A manual certification campaign is an access review process that relies on spreadsheets, exports, email approvals, and human follow-up to verify whether access is still appropriate. It is often used to compensate for weak integration, but it scales poorly and quickly becomes stale in large environments.
What a manual certification campaign really is
A manual certification campaign is not just an access review with a spreadsheet attached. It is a governance process where reviewers must inspect exported entitlements, decide whether access is still justified, and send approvals or removals back through humans rather than through an integrated workflow.
That distinction matters because the campaign is usually trying to answer a simple question, but doing it with a brittle operating model. The process can still produce a valid decision, yet the quality of that decision depends heavily on data freshness, reviewer discipline, and whether someone actually follows through on remediation.
Why manual campaigns become stale and noisy
Manual campaigns tend to degrade as the environment grows because access state changes faster than the review cycle. By the time reviewers open the spreadsheet, some entries are already obsolete, inherited, or tied to workflows that no longer reflect real business need.
They also create noise. Reviewers are forced to approve or reject long lists without enough context, which encourages rubber stamping, delayed action, and inconsistent decisions between teams. Over time, the campaign can become a documentation exercise instead of a control.
A related weakness is that manual methods often capture only the visible entitlement at a moment in time, not the business reason behind it. That makes it hard to distinguish appropriate standing access from access that should have been removed after a project, role change, or temporary exception ended.
Where manual certification fits in access governance
Even with its flaws, a manual certification campaign is still an access governance control. It is used when organizations need to demonstrate periodic review, validate who should retain access, or compensate for systems that do not yet expose clean review data through a governance platform.
In practice, it sits between entitlement discovery and remediation. The review tells you what should change, but the value depends on whether the result is acted on, tracked, and closed. Without that closed loop, the campaign records a judgment without changing exposure.
Manual review can also be the first place where inconsistent ownership becomes visible. If nobody knows who should certify a system, who owns a role, or which manager understands the entitlement, the campaign exposes a governance gap that is larger than the review itself.
How to think about scale, evidence, and control quality
The central problem with manual certification is not that humans are unreliable, it is that humans are expensive control points. As the number of identities, applications, and entitlements rises, review quality falls unless the process is narrowed to the riskiest access and supported by better context.
The strongest manual campaigns focus on material access rather than everything at once. That means privileged access, sensitive systems, dormant entitlements, and outlier permissions get more attention than low-risk routine access, because the purpose is not to review volume but to reduce meaningful exposure.
A useful campaign also needs traceable evidence. If reviewers cannot see why access exists, who requested it, when it was last used, and what will happen after revocation, the control becomes hard to defend and even harder to improve.
Risk and Threat Considerations
Manual certification campaigns create control risk when they are too slow, too broad, or too easy to rubber stamp. That leaves excessive access in place longer than intended and gives attackers more opportunity to exploit stale entitlements, orphaned permissions, or overlooked privileged access.
Failure mechanism: The review is based on stale exports and limited context, so reviewers approve access they cannot confidently validate or miss access that should be removed. Weak follow-up then leaves the bad decision in place.
Impact: Privilege creep, delayed deprovisioning, and prolonged exposure to account takeover, insider misuse, or lateral movement become more likely, especially in large environments with many recurring reviews.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access certification supports periodic account and entitlement review. |
| AC-6 — Least Privilege | Certification campaigns are used to remove excessive access and preserve least privilege. | |
| IA-5 — Authenticator Management | Campaigns often uncover stale credentials and access material that should be retired. | |
| Recommendation — Use AC-2 to review accounts and revoke access that is no longer justified. Apply AC-6 to reduce standing access to the minimum needed for each role. Use IA-5 to manage credential lifecycle and retire unused authenticators promptly. | ||
| CIS Controls v8 | CIS-5 — Account Management | CIS account management aligns to periodic review and removal of unnecessary access. |
| Recommendation — Implement CIS-5 to regularly validate accounts and remove unnecessary access. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Manual certification is an access-control governance activity under the ISMS. |
| Recommendation — Use A.5.15 to define access review ownership and review cadence. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Manual reviews often target excessive privileges held by non-human identities. |
| NHI-01 — Improper Offboarding | Certification campaigns often reveal identities and access that should have been removed. | |
| Recommendation — Apply NHI-05 to identify and remove excessive access from non-human identities. Use NHI-01 to revoke access that should have been removed during offboarding. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions and Authorizations | Periodic entitlement review directly supports authorization governance. |
| Recommendation — Use PR.AA-05 to validate and trim access permissions on a regular schedule. | ||
Practitioner Guidance
Why practitioners should care: A manual certification campaign should be treated as a temporary or targeted control, not as the default operating model for recurring access governance. Its value depends on how well it is scoped, contextualised, and closed out.
Common misunderstanding: A completed spreadsheet does not equal effective certification. If the process does not remove access, retain evidence, and update the source of truth, the campaign has produced paperwork rather than governance.
Practitioner takeaway: The best manual campaigns are narrow, risk-focused, and tightly closed looped, because the goal is to reduce access that should not exist, not to maximize review volume.
Related resources from NHI Mgmt Group
- How can organisations reduce manual effort in access certification and evidence collection?
- When does automated access review reduce risk more than manual certification?
- Why do manual access request and certification processes break down in SaaS environments?
- How should security teams reduce manual effort in access certification campaigns?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org