Certification Campaign in Saviynt

What Is a Certification Campaign
in Saviynt?

A Certification Campaign (also called an Access Review Campaign)
in Saviynt IGA is a governance activity where managers,
application owners, or role owners review the access privileges assigned to users.
It helps verify whether users still require their access or not
ensuring access appropriateness.

Key Objectives

1.  Access Governance
Ensure users only have access relevant to their roles.
2. Regulatory Compliance
Meet audit and compliance requirements (e.g., SOX, GDPR, HIPAA).
3. Risk Mitigation
Detect and remove excessive or orphaned access.
4. Access Lifecycle Maintenance
Keep entitlements aligned with job responsibilities.

Steps to Create and Run a Certification Campaign

Here’s how a typical campaign runs in Saviynt :
1. Define the Campaign Scope

- The user triChoose campaign type (e.g., Manager, Application Owner, Role Owner).
- Specify applications, users, or entitlements to include.
- Set rules/filters (e.g., exclude service accounts)

2. Configure Review Details

- Define review attributes (access, roles, entitlements).
- Set reviewers (e.g., managers, owners).
- Choose certification actions (approve, revoke, delegate, etc.).

3. Set Campaign Options

- Define duration and reminders.
- Configure escalation policies.
- Enable automatic revocation if no action is taken (optional).

4. Launch the Campaign

- Reviewers get notified via email.They log into Saviynt’s Certification
- Dashboard to review and act on access.

5. Review & Decision

- Reviewers can approve, revoke, or delegate access.
- Actions can trigger workflows for deprovisioning.

6. Close & Report

- Once completed, the campaign is closed.
- Reports are generated for auditors (including reviewer actions and decisions).

Reporting and Auditing

Saviynt provides:

Best Practices

Core values that shape our approach to every client relationship and
project delivery.
1.  Schedule campaigns periodically (quarterly, bi-annually).
2. Use risk-based prioritization — focus on high-risk entitlements first.
3. Automate reminders and escalations.
4. Integrate with ticketing/deprovisioning systems (like ServiceNow).
5. Keep campaigns concise to improve reviewer participation.