IT Glossary

Access Attestation

Access attestation is a named person formally confirming an entitlement is correct. Learn who signs, what it proves, and how it differs from a review.

August 7, 2026

What is access attestation?

Access attestation is the formal act by which a named, accountable person confirms on the record that a specific entitlement is correct and still justified. It is the signature at the end of the process: the review examines the access, while the attestation is the statement that someone takes responsibility for it. That statement, with a date and an identity attached, is what an auditor accepts as evidence.

What an attestation must contain

  • The exact entitlement concerned, not a vague reference to a system.
  • The identity of the person attesting, and the basis of their accountability.
  • The decision taken: confirm, modify, or revoke, with a reason where the entitlement is sensitive.
  • A timestamp, and the campaign or trigger the attestation belongs to.
  • Proof that any revocation decided was actually executed in the target system.

Review, certification, attestation: the difference

The three words are used interchangeably in vendor material, which helps nobody. The review is the examination of who holds what. The certification is the process that runs that review across a defined perimeter and cycle. The attestation is the individual statement of responsibility inside it. A company can review access constantly and still have nothing to show an auditor, because nobody ever attested to anything.

Examples and use cases

A finance director attests each quarter that the twelve people holding payment approval rights are the correct twelve, and revokes one who moved to another team. That single dated and signed line is worth more in an audit than a full export of the entitlement database, because it establishes accountability rather than merely describing a state. Corma captures those attestations line by line and keeps them alongside the evidence of execution.

Related concepts

FAQ

What is the difference between attestation and certification?

Certification is the process that organizes the review across a perimeter and a cycle. Attestation is the individual confirmation made by an accountable person inside that process.

Who can attest to an entitlement?

The person accountable for the risk it carries, normally the direct manager or the business owner of the application, not the IT administrator who applied it.

Is an access attestation legally binding?

It is not a legal instrument, but it establishes internal accountability and it is the evidence auditors expect under ISO 27001, SOC 2, and NIS2 governance obligations.

What happens if an attested entitlement turns out to be wrong?

The record shows who confirmed it and when, which is exactly the point. Attestation exists to make accountability explicit rather than diffuse.

Request a demo