Manav.id
Compliance · 4 min read

The economics of review: how much attestation can an organisation afford?

The economics of review: how much attestation can an organisation afford?

Reviewer time is treated as free because it does not appear on the identity programme's budget. It appears on everyone else's, distributed across hundreds of managers, and it is the single largest cost of running access certification.

How much attestation can an organisation afford?

Far less than it currently spends, and it spends it uniformly. Certification campaigns allocate scarce human review evenly across entitlements whose risk differs by orders of magnitude. Attention is the budget, and spreading it flat guarantees the high-risk items get the same seconds as the trivial ones.

Key takeaways
  • Campaign scope is driven by connector coverage and audit scope, not by risk-weighted value of review. Because reviewer time is uncosted, the programme expands until quality collapses.
  • The total annual attestation cost is computable from data you already have, and it is usually larger than the identity programme's entire budget.
  • There is a crossover point where a cryptographic per-action gate on a narrow high-risk set outperforms broad periodic review.

Prerequisites

10,000 items in the campaignuniform treatmentReviewer has ~2 hoursrealisticallyUnder a second per itemarithmeticHigh-risk items get the same secondas a mailing list
The total review time is roughly constant. Only its distribution is a choice.

Step 1 — Compute the annual bill

Straightforward arithmetic that nobody runs.

annual_cost = campaigns_per_year
            × reviewers_per_campaign
            × median_minutes_per_reviewer
            ÷ 60
            × loaded_hourly_rate

Worked example at three organisation sizes, using a loaded management rate of $95 per hour:

Illustrative. Substitute your own campaign data; the magnitude is the point.
OrganisationReviewersCampaigns/yrMedian min/reviewerAnnual cost
3,000 employees220435$48,800
15,000 employees1,150448$349,600
60,000 employees4,400455$1,532,000

Two observations. The largest figure exceeds most identity programme budgets outright. And none of these organisations has this number in any document.

Step 2 — Compute what it buys

Now weight the spend by risk. Classify entitlements into three tiers by the consequence of inappropriate access, and compute what share of the review minutes each tier consumes.

In every estate this has been measured, the distribution is inverted: the low-risk tier holds the overwhelming majority of items and therefore consumes the overwhelming majority of review time, while the high-risk tier — privileged access, financially significant transactions, sensitive data — is a small minority of items and receives a proportionate minority of attention.

That is not a failure of the reviewers. It is what uniform allocation produces.

Step 3 — Find the crossover

For a given entitlement class, compare two approaches.

Periodic certificationPer-action gate
Cost driverItems × reviewers × frequencyActions × gesture time
Cost timingFixed, quarterlyVariable, per use
Evidence producedA decision about standing accessA record of each use
Better whenAccess is broad and rarely exercisedAccess is narrow and consequentially exercised

The crossover is where action frequency is low relative to the population holding the entitlement. A privileged entitlement held by 40 people and exercised 12 times a month is cheaper and better governed by a per-action gate than by quarterly certification of 40 items.

Step 4 — Reallocate rather than reduce

The output of this analysis should not be a smaller programme. It should be the same budget spent differently:

  1. Remove low-risk entitlements from certification scope entirely, where audit scope permits. Document the risk rationale.
  2. Increase depth on the high-risk tier — fewer items, better descriptions, longer review windows.
  3. Move the narrow, high-consequence, low-frequency set to per-action gating.
  4. Reinvest a portion of the freed time in entitlement description quality, which raises the value of everything else.

The constraint that limits this

Audit scope may mandate certification of entitlements your risk model would deprioritise. That is a real constraint and it should be negotiated with the external auditor rather than ignored.

The negotiation is more likely to succeed when you arrive with a costed risk-weighted allocation than with a request to do less. Auditors respond to a documented rationale; they do not respond to programme fatigue.

Doing the arithmetic

Where the budget actually goes
ScenarioSeconds per itemQuality
10,000 items, 2 hours, uniform0.7None
1,000 items, 2 hours, uniform7Low
200 high-risk items, 2 hours36Meaningful
9,800 low-risk itemsAutomated rulesAppropriate

The arithmetic is not subtle and it is rarely done. A programme that reduces campaign scope by 95% and reviews the remainder properly produces more assurance than one that certifies everything.

Objections and honest limits

“Auditors expect full-scope campaigns.” They expect a control that operates. A risk-tiered programme with documented criteria and demonstrable review on the high tier is a stronger story than a full-scope campaign with a zero revocation rate.

“Risk tiering is subjective.” Blast radius, usage and data sensitivity are computable. The tiering can be derived rather than debated, and the criteria become the auditable artefact.

Reallocating the attention budget

  1. Measure the current seconds-per-item. Campaign size divided by realistic reviewer time.
  2. Tier by computable risk. Blast radius, data sensitivity, usage.
  3. Automate the bottom tiers. Rules, not reviewers.
  4. Spend the freed budget on the top tier. And require a signature there.

Terms used here

Attestation budget
The total human review attention available, which is fixed regardless of campaign scope.
Risk tiering
Sorting entitlements by computable risk so review effort follows consequence.
Campaign scope
How many items are certified, which in most programmes is everything.

Frequently asked questions

Is reviewer time really a cost? It is the largest cost of the programme and the only one not carried on the programme's budget. That accounting artefact is why campaigns expand without resistance.

Will auditors accept reduced scope? Sometimes, with a documented risk rationale and evidence that depth increased where risk concentrates. Arrive with the analysis rather than the request.

Does this mean certification is a waste? No. It means uniform allocation of a scarce resource across items of wildly differing risk produces poor value, which is fixable without abandoning the control.

What if we cannot measure reviewer minutes? Your platform records session timestamps. If it genuinely does not, sample twenty reviewers with a timer for one campaign.

Do auditors require full-scope campaigns? They require an operating control. A risk-tiered programme with demonstrable review on the top tier is a stronger story than full scope with no revocations.

Is risk tiering subjective? Blast radius, data sensitivity and usage are computable, so the tiering can be derived and the criteria audited.

What is the first thing to measure? Seconds per item — campaign size divided by realistic reviewer time. The number is usually under one.

Where this fits in Manav

Manav turns an access decision into an artefact: what the reviewer was shown, who they were, what authority they held, signed and verifiable by an auditor without your systems.

See review receipts →

Sources and further reading