Campaign Completion Rate measures how much of a review or certification campaign was finished within the intended scope and timeframe. It is an audit-oriented governance metric because it shows whether the process ran to completion and can produce evidence that access reviews were actually performed.
Expanded Definition
Campaign Completion Rate is the percentage of planned review activity that is actually finished within the defined period and scope. In NHI governance, that usually means access recertifications, service account attestations, secret reviews, or other audit-driven campaigns that must be closed out with evidence. It is related to, but not the same as, coverage, because a campaign can cover a large population and still fail if reviewers do not complete required decisions before the deadline.
Used properly, the metric helps distinguish operational progress from mere assignment. It answers whether the control cycle ran to completion and whether the organisation can demonstrate execution to auditors, risk owners, and compliance teams. Definitions vary across vendors, especially around whether late completions count, whether partial approvals count, and how rescoped populations are handled. For broader governance language, the NIST Cybersecurity Framework 2.0 is useful for anchoring outcomes to repeatable control execution rather than one-time activity.
The most common misapplication is treating campaign launch volume as completion, which occurs when teams count assigned reviews as finished before evidence is collected and decisions are formally closed.
Examples and Use Cases
Implementing Campaign Completion Rate rigorously often introduces timing pressure, requiring organisations to weigh faster audit closure against the risk of approving incomplete or low-quality reviews.
- A quarterly NHI access review closes 94% of service account attestations before the deadline, while the remaining 6% are tracked as overdue exceptions for management follow-up.
- A secrets review campaign covers all high-risk repositories, but completion is only credited when each owner records a decision, preserving evidence for later audit.
- An identity governance program uses completion rate to compare business units, revealing that one team repeatedly misses deadlines despite receiving the same campaign notice.
- A security operations team links completion status to remediation workflows so unresolved items automatically escalate after the review window ends.
- For identity hygiene and secret exposure context, the State of Secrets in AppSec research is a useful reminder that process maturity often lags stated confidence, while the DeepSeek breach shows how hidden exposure can outlast assumed control.
Why It Matters in NHI Security
Campaign Completion Rate matters because unfinished reviews create a false sense of control. In NHI environments, that gap can leave stale credentials, orphaned service accounts, or overprivileged agents in place long after owners believe governance has been performed. Completion metrics help prove that review campaigns did not merely start, but actually produced decisions, evidence, and remediation actions. That distinction becomes important during audits, incident response, and executive reporting.
NHI risk is often amplified when operational teams assume that assigned equals reviewed. NHIMG research shows how quickly exposure becomes consequential in practice: in the LLMjacking analysis, exposed AWS credentials were attempted within minutes, while the State of Secrets in AppSec found an average 27-day remediation time for leaked secrets. Those delays are exactly where incomplete campaigns become dangerous, because unresolved items often remain active long after the review window closes. Organisations typically encounter the real cost only after an audit finding, credential leak, or misuse event, at which point Campaign Completion Rate becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-06 | Governance campaigns verify that NHI reviews and attestations are completed, not merely started. |
| NIST CSF 2.0 | GV.RM-01 | Risk governance requires measurable control execution and documented outcomes. |
| NIST Zero Trust (SP 800-207) | AC-6 | Zero trust depends on continuously validated access, which review campaigns help enforce. |
| NIST SP 800-63 | IAL2 | Identity assurance programs rely on completed verification and periodic reassessment. |
| NIST AI RMF | GOVERN | AI risk governance requires documented completion of oversight and review activities. |
Tie campaign completion to least-privilege validation and remove unresolved access exceptions.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org