Recertification
In a recertification, responsible people check whether existing access is still needed and confirm or revoke it. Nova groups this review into campaigns. Administrators manage campaigns under “Compliance” → “Recertification”.
Creating a campaign
“New campaign” creates a campaign:
- “Scope” – whose access is reviewed: “All users”, a “Department”, an “Org unit” (without sub-units), all identities with an account in a “System”, or “AI Agents”. Nova excludes disabled and deleted identities.
- “Reviewer” – who reviews: the identity's “Manager”, the role's “Role owner”, a “Specific user” or, for AI agents, their “Agent owner (AI identity)”.
- “Deadline” – optional.
- “Campaign type” and “Standard” (e.g. ISO 27001) serve for classification.
Nova immediately creates one item per identity and assignment. Reviewed are the business-role and direct entitlement assignments valid on the day of creation; entitlements an identity receives through a business role are covered by reviewing that business role. Each item records identity, role, system and risk rating as at creation. Nova rejects a scope without items. For the “AI Agents” scope, the capabilities of linked routine agents are added as separate items.
If no reviewer can be resolved for an item, the person who created the campaign reviews it.
Flags on items
Nova flags items that deserve particular attention; the “Flagged” filter lists them together:
- “SoD conflict” – the assignment is part of a conflict under an active SoD rule.
- “External w/ high access” – an external identity holds a role rated “Critical”.
- “No peer holds this” – within the scope, only this one identity holds the role.
- “Reviewer defaulted to admin” – no reviewer could be resolved for the item.
Starting and deciding
A campaign starts as “Draft”. “Start” sets it to “In review”; Nova notifies every reviewer of the number of their items.
- Each item is decided with “Confirm” or “Revoke”. A revocation requires a reason.
- Reviewers decide only the items assigned to them; administrators decide all.
- Several items can be selected and decided together. “Confirm all” confirms all open items – for reviewers only their own.
- A decision is final. Nova stores it on the item with person, time and reason.
- Items can only be decided while the campaign is “In review”.
The “Deadline” does not close a campaign automatically. The background job “Recertification Deadline Reminder” reminds reviewers with open items at most once a day as soon as the deadline lies within “Remind within (days)” – default 7 – or has passed. Nova does not create this job by itself; administrators set it up under “Monitoring” → “Background Jobs”.
Completion and revocation
Once all items are decided, administrators close the campaign with “Complete campaign”. Nova asks whether the revocations should be executed now:
- Execute: Nova removes the revoked assignments in Nova – for a business role including the entitlements received through it. If “Auto-provision backend systems” is switched on, Nova starts provisioning runs for the affected identities to remove the roles in the target systems as well. If the capabilities of a routine agent are revoked, Nova switches that routine agent off.
- Do not execute: the decisions remain documented and the access stays in place. The campaign is closed nevertheless; the revocations can no longer be executed through it later.
Revocation only on completion
A “Revoke” only takes effect when the revocations are executed on completion. Until then, the access remains unchanged.
After completion, Nova notifies the person who created the campaign and the administrators. “Download CSV” gives administrators all items with reviewer, decision, reason, time, flags and revocation status as evidence. Completed campaigns show under “Risk reduction (revoked)” how many revoked assignments had which risk rating. Nova logs the creation, start, decisions and completion of a campaign.