific trust-signal categories used to score certification items and identify outliers.
  • The planned copilot workflow for assisting certifiers with recommendations and threshold-based approvals.
  • The metadata enrichment approach for entitlement and role descriptions that the source says is coming next.
  • Examples of how the scoring model can be tuned to match local governance policy.

👉 Read Saviynt's blog on intelligent certifications and access review →

Intelligent certifications: what changes for access review teams?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15569
 

Certification at scale becomes a control-quality problem, not a workflow problem. Once campaigns reach hundreds of thousands of review items, the main risk is not that certification stops running. It is that certifiers no longer have enough context to make meaningful decisions, so the process turns into compliance theatre. The implications are clearest in mixed human and NHI estates, where access review must account for service accounts, API keys, and human roles at the same time.

A few things that frame the scale:

  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: When should teams rely on certification automation instead of manual review?

A: Only when the access pattern is well understood, the metadata is complete, and the approval threshold is explicit and auditable. Automation is not a substitute for governance maturity. If the programme cannot explain why an item was approved, it should not be approved automatically.

👉 Read our full editorial: Intelligent certifications change how IGA teams handle access review



   
ReplyQuote
Share: