What Is Access Certification in SailPoint IIQ?
Access certification in SailPoint IIQ is an automated review process where designated reviewers — typically managers or application owners — examine what access users currently hold and formally approve or revoke it. IdentityIQ generates the review lists, routes them to the right certifiers, records every decision, and executes the revocations.
Think of it as the enterprise equivalent of an audit roll-call. Over time, employees accumulate access: a developer who moved from the payments team to the lending team eighteen months ago may still hold payments database entitlements nobody remembered to remove. Access certification is the structured process that catches exactly this kind of access creep before an auditor — or an attacker — does.
One terminology point trips up almost every learner. In IIQ, a certification is the overall campaign — the scheduled event defining what gets reviewed, by whom, and by when. An access review is the individual work item a single reviewer receives within that campaign. One quarterly manager certification can generate hundreds of separate access reviews, one per manager. SailPoint's official Certifications and Access Reviews documentation uses this distinction consistently, and so do interviewers.
Quick answer: Access certification = a scheduled, audited review where managers and application owners confirm or revoke user access. It is the single most audit-visible capability in SailPoint IIQ, and it is covered as Module 11 of 14 in the SailPoint Academy curriculum.
Why Do Enterprises Run Access Certification Campaigns?
Enterprises run access certification campaigns because regulators and auditors require documented, periodic proof that user access is reviewed and excess access is removed. This is not an optional hygiene practice — for regulated companies it is mandated, which is precisely why certification skills are tested in nearly every SailPoint IIQ interview.
Three regulatory drivers dominate in the enterprises that hire SailPoint professionals in India:
SOX & SOC 2
US-listed companies and BFSI GCCs in Hyderabad and Bangalore must show auditors periodic access attestation and segregation-of-duties enforcement on financial systems.
RBI IT Governance
India's Reserve Bank requires financial institutions to run periodic access reviews for employees and contractors as part of identity lifecycle controls.
DPDP Act 2023
India's data protection law pushes enterprises to prove who can access personal data — driving recurring certification of data-touching entitlements.
In practice, this means a BFSI GCC will run manager certifications every quarter, application owner certifications on critical financial apps every half-year, and event-based certifications whenever someone changes departments. Each completed campaign becomes audit evidence. When an external auditor asks "prove that access to your payments platform was reviewed this year," the IAM team exports the campaign decision history from IIQ. That export is the deliverable the entire process exists to produce.
The 7 Certification Types in SailPoint IIQ
SailPoint IIQ supports seven certification approaches, and a working consultant is expected to know when to use each. These map exactly to what Module 11 (Access Certification) of the SailPoint Academy 14-module curriculum covers:
1. Entitlement Certification
Reviews individual entitlements — the granular permissions users hold on applications. The most fine-grained review and the foundation of access governance.
2. Role Certification
Reviews role assignments and role composition — does this business role still contain the right IT entitlements, and should this user still hold it?
3. Advance Certification
Targeted, filtered certifications scoped to a precise population or access slice — for example, only privileged entitlements on a specific application.
4. Manager Certification
Each manager reviews their direct reports' access. The most commonly scheduled certification in production — usually quarterly in BFSI environments.
5. App Owner Certification
The owner of an application reviews everyone who has access to it. Standard for critical financial and customer-data systems.
6. Certification Rule
BeanShell rules that customize certification behaviour — pre-delegation, exclusion logic, escalations, and decision automation hooks.
7. Event-Based Certification
Triggered automatically by identity changes — a manager change or department move can launch an immediate review routed to the new manager.
The combination interviewers probe
Event-based certification is where Module 11 meets Module 12 (Lifecycle Events). A mover event — someone changing departments — can trigger a certification routed to the new manager automatically. Interviewers love this question because it tests whether you understand how IIQ modules connect, not just their definitions. Read our Lifecycle Events explainer for the other half of that answer.
Want to configure a real certification campaign yourself?
Attend a free 60-minute live demo before you decide — no payment, no commitment.
The 4 Phases of a Certification Campaign
Every IIQ certification moves through up to four phases: Active, Challenge (optional), Revocation, and End. Knowing the order and what happens in each phase is one of the most reliably asked SailPoint IIQ interview questions — and the source of most real-world campaign configuration mistakes.
Active Phase
The review period. Certifiers work through their access reviews and make approve or revoke decisions. Decisions can be changed as often as needed until the active period expires.
Always presentChallenge Phase
Users marked for revocation receive a work item and email with the details. They can accept the loss of access or challenge the decision — and the certifier must respond to each challenge.
OptionalRevocation Phase
Approved revocations are executed. Where provisioning is connected, IIQ removes access automatically; for disconnected systems, manual work items go to application revokers.
ConfigurableEnd Phase
The campaign closes and the audit record is finalized. If no revocation phase was enabled, outstanding revocations are processed during the end period.
Always presentThe phase definitions above follow SailPoint's official Phases of a Certification documentation. Two details separate candidates who have actually configured campaigns from those who memorized definitions: the challenge phase is optional and frequently disabled in fast-cycle environments, and revocation can be fully automatic only where IIQ has a provisioning connection to the target application.
How a Real Quarterly Certification Campaign Runs — Step by Step
A quarterly manager certification at a typical BFSI GCC follows six steps from planning to audit sign-off. This is the workflow you would own as a SailPoint IIQ consultant or IAM engineer:
- Define scope and schedule. The IAM team decides what is certified (entitlements, roles, or full identity access), which applications and populations are in scope, who certifies, and the phase durations. The certification is scheduled in IIQ.
- Generate reviews and notify certifiers. At launch, IIQ creates one access review work item per certifier and emails them. A 400-manager organisation gets 400 access reviews in one campaign.
- Review during the active phase. Managers work through their lists, approving access that matches the person's current job and revoking what does not. The IAM team chases completion — in real deployments, reminder escalations are configured because managers procrastinate.
- Handle challenges. If enabled, users disputing a revocation raise challenges, and certifiers must resolve each one before the item proceeds.
- Execute revocations. Connected applications get automatic deprovisioning; disconnected ones generate manual work items that must be tracked to closure — unclosed revocation work items are a classic audit finding.
- Sign off and export evidence. Certifiers sign off, the campaign closes, and completion reports plus decision histories are exported as audit evidence.
What the documentation doesn't tell you: the hardest part of running certifications in production is not configuration — it is certifier behaviour. Reviewers bulk-approving everything without reading ("rubber-stamping") is the number one reason auditors reject certification evidence. Real campaigns counter this with smaller scoped reviews, exclusion rules that remove noise, and escalation reminders — all configured through the Certification Rules covered in Module 11.
How Access Certification Shows Up in SailPoint IIQ Interviews
Access certification is one of the three most-tested IIQ topics in enterprise interviews, alongside lifecycle events and application onboarding. Consultant and developer candidates at Big 4 firms and BFSI GCCs should be ready for these recurring questions:
- Name the certification types in IIQ and explain when you would use manager certification versus application owner certification.
- Walk through the phases of a certification campaign in order — and explain what happens if the challenge phase is disabled.
- What happens technically when a reviewer revokes an entitlement on a connected application versus a disconnected one?
- How would you configure an event-based certification when an identity's manager changes?
- How do you reduce rubber-stamping in a manager certification campaign?
The pattern across all five: interviewers reward answers grounded in campaign behaviour, not definitions. Saying "the challenge phase is optional and adds a dispute window between decision and revocation" signals hands-on exposure. For the broader question bank, see our SailPoint IIQ interview questions guide, and for where certification skills fit in the larger career ladder, our IAM career paths page maps the roles that test them.
How SailPoint Academy Teaches Access Certification (Module 11)
SailPoint Academy covers access certification as Module 11 of its 14-module live online program — and it is taught hands-on, with every student configuring and running campaigns in a live IIQ environment rather than watching slides.
Module 11: Access Certification — Full Topic List
- Entitlement Certification
- Role Certification
- Advance Certification
- Manager Certification
- App Owner Certification
- Certification Rule
- Event-based Certification
What You Practice Live
- Scheduling a manager certification campaign end-to-end
- Configuring challenge and revocation phase durations
- Writing a certification exclusion rule in BeanShell
- Triggering an event-based certification from a mover event
- Reading campaign reports the way an auditor does
The program is 100% live on Zoom, capped at 25 students per batch, runs 2 months, and costs Rs. 25,000. Because the training is live online, it is accessible to IT professionals anywhere — India, the US, the UK, or the Middle East. SailPoint Academy is an independent training provider and is not affiliated with SailPoint Technologies; students receive a SailPoint Academy certificate of completion along with placement assistance, resume support, and mock interviews. Full details are on the SailPoint IIQ course page.
Frequently Asked Questions
Learn Access Certification by Actually Running Campaigns
Attend a free 60-minute live demo — see a real certification campaign configured in a live IIQ environment, meet the trainer, and decide with complete clarity. No payment. No commitment.
