Okay, here's the clicker. So some of what I say here is going to be repetitive, but it's going to be a more more of a story flow.
So, bear with me, but I think it will resonate with you. So I want to start with why are we having challenges with certifications. And when I think about it, I really put it into four different categories. The first one is volume. So we are pushing out way too much data to our reviewers. They're overwhelmed by the data. I'll be honest, I don't think there's anybody from SailPoint in the room.
No, no legal compliance. I am terrible at this. When I get my team's certifications, I skim it and I approve. And I know, I know, I've been doing this a really long time. I know that's a bad practice, but it's just too overwhelming and as we push this to the business, this is not their day job, right? This is not, they're worried about the business and this volume and frequency is just too much. So there's that. The second thing is the certification campaign lacks context. Lacks context. So I see all of this access and I see that this person has this entitlement.
Sometimes it's to systems I don't even know and the entitlements are even worse. I don't know anything about them. I don't know what it's enabling. The timing of it, it's a point in time review. So when you stage your campaign, you get a blueprint of access. By the time the campaign is done, typically 30 days, depending on your organization, that access and what you reviewed is no longer valid. It's still at that point. So it's not even a fresh representation of access. And last but not least is what we kind of hit on on the panel is the focus.
So, so much of it is centered on certifying a user to entitlement mapping. And I'll have to compare with the ideal state to make this one make sense. But the reality is we're always going to have to do campaigns just for audit purposes of some kind. It would be much better if we were certifying policies and roles and intent, if you will, versus each of those line items. Reduce volume, reduce volume, reduce volume at the end is what we're really trying to do there. So that's some of the challenge. We talked about some of these, but I just want to give you some data.
For the typical customer, revocation rates are less than 2%. That says it all. We are not reducing, we are not using the certification as a means for revoking access. It is not a compensating control.
So in, I don't know what you call them in your organizations, but in my history, we had our controls, which were the policies and access request and approval. The compensating control was considered the certification. It's not working. It is not a control. It is just the checkbox we talked about. Contrast this with request and approval. 85% of access is granted through request and approval. So many of you are in the room, a few new ones, so I'll repeat myself. But think about this.
If access request, 85 to 90% of access is approved via access request, and then we're not revoking any of it in our certifications, it means our users are overpermissioned. Quite certainly. And I don't know about you all, but many organizations still use model after. So what ends up happening is we do this, we have overpermissioned users, and we're still using model after. We all know it's a bad security practice, but dang, it's super easy, right? It's real convenient. So that is happening today. Couple that with standing privilege. Vast majority of access is provision and forget.
We provision it indefinitely. And that's really just the state of where we are. And so that being said, things are changing. I think there really is a shift happening, like I said. CellPoint kind of in many ways invented, created this problem. I can admit that now. But so it's sort of weird to hear someone from CellPoint say I want to kill certifications, but I fundamentally believe we have to. We have to. It's not going to scale, it's not going to work. Why? Probably the number one reason why is non-human identities, agentic specifically.
I mean, we have the problems we just talked about today already. Now you times that by whatever multiplier you're comfortable with, 5, 10, 100, you've seen them all. We don't exactly know what the ratio is going to be. But there's no way a certification will be at all effective at that point if we're trying to certify that kind of volume.
Obviously, regulatory pressures are increasing. So interestingly, regulatory pressures around, especially here, is around data and protecting data, protecting AI, and ensuring ownership of AI, etc. So we might have alarm bells going off thinking, okay, that means we're going to have more to certify. I think this should be a call to pause or action to say how can we audit differently, right? What can we do different for these new types of identities in this new type of world? Is there ways to look at things different than certification?
Cloud, multi-cloud, still a reality and an issue, and cyber threats. So the new normal in the landscape is pretty jarring. I spent the first part of this week visiting customers, and mythos got brought up in every single conversation. And I went in wanting to talk about cool new features that CellPoint's delivering, and I went in with everyone focused on how are we securing the CellPoint platform and resiliency. And the reality is the threats are moving really, really, really quickly.
And I think this thing in the middle is the biggest aha, is the mean time to exploit was one year in 2021, one hour this year. So I think that's the reality of our environment. And here's what I would say. We can't keep doing things the same. So I want to present to you what at CellPoint we're calling real-time governance and this shift into a world of real-time governance. So it isn't just about reducing certifications. So let me walk through these.
First, moving from a model of exclusive privilege where we apply the highest controls to a small percentage of the population, namely infrastructure admins, AD domain admins, all the PAM stuff that we've been doing for a long time as an industry. We do apply pretty strict controls there. But the reality is, think about all of us in our workforce. You have accounts payable clerks who maybe have payables over a million dollars, right? Or you have an HR administrator who has access to highly sensitive information, sometimes even medical information.
Those are privileged transactions that we put standard controls on today. We've got to start thinking about what are the highest privileged things in our environment. We refer to that as the democratization of privilege, privilege for everyone. Excessive privilege today, we talked about that being over-permissioned. We need to move to a least privileged model. Standing privilege, moving to a zero standing. I know you guys know what that is. You've heard lots about it this week, I'm sure. Point in time, checkbox compliance, compliance rituals, if you will, moving to continuous risk management.
And last but not least, manual process and human-derived access controls, aka access request and approvals, access certification, moving to an autonomous IAM model where you have a self-driving, self-healing identity system. I can tell you, I lived my life in product and development. Autonomous IAM has been a marketing term, quite honestly, for about 10 years. That is changing.
I mean, I've been in technology a long time. Vlad's known me for like 30 years. But the reality is, is that I have never seen anything like what I'm seeing right now. I don't think any of us have. So it's pretty fascinating, and I think we'll be there. So as we present this to the industry, there's a few things we're hearing from customers. And I'm really not going to make this a sell point, sales pitch. So I will say, this will be my only plug, is we're obviously innovating and moving in this area based on the customer needs.
But I want to spend some time talking through how to solve for the problem we just laid out. The first thing customers are saying to us is, I need visibility. I need to see what is going on in my environment. I don't know. And part of this is just sort of a history of identity, right? We have a bunch of different identity systems, or we have a bunch of different applications, have a bunch of different controls. They're spread out everywhere. And organizations just have, if you will, identity sprawl. So they want to bring it together so that they get visibility into access in their environment.
And I watched a session of Enrique's where he talked about start with identity. Just bring in all your identities first, right? We have all different kinds of identities, some of them managed in different systems. Let's start there. Bring in all the identities. Get a picture of that. Start bringing in their entitlements and applications. Then we kind of move into this second pillar of privilege discovery and classification. And I think it's so important to really understand that you're not going to be able to apply the strictest controls to everything. Apply them to what really matters.
So how do you figure out what really matters when you have literally hundreds of thousands of entitlements in your environment? And so look for tools and technology to help you look at your entitlement catalog, enhance and enrich your entitlement catalog with metadata and better descriptions. AI has gotten really good at that. I will tell you, at CellPoint, our AI-driven descriptions is our most used AI feature on our entire platform, which I think is fascinating. But get your descriptions in and then look for AI-driven tools to help you classify those entitlements.
So discover them in your environment and help you classify them. I know we have a tool that was recently released that helps you pick the highly privileged entitlements that the vendors have identified. And we're using AI to enhance that and enrich that based on rules and policies you establish to scrub your entitlement catalog and recommend high-privileged entitlements. So super cool.
But by the time you have your, if you will, graph or your registry of all of your identities, all of your events, you have privilege identified, and you can start with your security posture management tools to identify risk and really understand what are your access pathways, where do you have overprivileged access, where do you have multiple access pathways to those highly privileged entitlements, you can start to form better policy around that. And that moves us into this third pillar, which is least privilege and governance. So we talked a lot about least privilege.
It's been around for over 50 years. This is not a new concept. But I do think, again, I'm repeating myself, we're in a world of agentic that we have to use policy. We just have to get there. And we've been, there's lots of reasons, something we didn't talk about on the panel. I think the hardest reason is because nobody actually knows who needs access to what, period. No one knows. I don't know what I need access to. My manager sure doesn't know. I am administrators, have no idea what people need access to.
The legal doesn't know, security doesn't know, HR doesn't know, even the app owner doesn't know who needs access to what. We don't know. And I think that's a, it was a flawed premise we started with was that we're going to go define policy and I'll just go talk to the app owner or I'll go talk to HR or whomever. And then you get there and they're just as lost as you are as the IAM admin. So how do we do it better, I think becomes the question. And this is going to bleed into column six a little bit.
But I do think that AI tooling and the power to gather usage and behavioral data is going to help inform policy. The ability just to pull data right now, AI is getting a whole lot smarter at recommending policy to us. So there is hope on the horizon. Regardless, we have to get there. We have to move to a policy driven model. AI is going to demand it, period. Like we cannot be using request and approval flows for the vast majority of access. It won't work. So I say least privilege, ensuring users have the minimal access necessary. And then access review and certification.
I am on a mission to kill it, but I also am real. I mean, I'm just saying that for effect, I think. We're going to have certifications of some kind. We have to because there's things, some kind of reporting. Maybe we don't need to call it certification, but we have to have some kind of reporting. I don't see a world where that goes away. I see a world where probably we have to do more of it. We just got to make it easier. And this is really where AI driven certification campaigns comes in to the equation. So now we've got more data as we've put these things in. We have policy.
We're moving to a policy driven model. You can apply rules, let's say, on top of your certification campaigns to really start to filter and minimize what has to get certified. And that's pretty exciting. I will tell you right now, we have a product that we're releasing to the market forthcoming. So we're not necessarily announcing anything that's more of a feature than a product, I should say. But we're in a POC with some very large customers who are using this. And I would have been happy to say a 10 percent reduction in line items in the campaign.
One of the largest customers hit 65 percent reduction in line items from applying this. At sell point ourselves as customer zero, we hit 80 percent and the other customer hit 10 percent. So it's pretty cool because you can put some thresholds in, define some rules and filter that campaign down. So as a leader, as a business owner, if I get a campaign and I have five things to certify, but I know there are highly sensitive things that didn't pass all those other checks, I'm going to pay more attention. So we've got to change the game. Two minutes left.
The rest of them are somewhat self-explanatory except for the last one. Obviously, just-in-time in all of its modalities. Think of just-in-time, it could be time-based. You only provision it for 90 days. You could do what we call just-in-time provisioning. And in this case, it kind of mimics the traditions of PAM vendors where you allow access, but the person has to check it out. So we refer to that as just-in-time provisioning. Just-in-time provisioning with conditions. So when you go to check it out, you check conditions and the environment and say, is this device healthy?
Is it company-owned? Are they coming at the right time of day? You guys know the drill. But that's really, and then finally is just-in-time or real-time authorization where you're actually forming the authorization decision at the point of access. It's not pre-provisioned at all. So these are exciting modalities. They're definitely going to reduce what gets certified. Because that stuff, the policy will get certified, but not the line item. Continuous risk detection and response is along the same lines, is not only are we checking conditions at the point of access, but once they're in session.
It used to be that once a user logged in, identity was out. No longer did we apply security technologies, took over, DLP, whatever.
Today, identity lives on into the session, and we're making authorization decisions even in session. And this really moves us to that continuous risk management, going from compliance rituals to continuous risk management. And then the last thing I want to bring up, and I'm going to be on time for probably the first time in my life, is autonomous IAM, where now I have this wealth of data. I have events coming in. I have mappings and relationships. I have policy. I have the ability now to put LLMs on top of things like usage data, et cetera, and have a self-healing identity system.
This, I'm retiring when this delivers, because this is the utopian dream, really, truly, of being able to get to a place where the system actually knows who needs access to what. That's the aha moment, is the system now knows.
And so, super excited for that. All of this ends up bringing us to a place of reduced certification.
So, thank you, everybody. First of all, thank you, Laurie. We have three minutes. We are in this ominous room-changing break.
So, that gives us the chance, first, to change rooms if you want to. And second, if there's one question left with a short answer, that would be your option. Is there a question in the room? Don't queue.
Okay, then we leave it with that. We have one hour coming up. If you stay in the room, you are in for a treat.
First, with PwC talking about CIM, and then a 40-minute discussion with Eve Mahler and Dean Sachs talking about the digital estate, which is really a great topic. And after that, we have a break, Martin's closing keynote.
Yeah, that's it for me. Thank you very much again, Laurie, for being here today.