TL;DR: As access environments grow more complex, multi-level access reviews can reduce manual work, improve audit readiness, and strengthen accountability, according to Zluri. The deeper issue is that review cadence, remediation lag, and entitlement sprawl now create a governance gap that traditional certification workflows struggle to close.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “How to Simplify Audits with Multi-Level Access Reviews”.
By the numbers:
- 36% of companies describe access reviews as being extremely manual, according to Zluri's State of Access Reviews Report.
Key questions
Q: How should IAM teams govern access reviews across multiple systems?
A: They should define one accountable review owner, one evidence standard, and one remediation path that applies across every connected directory, SaaS platform, and on-prem system.
Q: Why do manual access reviews create audit risk in complex environments?
A: Manual access reviews create audit risk because they depend on fragmented records, human reconciliation, and late-stage evidence gathering.
Q: What are the signs that an access certification campaign is failing in practice?
A: A campaign is failing when reviewers are working from stale data, the review window is too vague, or the process becomes so frequent that people stop giving it proper attention.
Practitioner guidance
- Define review tiers by decision context Assign first- and second-level reviewers based on who has the best operational and governance context for the entitlement, not by organisational hierarchy alone.
- Tie certification outcomes to enforcement Make revoke and modify actions flow directly from approved review decisions so remediation does not sit in a separate manual queue.
- Centralise entitlement discovery before campaigns Pull user, application, and access data into one review view so reviewers can judge permissions against a complete inventory.
Bottom line: Access reviews become weak controls when the programme cannot keep pace with entitlement growth, reviewer context, and remediation lag.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Multi-level access reviews are a response to governance latency, not just audit pressure. The core issue in modern IAM is not whether reviews exist, but whether they can keep pace with the rate at which access changes. When remediation trails the decision, entitlement drift remains active long after certification closes. Practitioners should treat review latency as a control weakness in its own right.
A few things that frame the scale:
- Over 70% of organisations lack automated access risk analysis, user access reviews and provisioning and deprovisioning, according to Pathlock's 2025 Digital Transformation and Access Risk Report.
A question worth separating out:
Q: Who is accountable when an access review decision is not enforced?
A: Accountability sits with the identity governance owner, the system owner, and the process owner, because a certification that does not change entitlement state is incomplete control design. Organisations should treat unenforced revocation as a governance failure, not a reviewer failure, because the workflow itself did not close the loop.
👉 Read our full editorial: Multi-level access reviews reveal the audit gap in IAM