TL;DR: Spreadsheet-based access reviews in manufacturing create the appearance of compliance while stripping out SoD conflict context, lifecycle events, and remediation evidence, according to OpenIAM. The deeper problem is that review cadence, not role names alone, determines whether access governance can actually catch inappropriate entitlements.
At a glance
What this is: This is an analysis of why spreadsheet-driven user access reviews break down in manufacturing, with the key finding that lists without business, lifecycle, and risk context cannot produce meaningful governance.
Why it matters: It matters because IAM, IGA, and PAM teams need review evidence that stands up to audit while still catching SoD conflicts, contractor expiry, and cross-system privilege drift.
By the numbers:
- Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
👉 Read OpenIAM's analysis of why spreadsheet access reviews fail in manufacturing
Context
User access reviews are supposed to confirm that access still matches current job responsibility, risk, and lifecycle status. In manufacturing, that is hard enough across SAP, directory groups, plant applications, contractor accounts, and privileged access. Spreadsheet reviews fail because they separate the decision from the context needed to make the decision meaningful, which is a governance problem before it is a tooling problem.
The primary IAM issue here is not whether reviews happen, but whether they can actually identify SoD conflicts, plant transfer changes, contractor expirations, and remediation outcomes. When review artefacts reduce identity governance to a list of role names, they turn access certification into an administrative exercise instead of a control.
For manufacturing teams, that means the control failure sits in the evidence model as much as in the review workflow. A fixed-cycle spreadsheet cannot follow event-driven lifecycle changes, cannot show cross-system risk, and cannot prove that revoked access was actually removed.
Key questions
Q: What breaks when user access reviews stay spreadsheet-based?
A: Spreadsheet-based reviews break because they capture a stale snapshot, hide effective permissions, and rely on human follow-up for enforcement. By the time approvals return, access may already have changed. The result is rubber-stamped decisions, slow revocation, and weak audit evidence. Continuous identity ingestion and automated remediation close those gaps.
Q: Why do manufacturing access reviews need lifecycle-triggered campaigns?
A: Manufacturing environments change access through plant transfers, promotions, terminations, and contractor end dates. If reviews run only on a fixed schedule, inappropriate access can persist for months before anyone looks at it. Lifecycle-triggered campaigns close that gap by reviewing access when the role or relationship changes, not after the next calendar milestone.
Q: How do organisations know whether access reviews are working?
A: Access reviews are working when they lead to timely removals, reduced exception volume, and role definitions that stop accumulating unused rights. If the same accounts keep reappearing with the same excess access, the review process is only producing paperwork. Evidence of change is the real success signal.
Q: When does a spreadsheet review become a compliance risk?
A: It becomes a risk when approvers cannot see SoD conflicts, cross-system combinations, or contractor expiry status, because then they are signing off on incomplete identity information. That creates false confidence and leaves the organisation unable to show that inappropriate access was identified and removed in a defensible way.
Technical breakdown
Why role names are not reviewable identity evidence
A spreadsheet typically presents access as a row of role names or group memberships. That format hides the authorization object, the business function behind the entitlement, and any conflict created by combining roles across SAP modules or connected systems. A manager can approve a technical label without understanding whether it maps to procurement, payments, production, or quality. In governance terms, the reviewer is judging an identifier, not the actual access relationship. Practical review decisions depend on context attached to the identity object, not on the raw entitlement name.
Practical implication: Present business context, SoD status, and cross-system relationships with every entitlement before asking for approval.
How lifecycle events break fixed-cycle review models
Manufacturing identity changes are often event-driven. Plant transfers, promotions, contract end dates, and temporary coverage roles all alter access meaning before the next scheduled campaign. Spreadsheet reviews usually run on a calendar, so they miss the moment when access becomes inappropriate. That creates a window where access remains valid on paper but invalid in practice. The control gap is not lack of review intent, but lack of lifecycle coupling between HR, contractor management, and access certification.
Practical implication: Trigger reviews from mover, leaver, and contractor events instead of relying only on quarterly or annual campaigns.
Why remediation evidence is the real audit boundary
An access review is only useful if the revocation or exception outcome is captured end to end. Spreadsheets rarely provide structured proof that an approved revocation was executed, when it was executed, or whether an exception was justified and retained. Auditors look for a chain that links scope, decision, action, timestamp, and retained evidence. Without that chain, the review becomes a record of administrative activity rather than a defensible governance control. The technical weakness is not the export itself, but the absence of workflow state and immutable completion evidence.
Practical implication: Route revocations and exceptions through a governed workflow with timestamps and exportable audit records.
NHI Mgmt Group analysis
Spreadsheet access reviews create evidence without assurance. A completed file proves that items were marked, not that access was understood, challenged, or removed. In manufacturing, where a single user may span SAP, directory groups, and plant systems, that distinction matters because audit confidence depends on control substance, not activity volume. The practical conclusion is that review artefacts must show context and outcome, not just participation.
Access certification that ignores lifecycle state is already obsolete by the time it closes. Plant transfers, contract expirations, and temporary role changes alter access faster than a fixed spreadsheet cycle can observe. That means the review process is structurally misaligned with the pace of identity change. Practitioners should treat lifecycle coupling as the core design requirement, not a nice-to-have enhancement.
SoD risk is invisible when access is reviewed as isolated rows. Manufacturing segregation failures usually appear in combinations, not in single entitlements. A manager who sees only a role list cannot identify whether vendor master access, payment authority, and production privileges overlap in a dangerous way. The implication is that identity governance must evaluate combinations across systems, not certify one application at a time.
Audit readiness requires executable evidence, not reconstructed evidence. If revocation lives in email, tickets, and spreadsheets, the organisation spends audit time proving the control happened after the fact. That is a weak operating model because it depends on manual reconstruction under pressure. The right conclusion is that access reviews need a record that is created by the workflow itself, not assembled later from fragments.
From our research:
- Only 44% of developers are reported to follow security best practices for secrets management, according to The State of Secrets in AppSec.
- Organisations maintain an average of 6 distinct secrets manager instances, which fragments control and complicates lifecycle governance.
- For related lifecycle guidance, see NHI Lifecycle Management Guide and the OWASP Non-Human Identity Top 10 for control alignment.
What this signals
Identity governance programmes should treat spreadsheet-based reviews as a transitional artefact, not a control destination. The design problem is not limited to SAP or manufacturing. Any programme that relies on static exports will struggle once lifecycle events, cross-system entitlements, and evidence retention become audit expectations rather than nice-to-haves. The practical signal is clear: move toward workflow-native certification with event triggers and structured decision state.
Access review maturity now depends on whether the organisation can connect identity data to operational risk. If approvers cannot see SoD conflicts, contractor expiry, or transfer history at the point of decision, the review cannot be trusted as a governance signal. That gap will push more teams toward integrated IAM, IGA, and lifecycle controls rather than isolated spreadsheet campaigns.
For practitioners
- Replace spreadsheet-only reviews with governed workflow Require every certification campaign to carry reviewer identity, decision state, timestamps, and tracked remediation so the evidence trail is exportable without manual reconstruction.
- Bind reviews to lifecycle triggers Connect mover, leaver, plant transfer, and contractor expiration events to access review initiation so inappropriate access is challenged when the identity changes, not at the next calendar cycle.
- Surface SoD conflict context in every item Show conflict status, role combination risk, and cross-system entitlements directly in the review queue so approvers can see why an access item is risky before they approve it.
- Track revocation completion to closure Do not close the review until revoked access is confirmed removed and the timestamp is recorded in the same control record as the original decision.
- Separate employee and contractor governance Apply time-bound grants and expiration checks to contractor accounts so they cannot drift into the same slow review cadence as permanent staff.
Key takeaways
- Spreadsheet reviews in manufacturing fail because they remove the context needed to judge access, not because teams lack effort.
- The real evidence gap is remediation and lifecycle linkage, since audit value depends on proving what changed after the review.
- Access governance improves when reviews are event-triggered, context-rich, and backed by workflow-native completion records.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 — Access Permissions and Authorisations | The article is about governing who can approve and retain access in manufacturing. |
| Recommendation — Map review outcomes to PR.AC-4 and require access decisions to include business context and authorisation evidence. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Periodic and event-driven access review are core account management controls. |
| AC-6 — Least Privilege | Spreadsheet reviews fail when privilege is not evaluated against effective access. | |
| Recommendation — Apply AC-2 to trigger review, revocation, and exception handling from account lifecycle events. Use AC-6 to reduce access combinations that exceed current job need or create SoD exposure. | ||
| CIS Controls v8 | CIS-5 — Account Management | The post focuses on governed review, revocation, and contractor account control. |
| Recommendation — Use CIS Control 5 to centralise account review, expiration, and offboarding evidence. | ||
| ISO/IEC 27001:2022 | A.8.2 — Privileged Access Rights | Privileged and elevated access in plant and SAP environments needs controlled review. |
| Recommendation — Apply A.8.2 to review privileged entitlements with context and time-bound approval evidence. | ||
Key terms
- Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
- Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
- Lifecycle Trigger: A lifecycle trigger is the event or source signal that causes an access change, such as a role update, termination, or transfer. If the trigger is stale, missing, or poorly governed, the identity system can keep access alive long after the business need has ended.
- Remediation evidence: Remediation evidence is the record that shows an access issue was identified and corrected. It usually includes the reviewer, the decision, the change request, and the completed revocation or adjustment, which allows auditors to verify that the control actually closed the gap.
What's in the full article
OpenIAM's full article covers the operational detail this post intentionally leaves for the source:
- The spreadsheet review failure modes mapped to SAP, directory, plant, and contractor access.
- The audit evidence model for reviewer decisions, revocations, and exception handling.
- The event-driven access review pattern for joiner, mover, leaver, and contractor changes.
- The manufacturing-specific SoD conflict examples that a role-name-only review will miss.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on September 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org