• Download a trial
  • Sales
  • Support
  • Login
logo
  • Home
  • Products
  • Solutions
  • Partners
  • About Us
  • Consulting
  • Resources
Request a Quote
  • Workforce Identity
  • Customer Identity
  • Comparison
  • Subscriptions

All Features

Overview of all features in Workforce Identity

User Onboarding and Offboarding

Automate joiner, mover, leaver processes

Access Request

Access requests with multi-step approvals

User Access Reviews

Save time with user access reviews

Self-Service Portal

Self-service portal for all end user activities

Segregation of Duties

Detect and remediate SoD violations

Password Management

Enforce password policies and enable synchronization

Single Sign-On (SSO)

Enable SSO using standards - SAML, oAuth, OIDC

Authentication and MFA

Improve security with adaptive authentication and MFA

3rd Party IdP Integration

Integrate with your existing identity provider

Integration API

Use the REST API to add identity into your applications

Connector Library

Integrate on-premise and SaaS applications

Modern Architecture

Microservice architecture that supports deployment using RPM, Kubernetes or OpenShift

Workforce Identity Concepts

All Features

Overview of all features in Customer IAM

Authentication and MFA

Improve security with adaptive authentication and MFA 

Single Sign-On (SSO)

Enable SSO using standards - SAML, oAuth, OIDC

Password Management

Enforce password policies and enable synchronization

Modern Architecture

Microservice architecture that supports deployment using RPM, Kubernetes or OpenShift

Customer Identity Concepts

Community vs Enterprise

Summary of the differences between the Community and Enterprise editions

Subscription Benefits

Overview of the benefits provided by an OpenIAM subscription

  • Integrations
  • Verticals
  • Workforce Use Cases
  • CIAM Use Cases
  • Compliance
  • Data Breach Mitigation

Active Directory

Azure (O365)

SAP

Workday

AWS

Linux Server

LDAP

Microsoft SQL Server

Google Cloud

Windows Server

Oracle EBS

ServiceNow

Oracle Fusion

Entra ID

Salesforce

Keycloak

Custom Applications

Education

Manage identity for students, staff and alumni

Financial Services

Address the compliance and security challenges of the financial sector

Manufacturing

Identity Governance That Works in Practice

Access Governance

CIAM for Regulated Industries

NIS2

Achieve compliance with the EU directive for cybersecurity frameworks.

DORA

Comply with the Digital Operational Resilience Act for the EU.

HIPAA

For healthcare organizations seeking HIPAA compliance.

PCI DSS

Compliance with the Payment Card Industry Data Security Standard

SOC 2

Solutions for organizations subject to SOC 2 audits

GDPR

Take advantage of OpenIAM to comply with the General Data Protection Regulation

Social Engineering Attacks

  • Partners

Current Partners

Our Current Partners

Partner Registration

  • About Us

About OpenIAM

Learn about OpenIAM

Press Releases

References to OpenIAM press releases

OpenIAM in the Media

References to OpenIAM in the media

Careers

Learn about open positions at OpenIAM.

  • Consulting

Proof of Value

Customized engagement to confirm defined proof of value objectives

Jump Start

Customized engagement to rapidly deliver a solution into production

Solution Implementation

Engagement with the objective to deliver a complete IAM solution based on customer requirements

  • Resources

Videos

Collection of videos describing how OpenIAM can be used to solve common use cases

Community Portal

Collaborative community portal to learn more about OpenIAM

CE Documentation

Documentation for the Community Edition

Blog

Musings on identity penned by the OpenIAM team

Webinar Calendar

Upcoming webinars and training sessions

Workforce Identity Concepts

Customer Identity Concepts

SAP SoD Risk Reference for Manufacturing

Why Spreadsheet Access Reviews Fail Manufacturing Teams

September 10, 2026
Mansoor Alam

A user access review is the process by which an organization periodically confirms that every user's access is still appropriate — and that access no longer needed has been removed. In manufacturing, these reviews cover SAP roles, directory groups, plant applications, contractor accounts, and privileged access across a complex multi-system estate.

The challenge is not that manufacturing companies are skipping these reviews. It is that most are running them on spreadsheets — and spreadsheet-based reviews create the appearance of compliance without the substance of it.

Key Takeaways

  • Spreadsheet access reviews separate the review decision from the risk context, the remediation evidence, and the lifecycle data that make a review meaningful.
  • A manager approving a list of role names cannot see SoD conflicts, plant transfer history, or contractor expiration status.
  • A completed spreadsheet proves a list was reviewed — not that inappropriate access was identified, acted on, and documented.

What does a spreadsheet access review actually look like?

In most manufacturing organizations, an IAM or GRC team exports access data from SAP and other systems into a spreadsheet and distributes it to managers and application owners. Reviewers mark each row — approve or revoke. Completed sheets are collected, filed, and the review is closed.

The problem is what the spreadsheet does not contain. The manager sees a list of SAP role names. They do not see that two of those roles, held by the same user, create a vendor master and payment run conflict. They do not see that the user transferred from a plant in Germany four months ago, that one account belongs to a contractor whose engagement ended six weeks ago, or that elevated directory group membership extends the user's effective access well beyond what the SAP roles suggest.

Role names, without context, are not reviewable in any meaningful sense.

Why do spreadsheet access reviews fail manufacturing teams?

The failure is structural, not accidental. It shows up in six recurring patterns.

  1. Reviewers lack the context to make meaningful decisions. SAP role names are technical identifiers. A business manager looking at "MM_BUYER_SENIOR" cannot tell from the name whether it creates risk, so most managers approve what they do not understand rather than escalate every unfamiliar role. The rubber-stamp problem is not a behavior problem. It is a design problem.
  2. Plant access is reviewed in isolation from enterprise access. A user may hold individually acceptable access in each system while holding a cross-system combination that creates material risk. Spreadsheet reviews, almost always system-by-system, never surface this.
  3. Contractor access becomes permanent by default. Contractor accounts get the same periodic cycle as employees — too infrequent to catch expired engagements before they become a finding. Without automated expiration and time-bound grants, the quarterly spreadsheet is the only checkpoint, and it never runs at the moment an engagement ends.
  4. Lifecycle events do not trigger timely reviews. A plant transfer, promotion, termination, or role change should trigger a review in real time. Spreadsheets run on fixed schedules, so a user who changes roles in January may not be reviewed until Q3. Six months of inappropriate access is not a control — it is a gap.
  5. Remediation evidence is incomplete or absent. When a reviewer marks a row for revocation, what follows is usually an email, a ticket that may or may not be tracked, and no structured record of what was done or when. A review that cannot demonstrate remediation outcomes is not audit-ready — it is audit theater.
  6. Review decisions are disconnected from SoD risk. The most dangerous combinations — vendor master plus payment run, production order creation plus confirmation — only become visible when access is mapped across roles and modules simultaneously. For a breakdown of the conflicts a review should catch, see The 10 Most Dangerous SAP Access Conflicts in Manufacturing.

What does a completed spreadsheet review actually prove?

A completed spreadsheet proves that a list was distributed, rows were marked, and the sheet was filed. It does not prove that reviewers understood what they approved, that conflicts were identified, that revoked access was actually removed, or that the review covered the full user profile.

An auditor is looking for a governed process: a triggered or scheduled campaign, access presented with business context and risk indicators, decisions captured in workflow, revocations tracked to completion with timestamps, exceptions documented with rationale, and the full record retained as exportable evidence. A spreadsheet produces the first item on that list at best.

Why is manufacturing harder than most industries?

Manufacturing amplifies every weakness in spreadsheet-based reviews because its identity estate is more complex and more dynamic than in most industries.

Multi-plant operations mean frequent role changes. Employees move between plants, take temporary supervisory roles, and cover for absent colleagues — changing access requirements faster than a quarterly cycle can track.

Contractor populations are large and transient. Non-employee workforces need the same rigor as employees — defined sponsors, time-bound grants, reviews triggered at contract end. Spreadsheets treat them as just more rows.

SAP environments are deep and cross-functional. The real risk lives at the authorization-object level, in combinations spanning procurement, finance, production, quality, and HR. A list of role names cannot surface that depth.

Audit scope has expanded. Auditors now test access governance across SAP, Active Directory, ServiceNow, HR systems, and plant applications — and expect one coherent evidence trail, not disconnected system-by-system artifacts.

What does a meaningful access review process look like?

The alternative is not more spreadsheets with better formatting. It is a governed process in which reviews are triggered by events — joiner, mover, leaver, plant transfer, contractor expiration — as well as scheduled campaigns. Reviewers see access with business context: what the role does, what risk it carries, whether it conflicts with the user's other access. Revocations are tracked to completion with timestamps. Exceptions are documented with rationale, not silently carried forward. And the entire record lives in a single audit trail that needs no manual reconstruction.

This is what teams operating under SOX ITGC, ISO 27001, or internal risk governance need to demonstrate: not a completed spreadsheet, but a defensible evidence trail.

For the full picture of manufacturing identity governance beyond access reviews — including the evidence gap argument and the seven-step framework — the white paper The Audit Was Never Just SAP covers the complete model. The OpenIAM manufacturing identity governance solution page covers how a unified platform supports this process.

Frequently asked questions

What is a user access review in manufacturing?

A periodic or event-driven process in which managers confirm that each user's access across SAP, plant systems, and directory services is still appropriate for their current role. It should surface SoD conflicts, flag expired accounts, and produce a documented decision for every item in scope.

Why do spreadsheet access reviews fail in manufacturing environments?

They present role names without risk context, run on fixed schedules that miss lifecycle events, review systems in isolation, and produce no structured evidence of remediation. Completed spreadsheets prove only that a list was distributed — not that inappropriate access was identified and removed.

How often should manufacturing companies run access reviews?

On two tracks: scheduled campaigns at least annually (quarterly for high-risk and privileged access), and event-driven reviews triggered by plant transfers, role changes, terminations, and contractor expirations. Schedules alone mean access that becomes inappropriate in January may not be caught until Q3.

How should SAP SoD violations appear in access reviews?

Each item should be flagged with its SoD conflict status — whether the role, combined with the user's other access, creates a violation — and its risk rating. The reviewer's decision then becomes a documented risk judgment, not a blind approval of a role name.

What evidence does an auditor expect from an access review?

The full chain: campaign scope and trigger, reviewer identity and decision for each item, remediation actions for revoked items, timestamps confirming when access was removed, and documented exceptions with rationale. A spreadsheet satisfies none of this without a governed workflow behind it.

How do automated access reviews improve compliance outcomes?

They present access with SoD conflict context, trigger reviews from HR lifecycle events in real time, track remediation to completion with timestamps, cover SAP and non-SAP systems in a single campaign, and retain every decision in an exportable audit trail.

Share

Leave a Comment

footer-top-logo
openIAM-white-logo

All modules of our IAM platform share a common infrastructure allowing customers to see one unified identity solution versus a collection of disparate products.

  • linkedin-icon
  • facebook-icon
  • twitter-icon
  • youtube-icon

sales@openiam.com

(858)935-7561

Copyright © 2026 OpenIAM. All rights reserved.
  • Privacy Policy