Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when MSP SaaS governance still relies…
Governance, Ownership & Risk

What breaks when MSP SaaS governance still relies on spreadsheets?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 10, 2026 Domain: Governance, Ownership & Risk

The control model breaks because spreadsheets cannot enforce lifecycle state. They may list users, apps and licences, but they do not revoke access, reconcile usage or keep pace with tenant change. In MSP operations, that means stale permissions, orphaned licences and delayed offboarding can persist long after the business reason has ended.

Why spreadsheet-driven governance fails in MSP environments

Spreadsheet governance is a record-keeping model, not a control model. It can describe who should have access, but it cannot prove who still does, which tenant the access applies to, or whether the access should have expired after a client, role or contract change. In managed service operations, those gaps create a disconnect between the inventory and the live authority surface.

The practical failure is temporal. MSPs work across many tenants, shared support teams and fast-changing customer relationships, so entitlement state changes continuously. A spreadsheet can be updated after the fact, but it cannot enforce those changes at the moment a user leaves, a contract ends or a licence is no longer justified. That is why stale access and stale licence allocations remain in circulation.

What breaks when revocation, reconciliation and tenant change are manual

Once the governance process depends on humans to chase every update, three things usually break first: revocation, reconciliation and ownership. Access may still exist after offboarding, usage data may no longer match the spreadsheet, and no one has a reliable owner for exceptions that span client, platform and MSP internal teams. The result is drift between policy and reality.

This becomes more serious when the spreadsheet is treated as the source of truth for multiple control questions at once. It may be used to show licence entitlement, user approval and platform ownership, but those are different lifecycle states. If one row is not updated, the record can imply compliance while the underlying SaaS tenant still contains active permissions, shared credentials or dormant admin paths.

Where MSPs also manage access to customer environments, the SalesBleed Salesforce Agentforce 2026 material is a useful reminder that governance failures are rarely only about storage of names and roles, they are about whether active access paths remain bound to real-world state changes.

Why stale SaaS records become a security and operational problem

Stale SaaS records are not just an admin annoyance. They increase the chance of orphaned access, unnecessary privilege retention and billing waste, and they make it harder to answer basic questions during incident response or audit: who had access, when it changed, and whether the change was actually enforced. That is a control integrity issue, not just a housekeeping issue.

When spreadsheets lag behind tenant reality, they also weaken segmentation between customers. MSPs often need to prove that one client's access, data and administrative reach are not leaking into another's environment. If the governance artefact is manual, reviewers may miss cross-tenant entitlements, inherited admin rights or old service accounts that continue to function long after their business purpose has ended.

Risk and Threat Considerations

Spreadsheet-based governance creates exposure because it cannot reliably detect or remove standing access. In MSP SaaS environments, that leaves a wide attack and misuse window for former staff, over-entitled operators, compromised credentials and forgotten tenant relationships.

Failure mechanism: The spreadsheet records intent, but the SaaS tenant enforces reality. If the record is not synchronised to provisioning, deprovisioning and usage reconciliation, stale permissions, orphaned licences and delayed offboarding remain active and can be exploited or simply persist unnoticed.

Impact: The organisation loses control over access lifecycle, increases blast radius across tenants, and may face audit failure, customer trust damage and avoidable exposure from accounts that should have been removed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementSpreadsheets fail where account lifecycle and access review need enforced control.
Recommendation — Automate account review, revocation and exception tracking instead of relying on manual lists.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementManual tracking often misses credential and access lifecycle changes for SaaS users.
AC-2 — Account ManagementThe issue is stale accounts and delayed offboarding across managed tenants.
Recommendation — Manage credential issuance, rotation and revocation through enforced lifecycle controls. Centralize account provisioning, disabling and review to keep tenant access current.
ISO/IEC 27001:2022A.5.16 — Identity managementThe subject concerns governing identities and their lifecycle across SaaS access.
Recommendation — Define and operate identity lifecycle controls that keep access aligned to current business need.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingDelayed offboarding is a direct failure mode in MSP SaaS governance.
NHI-05 — Overprivileged NHISpreadsheet governance often leaves excessive access in place after role change.
Recommendation — Remove access paths promptly when an account or relationship is no longer needed. Continuously reduce standing privilege and remove excess access that no longer matches need.

Practitioner Guidance

What to verify: Treat the spreadsheet as evidence of review, not evidence of enforcement. Verify that every lifecycle event, joiner, mover, leaver, contract end and role change, produces a real tenant-side state change and not just a row update.

Common mistake: Teams often believe licence clean-up is enough. In MSP environments, removing a licence without reconciling delegated access, admin roles and shared support pathways leaves the underlying control gap untouched.

What good looks like: A practitioner can show current entitlement state directly from the SaaS admin plane, prove that offboarding is time-bound, and explain which control owns each tenant exception instead of relying on a workbook as the governing record.

Practitioner takeaway: If the spreadsheet is the place where access is decided, approved and remembered, the MSP does not have governance, it has documentation of governance intent.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org