Size an access certification campaign: decisions to make, reviewer hours, elapsed days and the annual effort across campaigns.
Certification effort is a straight product, which is why it grows alarmingly: doubling entitlements per identity doubles the campaign. Auto-approving low-risk decisions by policy and reviewing only exceptions is the only lever that changes the shape of the curve rather than its slope. Reviews that cannot finish inside their window get rubber-stamped in the last two days, which produces a clean audit artefact and no actual reduction in access.
Access Review
effort = identities × entitlements per identity × minutes per decision, less whatever policy auto-approves.
Campaign duration
elapsed days = hours per reviewer ÷ hours per day each reviewer can actually give.
effort = identities × entitlements per identity × minutes per decision, less whatever policy auto-approves. Certification effort is a straight product, which is why it grows alarmingly: doubling entitlements per identity doubles the campaign. Auto-approving low-risk decisions by policy and reviewing only exceptions is the only lever that changes the shape of the curve rather than its slope.
Reviews that cannot finish inside their window get rubber-stamped in the last two days, which produces a clean audit artefact and no actual reduction in access.
This calculator takes 8 inputs: Identities in scope, Entitlements per identity, Minutes per approve or revoke decision, Decisions auto-approved by policy, Reviewers taking part, Hours per day a reviewer can give, Days allowed for the campaign, Campaigns per year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Between roughly 30 seconds for a familiar group membership and several minutes when the reviewer has to work out what an entitlement grants. One to three minutes is the planning range, and the average rises sharply when entitlement names are technical rather than business-readable.
Reduce what is in scope rather than speeding up reviewers: auto-approve unchanged low-risk entitlements, review by role rather than by individual permission, certify privileged and data-sensitive access more often and everything else less often, and remove orphan and dormant accounts before the campaign starts instead of certifying them.