The review loses the identity context needed to make a meaningful decision. Managers see role names but not SoD conflicts, lifecycle changes, contractor expiry, or privilege combinations, so the process becomes a sign-off exercise rather than a control. The failure is structural because the evidence trail records the review, not the governance outcome.
Why Spreadsheet Access Reviews Fail in Manufacturing
Spreadsheet-driven reviews collapse the context that makes access governance meaningful. In manufacturing, the reviewer needs to see not just a role label, but whether the account sits inside a Segregation of Duties (SoD) Guide boundary, whether the access belongs to a contractor nearing expiry, and whether lifecycle events have already changed the entitlement. A flat sheet usually turns those questions into guesswork.
The practical failure is that the process asks managers to approve an identity record without the surrounding governance signal. That is especially damaging in plants where shared terminals, shift-based access, engineering overrides, and vendor support accounts can all look similar on paper while carrying very different risk.
When the review format hides privilege combinations and lifecycle state, the reviewer cannot distinguish a clean entitlement from a toxic one. The result is not simply lower review quality, it is a different control objective altogether: confirmation that someone looked, not validation that the access was still acceptable.
What Gets Lost When the Evidence Is Flattened
A spreadsheet strips out the relationships that make access decisions defensible. Role names do not show whether the person also holds plant-floor admin rights, whether a service or support account is overlapping with a human approval path, or whether the account should already have been removed as part of mover or leaver handling. Those missing links matter because access reviews are meant to test current authority, not old records.
This is why identity governance usually depends on a foundational IAM and IGA model, not just a list of names and permissions. The reviewer needs entitlement context, ownership, and a way to see whether the access still matches the job, contract, or system purpose. Without that, a review can approve stale access that happened to look legitimate in the export.
Manufacturing makes the problem sharper because operational roles often blend business process, plant safety, and vendor support. A spreadsheet cannot easily express that a single access item may be acceptable in isolation but unacceptable when combined with another entitlement, a temporary override, or a second system path. That is exactly the kind of hidden combination SoD controls are meant to surface.
How to Tell the Review Has Become Rubber Stamping
The strongest warning sign is when reviewers are asked to respond to a prefilled yes-or-no list with no evidence of why each access exists. Another signal is when the same report format is reused for every plant, department, and contractor population even though the underlying risk is different. At that point, the review is no longer testing governance, it is testing whether the recipient will accept the default.
For access review programs, the better pattern is to align the review object with the entitlement model, not the other way around. A useful access review should expose role, owner, account type, expiry, SoD conflict status, and the last known lifecycle event. If those fields are not present, the review may still be operationally efficient, but it is not giving the decision-maker enough context to revoke confidently.
That is also why lifecycle governance and review governance belong together. Joiner-Mover-Leaver (JML) Guide material is relevant here because many “should we keep this access?” questions are actually overdue mover or leaver decisions. If the review cannot tell whether the entitlement was already due for removal, the control is delayed before it starts.
Risk and Threat Considerations
Spreadsheet reviews create a quiet but material exposure: they make it easy to preserve privilege that should have been removed, especially when the account belongs to a contractor, shared operator, or support function. In manufacturing, that can leave standing access in places where availability, safety, or production integrity depend on tight entitlement boundaries.
Failure mechanism: the reviewer signs off on a role name or a static export instead of a current authority decision, so stale access, SoD conflicts, and excess privilege survive because the evidence format does not force them into view.
Impact: unauthorized production actions, delayed revocation, and weaker audit evidence follow, with the added risk that the organisation can prove a review happened while still being unable to prove the access was actually governed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Access reviews and entitlement control are core account-management safeguards. |
| Recommendation — Review accounts routinely and remove access that is no longer justified. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | The question is about governing access reviews, revocation, and account lifecycle decisions. |
| AC-6 — Least Privilege | Spreadsheet reviews miss excess privilege and toxic combinations that least privilege is meant to curb. | |
| AU-6 — Audit Review, Analysis, and Reporting | The page concerns whether the evidence trail supports a real governance outcome, not just a completed review. | |
| Recommendation — Maintain current account records and disable or remove unneeded access promptly. Limit entitlements to the minimum needed for the role and task. Analyze access-review evidence for unresolved exceptions and governance failures. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | The subject is periodic review and removal of access rights. |
| A.5.15 — Access control | Spreadsheet reviews are an access-control governance problem, not a reporting problem. | |
| Recommendation — Review access rights at defined intervals and remove rights that are no longer required. Apply access-control rules that are based on business need and current authority. | ||
Practitioner Guidance
What to verify: Before trusting any recertification result, verify that the review object includes account type, owner, expiry, lifecycle state, and conflict indicators. If a reviewer cannot see those fields, the review outcome should be treated as incomplete even if every row has a sign-off.
Common mistake: Treating spreadsheet completion as the control itself. In practice, the control is the decision quality, not the file. If the process does not force exception handling for SoD conflicts, contractor end dates, or dormant access, it will normalise approval of risky entitlements.
Practitioner takeaway: The goal is to review authority in context, not to collect approvals efficiently. In manufacturing, access reviews are only defensible when they preserve the identity and lifecycle signals needed to revoke, not just to record that someone clicked yes.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org