IT CanvassTalk to an advisor
Core concepts · LessonBy , SailPoint Trainer, 7 yrs · Published · IdentityIQ 8.4 · intermediate

Access certifications

Access certifications are the periodic reviews where managers confirm that people still need the access they hold.

Quick answer

An access certification, or attestation, is a campaign where reviewers, usually managers or application owners, look at who has what access and decide to keep or revoke it. IdentityIQ generates the review items, tracks every decision for audit, and provisions revocations automatically when the campaign closes.

Key takeaways
  • Certifications are periodic access reviews for compliance
  • Reviewers approve or revoke each access item
  • Common types: manager, application owner, role, entitlement owner
  • Revocations flow into automated provisioning
  • Every decision is recorded for audit

Access certifications are the periodic reviews where managers confirm that people still need the access they hold.

Access certifications are the periodic reviews in which designated reviewers look at the access people hold and explicitly attest that each item is still appropriate, revoking what is not. They are the single most important source of compliance evidence in SailPoint and the primary mechanism for catching access drift.

How a certification works

  • A campaign is generated against a defined population (a manager’s reports, an application’s users, a set of roles).
  • Each reviewer receives work items listing the access to review.
  • The reviewer approves (still needed) or revokes (should be removed) each item, with comments.
  • Revocations feed the provisioning engine to actually remove the access.
  • Every decision is recorded, and that record is the audit evidence.

Types of certification

  • Manager certifications, a manager reviews their team’s access.
  • Application/entitlement owner certifications, an owner reviews who holds their access.
  • Role membership certifications, review who is in a role.
  • Targeted/event-based micro-certifications, triggered by a risky change, far more effective than annual sweeps.

The enemy: rubber-stamping

A certification where reviewers approve everything is audit theatre, not control. The fix is context: plain-language entitlement descriptions (via Managed Attributes), risk and outlier flags, and campaigns scoped to a reviewable size. A reviewer shown 40 clearly-described items with outliers highlighted makes real decisions; one shown 800 cryptic items approves them all.

Certifications and least privilege

Certifications are how access drift is reversed over time. Combined with lifecycle-driven revocation, they continuously pull the environment back toward least privilege, catching the access that accumulated between role changes and never got removed.

Closing the loop

A revocation is only real when it provisions. Ensure that revoke decisions actually flow to the target systems, a certification that records revocations but never removes the access satisfies no one and creates false assurance.

Common pitfalls

  • Oversized campaigns causing rubber-stamping and generation performance problems.
  • Undescribed entitlements reviewers cannot judge.
  • Revocations that never provision, decisions recorded but access not removed.
Want this with a live instructor and a lab tenant?
SailPoint IGA training →

Practice challenge

+0 XPStreak ×0
Question 1 of 3
An access certification is used to?
Want this with a live instructor and a lab tenant?
SailPoint IGA training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support