Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› When should organisations prioritise SoD software over spreadsheet…
Governance, Ownership & Risk

When should organisations prioritise SoD software over spreadsheet reviews?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Prioritise software when access changes faster than manual review can reliably track, especially in SaaS-heavy environments with multiple business systems. Once conflict detection depends on repeated cross-referencing between applications, the control becomes too fragile to trust for audit, fraud prevention, or remediation.

When software becomes the safer control than manual review

Spreadsheet reviews work best when SoD violations are relatively static, the application estate is small, and a reviewer can still see the full set of risky combinations without stitching together several systems. Once the organisation has frequent access churn, shared roles, or multiple business platforms that each hold part of the picture, the control stops being dependable enough for remediation and assurance.

The practical shift is not “automation is modern” but “manual review no longer scales with the rate of change.” If the same entitlement can be granted in one system, mirrored in another, and revoked in a third, the review burden becomes a recurring reconciliation problem rather than a simple checklist.

For teams managing those cross-system entitlements, a purpose-built control platform is usually the point where conflict detection, mitigation tracking, and review evidence become trustworthy enough for audit and operational use. NHIMG’s Segregation of Duties (SoD) Guide is the most direct reference for how to structure rulesets, toxic combinations, and compensating controls when manual review is no longer sufficient.

What breaks in spreadsheet-led SoD reviews

Spreadsheet-led reviews fail in predictable ways: the inventory drifts, rule interpretation varies by reviewer, and exceptions become hard to re-test after the next access change. The control then depends on people noticing that a conflict exists across systems, not on a repeatable mechanism that continuously checks the current state.

This matters most where SoD is being used for fraud prevention, SOX-style internal control, or remediation of active access issues. If the reviewer has to reconcile application exports by hand, the answer can already be stale by the time the review is signed off.

Software does not remove the governance decision, but it does reduce the chance that a conflict is missed because one spreadsheet is out of date, one system was excluded, or one role mapping was copied incorrectly. That is the point where the control changes from periodic documentation to enforceable detection.

How to decide when the threshold has been crossed

A simple test is whether one person can still validate the complete conflict picture without repeatedly cross-referencing systems, business roles, and exception notes. If the answer is no, software is no longer optional process polish, it is part of making the control reliable.

  • If access changes weekly or faster, prefer software because manual review will lag the actual state.
  • If the same user can hold entitlements across several business applications, prefer software because conflict logic must be evaluated across the whole access path.
  • If auditors or investigators need repeatable evidence of who approved what and when, prefer software because spreadsheets rarely preserve a durable control trail.
  • If exceptions are frequent, prefer software because compensating controls need lifecycle tracking, not one-off notes.

Spreadsheet reviews still have a place for low-volume environments, one-time cleanup, or early-stage discovery. But once the process needs recurring assurance, the operational overhead of keeping the sheet current starts to exceed the value of the review itself.

Risk and Threat Considerations

Manual SoD reviews create exposure when the review cadence cannot keep pace with the rate of access change. The main risk is not only missed conflicts, but false confidence, because a spreadsheet can look complete even after the underlying access has already changed.

Failure mechanism: The organisation relies on periodic human cross-checks across multiple systems, so drift, missed joins, and stale exports allow toxic combinations to persist between review cycles.

Impact: Conflicts may remain active long enough to enable fraud, privileged misuse, or audit findings, and remediation becomes slower because the evidence trail is fragmented across documents instead of being generated from current system state.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.15 — Access controlSoD software supports governed access decisions across business systems.
A.5.18 — Access rightsSoD reviews manage entitlement assignment, review and removal.
Recommendation — Define access rules and review evidence under access-control governance. Review access rights routinely and revoke conflicting entitlements quickly.
NIST SP 800-53 Rev 5AC-5 — Separation of DutiesThe question is directly about choosing controls that enforce SoD.
AC-6 — Least PrivilegeSoD tooling helps reduce excessive access that creates toxic combinations.
Recommendation — Implement separation constraints where one person could otherwise combine conflicting duties. Limit privileges so users only retain the access needed for their role.
CIS Controls v8CIS-5 — Account ManagementSoD depends on timely provisioning, review and removal of conflicting access.
Recommendation — Centralise account lifecycle control to catch and remove conflicting access.

Practitioner Guidance

What to prioritise: Move first when the control’s failure mode is freshness, not formatting. If the review depends on matching identities, roles, and exceptions across more than one application, treat that as the threshold for software-assisted SoD.

What to verify: Check whether the tool can evaluate the same rule against live or regularly refreshed entitlement data, retain the approval trail, and track compensating controls through closure. If it cannot do those three things, it may only automate a spreadsheet workflow.

Common mistake: Teams often buy SoD software to produce nicer reports but keep the same manual reconciliation model underneath. That rarely improves assurance because the real control still depends on human memory and export hygiene.

Practitioner takeaway: Use spreadsheets only while the review remains small enough to be fully understood at a glance; once SoD depends on continuous reconciliation across systems, software becomes the control that preserves auditability and prevents drift.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org