Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when IAM is managed through spreadsheets…
Governance, Ownership & Risk

What breaks when IAM is managed through spreadsheets and tickets?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Access governance becomes fragmented, slow and hard to prove. Spreadsheets can record approvals, but they do not continuously enforce least privilege, segregation of duties or revocation. The result is stale entitlements, unclear ownership and weak audit evidence, which means critical systems can remain exposed even when the organisation believes access is under control.

Why spreadsheets and tickets break IAM in practice

Spreadsheets and ticket queues create a record of intent, not a control plane. They can document who asked for access, but they do not continuously validate whether the right entitlement still exists, whether approvals match policy, or whether the access path has drifted since the request was opened. That gap is why access governance becomes slow, fragmented and difficult to demonstrate.

The core problem is temporal. IAM decisions have a lifecycle, but manual workflow tools only capture snapshots. Once an entitlement is approved, any later change, such as a role change, project end, control exception or emergency fix, depends on a person noticing and updating the record. In practice that means the organisation is managing access after the fact instead of governing it as a living state.

Manual tracking also breaks ownership. A ticket may show who approved access, but not who owns the resource, who must review it next, or which business rule should trigger revocation. When ownership is ambiguous, stale entitlements persist, recertification becomes ceremonial, and least privilege degrades quietly across systems.

What this does to least privilege, segregation of duties and revocation

Least privilege fails first because spreadsheets rarely reflect effective permissions. They usually describe intended access, not the inherited, nested or cross-system access that actually exists. A user can keep access that is no longer justified, and no spreadsheet row will tell you that the entitlement has become excessive.

Segregation of duties weakens for the same reason. A ticket workflow can record separate approvals, but it does not reliably reason over combinations of access, inherited roles or later changes that create a conflict. The control looks present on paper while the real permission set becomes inconsistent with policy.

Revocation is the most visible failure. If removal depends on manual follow-up, access often remains active after transfer, exit or project completion. NHI Management Group’s Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs is a useful reference for the lifecycle discipline that manual ticketing usually cannot sustain at scale, especially where offboarding and rotation must happen promptly.

That same lifecycle problem appears in broader access-governance work. The issue is not whether a request was approved once, but whether the entitlement remains justified after the business context changes. If you cannot answer that quickly, the control has become documentary rather than operational.

Why audit evidence gets weaker as manual IAM grows

Manual IAM processes often produce a large amount of artefact, but weak assurance. Auditors and internal control owners need to see that access was approved, provisioned, reviewed and removed according to policy, and that the evidence chain is complete enough to trust. Spreadsheets and tickets can help, but they are fragile because they are easy to edit, split across tools and disconnected from the system state they describe.

The result is that evidence becomes reconstruction work. Teams spend time proving what happened instead of enforcing what should happen. NHI Management Group’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives captures this auditability problem well: governance is stronger when review, ownership and removal are tied to durable records and measurable control outcomes, not just request history.

For cloud and other high-change environments, the gap widens because effective permissions can differ sharply from what was originally granted. The broader the environment, the less useful a spreadsheet becomes as a source of truth. NHI Management Group’s Cloud PAM and CIEM Guide is relevant here because right-sizing and effective-permission analysis address the exact drift that ticket-based administration tends to miss.

Risk and Threat Considerations

When IAM is governed through spreadsheets and tickets, the main risk is not just delay, it is uncontrolled exposure. Stale access, unclear ownership and incomplete removal create a standing opportunity for misuse, whether by an insider, a compromised account or an attacker who inherits permissions long after they should have been removed.

Failure mechanism: Manual records do not continuously reconcile approvals against live entitlements, so excess access, dormant accounts and unresolved exceptions accumulate until the control is no longer aligned with reality.

Impact: Sensitive systems can remain accessible after business need has ended, audit evidence becomes hard to trust, and any compromise has a larger blast radius because revocation and containment are slower than the exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity & Access ManagementIAM governance and entitlement control are central to the question.
Recommendation — Enforce IAM controls that tie approvals to current effective access and revocation.
NIST SP 800-53 Rev 5AC-2 — Account ManagementManual IAM workflows fail when account lifecycle and removal are not controlled.
AC-6 — Least PrivilegeThe question is about loss of least privilege when access is tracked manually.
AU-6 — Audit Review, Analysis, and ReportingSpreadsheet-based evidence weakens auditability and control assurance.
Recommendation — Automate account lifecycle actions and remove stale access promptly. Continuously right-size permissions against actual job and system need. Retain verifiable evidence from system-enforced access events and reviews.
ISO/IEC 27001:2022A.5.15 — Access controlAccess governance and entitlement enforcement are the core issue.
A.5.18 — Access rightsThe page addresses granting, reviewing and removing access rights over time.
Recommendation — Define and enforce access rules in the live control environment, not only in records. Review and revoke access rights on a defined cadence tied to business need.

Practitioner Guidance

What to prioritise: Treat the live entitlement set as the control boundary, not the spreadsheet. If the request history and the actual access state diverge, the live state wins and must be the object of review, recertification and revocation.

What to verify: For each high-value system, verify that every privileged or sensitive entitlement has a named owner, a review cadence, a clear removal trigger and a way to compare granted access with effective access. If any one of those is missing, the process is not yet governable.

Common mistake: Teams often assume that a completed approval equals controlled access. It does not, because approval proves intent, not persistence, inheritance, or eventual removal.

Practitioner takeaway: If your IAM process cannot answer “who has what, why, and for how long” from current system state, then the spreadsheet is a logbook, not governance.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org