That headline is deliberately provocative. And no, you won’t get to zero in a single day. But there are tactical and strategic actions that can dramatically reduce the access recertification burden placed on the shoulders of your organization’s managers.
Access recertification is, without doubt, one of the areas where Identity Governance and Administration (IGA) most visibly fails. It is one of four major problem areas, alongside role management, application onboarding, and the tendency to over-customize IGA solutions to a point where they become unmanageable.
There is no organization I know of where departmental managers enthusiastically await the next recertification campaign. If there is one, I haven’t met it yet.
At the same time, there is no regulation anywhere that says: “You must present your managers with an enormous matrix of users and entitlements that no one truly understands, effectively pushing them toward rubber-stamping instead of risk mitigation.” To be fair, IGA vendors have invested significantly over the past years to improve the situation—by breaking down large campaigns, reducing matrix complexity, and providing more contextual information. Still, recertification remains a highly unpopular task.
If an industry has been trying to solve a problem for more than a decade and delivers mostly incremental improvements that address symptoms rather than root causes, it is time to step back and rethink the approach.
There are both tactical and strategic measures you can take.
Tactical Measures: Reduce the Noise First
Keep It Simple—and Lean
There is a thin line between sophistication and exaggeration. A good access model is lean. It is sophisticated where it needs to be, especially for business-critical entitlements, and pragmatic everywhere else. Most importantly, it is immediately understandable.
I have seen countless projects where person-months were spent defining, explaining, and debating overly complex role models and terminology. Questions like “What exactly is an IT functional role?” or “Is this the same business role as in SAP?” are not signs of maturity. They are indicators of unnecessary complexity.
Automate What Can Be Automated
Most entitlements can be assigned based on policies using attributes such as job role, organizational unit, location, or reporting line. In my experience, this applies to roughly 90% of entitlements in organizations with reasonably mature business process and data management. Let’s be conservative and say it’s “only” 80%.
If an entitlement is granted automatically based on a well-defined policy, why should it be part of a manual recertification process? The IGA system simply needs to distinguish between policy-based and manually requested access. The math is simple: if 80% of entitlements are automated, the recertification workload drops to 20%.
This is not just about birthright access. These policies must work equally well for joiners, movers, relocations, and leavers. Yes, this requires proper policy governance and attribute data governance, but that is still far easier to manage than endless recertification campaigns.
Use Time-Limited Access by Default
Time-limited access is one of the most effective - and most underestimated - mechanisms. If your recertification interval is six months, there is no reason to review an entitlement that has only been in place for three months.
If entitlements are granted for a maximum of six months, there is nothing to recertify. Instead, access must be actively renewed or extended. That process is simpler, more targeted, and results in higher access quality.
I like to compare this to email handling. Some emails are filtered automatically. Some can be answered with a single click or a short reply. And then there are those emails you postpone because they require real effort. Approving or extending access is the “easy email.” A recertification task is the one you dread.
With proper staggering and automation, and with only a fraction of entitlements left after policy-based assignment, this becomes manageable and far more effective from a risk perspective.
Leverage Usage-Aware and AI-Driven IGA
Modern IGA can (and should) go beyond proposing role candidates—an application of AI I personally find rather uninspiring. Much more valuable is understanding actual entitlement usage.
Usage-aware IGA can identify entitlements that are never used, or that are only required under specific circumstances, for example, year-end financial closing. Such entitlements should not be permanently assigned. They should be provisioned just in time and removed automatically afterward.
Depending on the granularity of entitlements such as business roles versus technical permissions, this approach alone can eliminate 80% or more of existing access. Ask your IGA vendor about these capabilities. If they don’t have them, that is telling.
Strategic Measures: Fix the Root Cause
Strategically, organizations must move toward policy-based access control. This again requires policy governance and high-quality identity data, but it addresses the real root cause: static, long-lived entitlements.
Static entitlements are, quite frankly, at the heart of many IAM problems. To be fair, long-lived unmanaged secrets and identities deserve the same criticism. Moving away from them is not only about reducing recertification pain. It is essential for managing emerging realities such as ephemeral workload identities and autonomous identities at the intersection of AI and identity—what we increasingly refer to as AIdentity.
You may never reach absolute zero. If you include the recertification of policies themselves, you probably shouldn’t. But there are multiple proven approaches that can drastically reduce recertification effort, improve risk mitigation, and keep you compliant at the same time.
Learn More
You can explore these topics in much greater depth through a KuppingerCole membership, which provides access to our research and direct interaction with our analysts. And, of course, by joining Europe’s premier identity event, the European Identity and Cloud Conference (EIC) in Berlin, May 19–22.