Prioritise software when access changes faster than manual review can reliably track, especially in SaaS-heavy environments with multiple business systems. Once conflict detection depends on repeated cross-referencing between applications, the control becomes too fragile to trust for audit, fraud prevention, or remediation.
When software becomes the safer control than manual review
Spreadsheet reviews work best when SoD violations are relatively static, the application estate is small, and a reviewer can still see the full set of risky combinations without stitching together several systems. Once the organisation has frequent access churn, shared roles, or multiple business platforms that each hold part of the picture, the control stops being dependable enough for remediation and assurance.
The practical shift is not “automation is modern” but “manual review no longer scales with the rate of change.” If the same entitlement can be granted in one system, mirrored in another, and revoked in a third, the review burden becomes a recurring reconciliation problem rather than a simple checklist.
For teams managing those cross-system entitlements, a purpose-built control platform is usually the point where conflict detection, mitigation tracking, and review evidence become trustworthy enough for audit and operational use. NHIMG’s Segregation of Duties (SoD) Guide is the most direct reference for how to structure rulesets, toxic combinations, and compensating controls when manual review is no longer sufficient.
What breaks in spreadsheet-led SoD reviews
Spreadsheet-led reviews fail in predictable ways: the inventory drifts, rule interpretation varies by reviewer, and exceptions become hard to re-test after the next access change. The control then depends on people noticing that a conflict exists across systems, not on a repeatable mechanism that continuously checks the current state.
This matters most where SoD is being used for fraud prevention, SOX-style internal control, or remediation of active access issues. If the reviewer has to reconcile application exports by hand, the answer can already be stale by the time the review is signed off.
Software does not remove the governance decision, but it does reduce the chance that a conflict is missed because one spreadsheet is out of date, one system was excluded, or one role mapping was copied incorrectly. That is the point where the control changes from periodic documentation to enforceable detection.
How to decide when the threshold has been crossed
A simple test is whether one person can still validate the complete conflict picture without repeatedly cross-referencing systems, business roles, and exception notes. If the answer is no, software is no longer optional process polish, it is part of making the control reliable.
- If access changes weekly or faster, prefer software because manual review will lag the actual state.
- If the same user can hold entitlements across several business applications, prefer software because conflict logic must be evaluated across the whole access path.
- If auditors or investigators need repeatable evidence of who approved what and when, prefer software because spreadsheets rarely preserve a durable control trail.
- If exceptions are frequent, prefer software because compensating controls need lifecycle tracking, not one-off notes.
Spreadsheet reviews still have a place for low-volume environments, one-time cleanup, or early-stage discovery. But once the process needs recurring assurance, the operational overhead of keeping the sheet current starts to exceed the value of the review itself.
Risk and Threat Considerations
Manual SoD reviews create exposure when the review cadence cannot keep pace with the rate of access change. The main risk is not only missed conflicts, but false confidence, because a spreadsheet can look complete even after the underlying access has already changed.
Failure mechanism: The organisation relies on periodic human cross-checks across multiple systems, so drift, missed joins, and stale exports allow toxic combinations to persist between review cycles.
Impact: Conflicts may remain active long enough to enable fraud, privileged misuse, or audit findings, and remediation becomes slower because the evidence trail is fragmented across documents instead of being generated from current system state.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.15 — Access control | SoD software supports governed access decisions across business systems. |
| A.5.18 — Access rights | SoD reviews manage entitlement assignment, review and removal. | |
| Recommendation — Define access rules and review evidence under access-control governance. Review access rights routinely and revoke conflicting entitlements quickly. | ||
| NIST SP 800-53 Rev 5 | AC-5 — Separation of Duties | The question is directly about choosing controls that enforce SoD. |
| AC-6 — Least Privilege | SoD tooling helps reduce excessive access that creates toxic combinations. | |
| Recommendation — Implement separation constraints where one person could otherwise combine conflicting duties. Limit privileges so users only retain the access needed for their role. | ||
| CIS Controls v8 | CIS-5 — Account Management | SoD depends on timely provisioning, review and removal of conflicting access. |
| Recommendation — Centralise account lifecycle control to catch and remove conflicting access. | ||
Practitioner Guidance
What to prioritise: Move first when the control’s failure mode is freshness, not formatting. If the review depends on matching identities, roles, and exceptions across more than one application, treat that as the threshold for software-assisted SoD.
What to verify: Check whether the tool can evaluate the same rule against live or regularly refreshed entitlement data, retain the approval trail, and track compensating controls through closure. If it cannot do those three things, it may only automate a spreadsheet workflow.
Common mistake: Teams often buy SoD software to produce nicer reports but keep the same manual reconciliation model underneath. That rarely improves assurance because the real control still depends on human memory and export hygiene.
Practitioner takeaway: Use spreadsheets only while the review remains small enough to be fully understood at a glance; once SoD depends on continuous reconciliation across systems, software becomes the control that preserves auditability and prevents drift.
Related resources from NHI Mgmt Group
- Should organisations prioritise live access visibility over periodic spreadsheet reviews?
- Should organisations prioritise external exposure or internal credential governance first?
- When should organisations prioritise discovery over access reviews?
- When should organisations prioritise access governance over software spend optimisation?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org