Knowledge Article
Certification Best Practices
Author
neil_mcglennon
SailPoint
Overview
Certification is an important governance feature that allows organizations to meet important audit, risk, and compliance guidelines to ensure the risk to their organization is well managed.
This is done by aggregating all accesses within an organization and presenting them to access reviewers, or certifiers, in order to make decisions if access is appropriate or not. Certification processes attempt to help answer if access should still be granted to a particular identity, and if not, then remove that altogether.
Certification may go by other names as well - access reviews, attestations, campaigns, certs, or others. Whatever your organization calls it, it still stands out a very important feature, that you want to get right. This document walks through the certification process, and talks about the overall certification best practices that you might want to consider for your organization.
Certification Process
The overall certification process consists of several phases, which we will discuss further in detail.

Certification Campaign Definition
In this phase, certification administrators define the certification campaigns which will ultimately be sent out to certifiers for access review.
The definition process involves defining the identities and accesses to be reviewed within a certification, the certifiers who will be reviewing a certification, as well as other behavioral aspects of the certification. This section describes some of those considerations.
Certifiers
A key aspect of certification definition is understanding who will actually be performing the access review. Certifications can be given to either individual certifiers or to groups of certifiers (via a governance group). Certifications can also be given to certifiers via relationship criteria as well - via ownership or manager.
Making sure the accesses go to the appropriate reviewer is very important from an audit standpoint. Determining the correct person to send an access review to is just as important as the performing of the access review itself. You want to make sure the certifiers are qualified to make the decision and have the tools necessary to understand what they are looking at. Otherwise certifiers don’t understand what they are looking at, can mistakenly remove things that might otherwise be necessary. With incorrect certifiers, there can be hidden risks too, as the question of appropriateness and completeness comes into question from auditors.
For general access, managers tend to be the closest to understanding what their direct reports do on a day-to-day basis, and therefore tend to understand what access they need the best. Manager certifications tend to be a staple of access reviews and are often the starting point for most organizations. Beyond that, specialized or complex access typically go to some sort of owner of that access, such as a source, access, or data owner.
The concept of self-certification or reviewing your own access tends to be a violation of audit principles. As a result, SailPoint has built-in functionality based on this best practice to prevent self-certification. Whenever a situation arises where access might be assigned to yourself, it is instead sent to your manager for access review. This tends to be in line with who the most common reviewers are, and likewise the manager could reassign as needed.
Amount of Time
This includes setting the length of time for a certification by electing a due date. As part of best practice, certification administrators should choose a due date that gives adequate time for their certifiers to effectively perform an access review. The amount of time given in a certification usually depends on a few key aspects - familiarity, certification cadence, and volume of access. If access is reviewed fairly frequently (say monthly) the decisions may be well-known to certifiers; likewise if access is familiar to certifiers, then they may not need as much time to perform the certification. However if there are large volumes of access, you may want to give certifiers more time to review.
Access Recommendations
One of the biggest problems in a certification is giving certifiers enough context to understand if access should be granted or not. While SailPoint provides details around identity, account, access, and activity information, sometimes further context - in relation to others - is needed. This is where access recommendations comes into play.
Access recommendations is a features based on SailPoint’s AI-based data intelligence platform, which analyzes users' access in relation to access-based peer groups, or a variety of other factors, such as similarities within department, location, access, etc. This understanding, along with historical relevance, can form contextual recommendations to certifiers to help them determine the best course of action.
Including these recommendations is a simple ‘on’ or ‘off’ configuration which can be included with each certification definition. As a best practice, SailPoint recommends opting into access recommendations to assist certifiers with their decisions.
Running Certifications
Certification definitions can be run immediately, or scheduled for future use (e.g. monthly certifications). Certification definitions can also be configured as part of workflow actions for usage in event-based scenarios - commonly for mover-based workflows, outlier detection, or discovery of out-of-band access.
Certification Generation
In this phase, a certification campaign is created and calculated by applying a certification campaign definition to the current state (i.e., snapshot) of the identity and access information. This usually happens automatically when a certification administrator runs a certification, or a particular schedule or time-based event is met.
While SailPoint has optimized around various certification processes, the time a certification spends in the generation phase depends on the amount of identity and access data to process and the overall complexity of the certification.
Once the certification has been generated, it automatically moves to the Preview phase.
Preview Phase
Once the certification campaign has been generated, it is available in the Preview phase. This stage is meant as an administrative window to look at the certification campaign before it is sent out to certifiers. Using this preview stage is considered a best practice as it allows certification administrators to correct any mistakes before they are sent out to the business. Generated certifications can be cancelled, reassigned, or event started if the results look good.
Once the certification has been started, it automatically moves to the Active phase, and any configured notifications are also sent out.
Active Phase
This phase certifiers perform the important decisions on accesses within an assigned certification campaign.
Certification Actions
Certifiers primarily elect either approve or revoke for the various assigned access items in the certification. Approve decisions essentially mean that the identity being reviewed should continue to have that access, and represents a net no-change to provisioning. Revoke decisions means the access being reviewed should be removed, and upon sign-off, any revocations are essentially items to be removed via provisioning.
Approval Differences: According to most auditors, a certification approval doesn’t serve as an after-the-fact replacement for an access request approval, as there are typically less people involved in access reviews.
For roles which are assigned automatically, the certifier can only acknowledge their assignment, but not otherwise revoke it, since it is automatically assigned via some sort of assignment criteria (e.g., job title equals Developer).
For identities or access which may be wrongly-assigned to a certifier, these can also be reassigned to other certifiers. By reassigning something, it effectively moves the responsibility of performing that certification decision to someone else. Most certifiers use this as an accountable form of delegation, and auditing and decision history carries with it. Just because a certifier reassigns something, doesn’t necessarily mean they can pawn their review duties off, as reassignments can also be reassigned back as well.
All decisions approve, revoke, and reassignments can also be done in bulk. These are meant as convenience and usability feature for making decisions easier within access reviews. It helps prevent decision fatigue. There is often debate as to intent behind usage of bulk features, so as best practice SailPoint tracks bulk decisions slightly differently than deliberate decisions in a certification campaign. These can be tracked to determine if certifiers are simply “rubber-stamping” their certifications instead of performing deliberate, intentional decisions.
Lastly, comments can also be added to certifications as well and serve as part of certification audit record.
Sign-Off
Upon certification completion, a certifier will be prompted to sign-off. The sign-off action represents a certifiers' final access review decisions. When they sign-off, no further decisions can occur, and a certification moves to its End phase. Subsequently any final revocations are also sent out to downstream provisioning channels.
End Phase
The end phase of the certification process is the final phase when either a certification has been signed-off, or has reached its due date.
Access Revocation and Remediation
Upon finalized certification sign-off or administrative closure of a certification process, any decisions to revoke or remove access need to be carried out, and subsequently sent to the target systems for provisioning. These are sometimes also known as remediations.
At this point, the access revocations are considered final and cannot be cancelled. How the provisioning fulfillment is completed entirely depends on the provisioning configuration of the source system. If accesses are from a source which does not support provisioning (like many delimited files) then a manual task will be generated for fulfillment. If accesses are from a source which supported direct provisioning (e.g. Active Directory, among many others) then provisioning will be fulfilled automatically via that source connector. If any service desk integrations (e.g. ServiceNow Service Desk Integration) are configured, and the source is part of a service desk integration, then the access revocations may flow over to be provisioned via that means as well.
Certification Approach
SailPoint’s approach for managing access reviews is to work smarter, not harder. Keep things simple, yet sophisticated, to ensure that all access for all identities is reviewed by the appropriate decision-maker (aka certifier). This will help ensure we abide by audit principles of completeness and appropriateness.
The way we do this is that we break dependencies away from a complex or tiered models, and instead leverage a layered certification model based on circumstance and appropriate reviewers. By not using a tiered model, there are no data dependencies between certifications. Certifiers can make decisions independently based on their own merit and guidance without cross-influence. There is less intrinsic approval carry-over, and the decisions tend to be more accurate.
For guidance around what access someone should or shouldn’t have - forget self-assignment or self-delegation - that is fraught with audit issues and introduces complexities and timing issues. Use AI-based access review recommendations to see how people stack up and compare with their peers. This can help certifiers in any certification campaign understand the context around who has the access and why.
SailPoint’s rich certification user interface helps certifiers understand everything they are looking at, including rich descriptions, icons, and details about identities, accounts, and access contents for items in the certification campaign.
Certification campaigns can be defined, rolled out, monitored, and administered in an easier fashion. It is easier to track what has and hasn’t been certified and ensure that auditors are happy that everything has been reviewed. In addition, because these are in a layered fashion they can be staggered, or they can even be run in parallel - its all the administrators choice in timing or events - which helps make sure certifiers have the appropriate amount of time to make decisions, and even change their mind, before signing-off as a final audit record.
Other Considerations
This section discusses additional considerations and best practices which you might want to consider for access certifications.
Descriptions
Successful governance implementations hinge on discovery - being able to understand the accesses that you are reviewing. Make sure that all accesses - roles, access profiles, and entitlements are adequately named and have rich, meaningful descriptions. This will help end users find and understand what they are reviewing and make the best of any sort of certification process. Making regular adjustments to these descriptions are a key preparation for any sort of certification cycle.
Account Correlation
Account correlation is the process of associating an account to its owning identity. As part of normal source administration, sources should be configured to automatically correlate to their identities as much as possible. In the event of failure to correlate, then accounts can be manually correlated to an identity. Management of account correlation is a key step to preparing for access reviews, so that the right accounts are associated with the right identities. This helps accesses get to the right reviewers, and also helps them determine the right decisions for that access.
Despite account correlation efforts, there may always be uncorrelated accounts. Any accounts that remain uncorrelated, can be reviewed by leveraging the uncorrelated accounts certification type. This will allow the uncorrelated accounts to be reviewed by certifier(s) that are appropriate.
Manager and Ownership
Manager is a foundational relationship that is used for anything from approval processes, to escalation processes, and more. Because of the foundational aspect of this, it is important to make sure that managers are defined in the system. If someone doesn’t have a manager, then they will not be certified. If they have an incorrect manager, that incorrect manager will be sent a certification. Missing managers identified with a simple out-of-the-box ‘missing managers’ identity search: NOT _exists_:manager
Check for appropriateness too. Just because there is a manager doesn’t mean it is correct! Incorrect data can also cause information to go to the wrong places.
Make sure that all accesses have proper ownership defined. This will not only help your certification processes, but help your overall governance of these accesses in general. These can be applied to things like role composition certifications, as well as reporting and searching for access by owner. A best practice recommended by SailPoint is to construct subscribed search queries which look for objects which are owned by users who have a lifecycle state set to a non-active value. This is a good way to catch “stranded” objects and re-designate owners for them when users leave your organization.
Workflows and Events
Certifications don’t have to be a static thing that run on a scheduled or ad-hoc basis. They can also be driven in response to events internally within SailPoint, or even externally in response to events. Workflows have defined actions for creating and activating certification campaigns.
Mover Scenario
One best practice scenario to review access whenever a person changes jobs or moves throughout the organization. This can easily be accomplished with SailPoint workflow capabilities by using an identity attribute changed trigger, and actions to create and activate a certification campaign for that identity. In fact, this is also included in the default Identity Security Cloud Mover workflow template.
Outlier Detection
Another best practice is to review access whenever an identity outlier is detected. Identity Outliers are a feature of SailPoint products where identities' accesses are compared to their peers, and are categorized according to low or high access distributions. Identities with low access similarity are called Low Similarity Outliers, and can be caused by ultra-specialized accesses. These can be specific, specialized functions in an organization, and are usually exceptions to the norm. Identities with high access similarity to multiple populations are called Structural Outliers, and usually are a sign that someone has accumulated access that might need to be pruned back - usually with an access review process. Whenever an identity outlier is detected, a workflow can be triggered, and in response certifications can be created and activated accordingly.
Out-of-Band Access Detection
Another best practice to review access whenever out-of-band access is detected. This can easily be accomplished with SailPoint workflow capabilities by using a source account updated trigger, and actions to create and activate a certification campaign for that identity.
Service Desks
Identity Security Cloud has a variety of integrations with service desk solutions, which you may want to consider for certification revocations when there is not the ability to directly provision - from either a technical or business standpoint.
Extensibility
Identity Security Cloud offers a rich set of REST APIs and event triggers which can allow extensibility and integration of certifications into various other systems. Here are some relevant REST APIs and Events which you might consider using as part of certification integrations:
REST APIs
- Certifications
- Certification Campaigns
- List Certification Campaigns
- Get Certification Campaign
- Create Certification Campaign
- Update Certification Campaign
- Delete Certification Campaign
- Activate
- Complete
- Run Certification Campaign Remediation Scan
- Reassign Certification Campaign
- Get Reports
- Run Report
- Get Reports Configuration
- Set Reports Configuration
- Campaign Templates
- Public Identities Config
Event Triggers
- Certification Campaign Generated
- Certification Campaign Activated
- Certification Campaign Ended
- Certification Signed-Off
- Outlier Detected