Users should only be able to certify assets if they are a "workspace admin." If technically any user can certify the assets they create, it doesn't actually hold any weight as to what assets are legitimate and what assets aren't.
Ideal solution: Admins can check a workspace setting or an account setting that limits certification to workspace admins only.
Current workaround: asking non-workspace admins nicely to not certify stuff. Generally we'd like to lock access to the feature though because asking users nicely to comply doesn't always work.