Made in Germany
GDPR & NIS2 compliant
25 Jahre IAM Experts
Vendor- & cloud-independent
Reality Check:
When no one reviews what was once approved
Access rights are granted for good reasons: new projects, department changes and special assignments. But they are rarely removed with the same consistency. Without a reliable, understandable review rhythm, the number of overprivileged accounts continues to grow.
Gradual accumulation of access rights
Department changes accumulate access rights while old ones are never removed.
Blanket approval instead of real review
Too many cryptic codes lead to reflexive “Everything OK” approvals.
Expired deadlines without consequences
Without escalation, reviews simply remain buried in the inbox.
No distinction between group types
Critical admin groups are reviewed just as rarely as non-critical standard groups.
Days of detective work during audits
Without a review cycle, every auditor question turns into an Excel search.

Your recertification with the IDM-Portal

Understandable access rights,
deliberately reviewed
Technology translated into plain language
Recertification means that responsible owners actively confirm at defined intervals who should still belong to which group, with critical admin groups reviewed more often and non-critical standard groups less often.
In many IGA solutions, recertification fails because attribute names are difficult to understand. The FirstWare IDM-Portal translates technical directory data into the language of your business departments.
Decision-makers immediately see in plain language who has which rights and can decide conveniently with one click via the web interface. You gain real control for your IT security.
Relief through
intelligent automation
Where rules apply, manual review is no longer needed
Not every group membership requires manual confirmation. When you control standard groups via attribute-based automation (RBAC/ABAC), for example by location or department, manual review effort is eliminated. If the attribute changes in the HR system, access is automatically cleaned up.
For recertification, only what truly requires a deliberate human decision remains, such as particularly sensitive group memberships or administrative permissions.


Review cycles aligned with
actual risk
Individual intervals instead of a one-size-fits-all model
Not every permission needs the same review interval. In the IDM-Portal, you define flexibly per group or group type how often reviews take place (monthly, quarterly, semi-annually or annually) and who is responsible.
Assignment is handled easily using naming conventions, such as the prefix "ADM" for administrative groups, which are then automatically reviewed more frequently than regular teams. You invest review effort exactly where the risk is highest.
Deadlines and automatic escalation management
No review remains unnoticed
When a recertification is due, the responsible Group Owner is notified automatically. If they do not respond in time, automatic reminders follow, additionally sent to the responsible manager before IT security is involved as the final escalation level.
After the deadline expires, a final result report is sent, regardless of whether the review was completed or not.


Every decision is documented
automatically
Review evidence in seconds instead of hours
Every confirmation, every rejection and every access revocation is logged tamper-proof with timestamp and decision-maker ID.
When auditors request evidence under NIS2, ISO 27001, GDPR, TISAX or KRITIS, you can export the finished review report in seconds.
What is the FirstWare IDM-Portal?
Flexible IAM solution for Identity Governance & Administration
The FirstWare IDM-Portal is a user-friendly IAM solution for automated provisioning and lifecycle management of all identities and groups in complex, hybrid IT landscapes.
Powered by my-IAM – the underlying technology platform that enables seamless integration of any IT systems and cloud services.

Audit-proof recertification independent of your system landscape
Whether cloud-native, hybrid or on-premises – access rights and group memberships can be recertified across systems from a single web interface:
HR integration
Personio, SAP SuccessFactors, SD Worx / Loga3
Identity Providers & Directories
Microsoft Entra ID, Active Directory, Keycloak
Specialized & industry software
Integration of databases, cloud SaaS and industry-specific software via API/CSV connectors with centralized logging.
No matter how individually your system landscape has grown, you get a single, consistent view of all identities, regardless of where the data originally comes from.

Your benefits
Plain language instead of blanket approval
Less effort through automation
Risk-based review intervals
No more missed deadlines
Audit evidence at the push of a button
Made in Germany
Frequently Asked Questions
Frequently asked questions about recertification, regular access reviews, transparent approval processes and secure control of access rights with the FirstWare IDM-Portal.
What is recertification (attestation) in the IAM context?
Recertification is the regular, active confirmation by a responsible person (for example a Group Owner or manager) that an employee still needs a specific permission. It prevents the gradual accumulation of access rights that are no longer required.
Does advanced IAM automation make recertification unnecessary?
No, but it drastically reduces the effort. Groups whose membership is controlled purely based on attributes (for example location = Munich) do not have to be reviewed manually. For sensitive special rights and manually assigned permissions, recertification remains essential and is explicitly required by auditors, for example for NIS2 and ISO 27001.
Why do recertifications in traditional systems so often fail in practice?
Because department managers are often confronted with unreadable database names and Active Directory codes. Overwhelmed by this, they often approve everything by default (“allow all”). The FirstWare IDM-Portal solves this problem by presenting access rights in understandable business language.
What happens if a responsible person ignores recertification?
The FirstWare IDM-Portal includes integrated deadline and escalation management. If the primary decision-maker does not respond in time, the review request is automatically escalated to the manager or IT security.
How does recertification differ from auditing & reporting?
Auditing & reporting chronologically documents what happened in the past, such as who changed what and when. Recertification is the forward-looking control step that checks whether the current status quo of access rights is still appropriate.
Let’s Talk
Make recertification stress-free at last
Let us show you in a short live demo how your key users can complete recertifications in just a few minutes and without frustration.
Call us at 0 8196 - 998 4330 or use our contact form.
