Because they record access after the fact rather than controlling its lifecycle. When joiner-mover-leaver events are handled manually, revocation is delayed, role changes are missed, and permissions accumulate beyond need. The result is stale access that survives because no enforcement point closes the loop.
Why spreadsheets create orphaned accounts and privilege creep
Spreadsheets are a record-keeping tool, not an enforcement mechanism. They can track who should have access, but they do not provision, revoke, recertify, or reconcile entitlements when people change roles or leave. Once access lives in a file instead of a control point, drift is inevitable: old access stays visible, but not necessarily corrected.
Why manual access tracking breaks at the joiner-mover-leaver boundary
Joiner-mover-leaver handling is where spreadsheet-driven processes fail most predictably. A move that should remove old-role access, or a leaver that should trigger revocation, depends on someone noticing, updating the sheet, and pushing the change through the right system. That creates delay, inconsistency, and gaps between business reality and actual permissions.
The problem is not only missed offboarding. Mover events often accumulate multiple access grants over time, especially when teams add exceptions to keep work moving. Without an authoritative lifecycle workflow, the spreadsheet becomes a history of approvals rather than a current source of truth. That is why orphaned accounts and excess permissions often appear together.
How stale access turns into privilege creep over time
privilege creep usually starts as temporary access that is never removed, then grows through repeated exceptions, duplicate roles, and ad hoc approvals. Because spreadsheets rarely model effective access, inherited entitlements, or dependencies between accounts, they hide the cumulative effect of small changes. The result is a larger access footprint than any single reviewer intended.
For identity governance, the critical issue is whether a change in employment status automatically changes access. If the answer is no, then the organisation is relying on memory, manual review, and after-the-fact cleanup. NHIMG’s IAM and IGA Basics explains why access governance must treat provisioning, review, and revocation as a lifecycle, not a spreadsheet exercise. The same pattern shows up in the Joiner-Mover-Leaver (JML) Guide, where delayed deprovisioning and missed role changes are the direct drivers of creep.
Risk and Threat Considerations
When spreadsheets are the main system of record for access, stale accounts and unnecessary privilege become persistent exposure rather than one-time mistakes. That increases the blast radius of forgotten accounts, makes audits unreliable, and gives attackers more opportunities to find valid access that nobody is actively watching.
Failure mechanism: Manual updates do not keep pace with HR or contractor changes, so revocation and right-sizing depend on human follow-through instead of control enforcement.
Impact: Orphaned accounts remain usable, excess privileges accumulate, and compromised credentials have more time and more access to work with.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.AM-01 — Physical devices and systems within the organization are inventoried | Access sprawl is easier to miss when accounts and systems are not inventoried. |
| PR.AA-04 — Identity and access permissions are managed, incorporating the principles of least privilege and separation of duties | Privilege creep is directly about permissions drifting beyond least privilege. | |
| Recommendation — Inventory systems and accounts so orphaned access can be found and removed. Manage permissions continuously and remove excess access when roles change. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Orphaned accounts arise when account lifecycle controls are handled manually. |
| AC-6 — Least Privilege | Privilege creep is the steady erosion of least privilege through extra access. | |
| IA-5 — Authenticator Management | Manual lifecycle handling often leaves credentials active after access should end. | |
| Recommendation — Automate account provisioning, review, disabling, and removal. Restrict users to the minimum access needed for current duties. Rotate and retire authenticators when access is no longer required. | ||
Practitioner Guidance
What to prioritise: Treat offboarding and role changes as control events, not administrative updates. If a spreadsheet is still the trigger, the first fix is to make revocation and entitlement changes originate from an authoritative lifecycle process, then verify that the target systems actually enforce the change.
What to verify: Check whether every access grant has an owner, an expiration or review cycle, and a matching removal path. If you cannot answer who removes access when someone moves or leaves, you have a process gap, not just a documentation issue.
Common mistake: Teams often focus on reviewing the sheet instead of reconciling the live account state. A clean spreadsheet does not matter if dormant accounts, shared accounts, or old role memberships still exist in production.
Practitioner takeaway: Spreadsheets can document access intent, but only lifecycle enforcement prevents privilege from outliving the business reason for it.
Related resources from NHI Mgmt Group
- Why do orphaned accounts and privilege creep create so much risk for CISOs?
- How should teams reduce the risk of orphaned service accounts and stale tokens?
- Why do orphaned accounts and privilege creep keep showing up in growing organisations?
- Why do orphaned accounts create more risk in regulated environments?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org