OpenIAM | Blog

Why Spreadsheet Access Reviews Fail Manufacturing Teams

Written by Mansoor Alam | Sep 10, 2026, 8:26:49 PM

A user access review is the process by which an organization periodically confirms that every user's access is still appropriate — and that access no longer needed has been removed. In manufacturing, these reviews cover SAP roles, directory groups, plant applications, contractor accounts, and privileged access across a complex multi-system estate.

The challenge is not that manufacturing companies are skipping these reviews. It is that most are running them on spreadsheets — and spreadsheet-based reviews create the appearance of compliance without the substance of it.

Key Takeaways

  • Spreadsheet access reviews separate the review decision from the risk context, the remediation evidence, and the lifecycle data that make a review meaningful.
  • A manager approving a list of role names cannot see SoD conflicts, plant transfer history, or contractor expiration status.
  • A completed spreadsheet proves a list was reviewed — not that inappropriate access was identified, acted on, and documented.

What does a spreadsheet access review actually look like?

In most manufacturing organizations, an IAM or GRC team exports access data from SAP and other systems into a spreadsheet and distributes it to managers and application owners. Reviewers mark each row — approve or revoke. Completed sheets are collected, filed, and the review is closed.

The problem is what the spreadsheet does not contain. The manager sees a list of SAP role names. They do not see that two of those roles, held by the same user, create a vendor master and payment run conflict. They do not see that the user transferred from a plant in Germany four months ago, that one account belongs to a contractor whose engagement ended six weeks ago, or that elevated directory group membership extends the user's effective access well beyond what the SAP roles suggest.

Role names, without context, are not reviewable in any meaningful sense.

Why do spreadsheet access reviews fail manufacturing teams?

The failure is structural, not accidental. It shows up in six recurring patterns.

  1. Reviewers lack the context to make meaningful decisions. SAP role names are technical identifiers. A business manager looking at "MM_BUYER_SENIOR" cannot tell from the name whether it creates risk, so most managers approve what they do not understand rather than escalate every unfamiliar role. The rubber-stamp problem is not a behavior problem. It is a design problem.
  2. Plant access is reviewed in isolation from enterprise access. A user may hold individually acceptable access in each system while holding a cross-system combination that creates material risk. Spreadsheet reviews, almost always system-by-system, never surface this.
  3. Contractor access becomes permanent by default. Contractor accounts get the same periodic cycle as employees — too infrequent to catch expired engagements before they become a finding. Without automated expiration and time-bound grants, the quarterly spreadsheet is the only checkpoint, and it never runs at the moment an engagement ends.
  4. Lifecycle events do not trigger timely reviews. A plant transfer, promotion, termination, or role change should trigger a review in real time. Spreadsheets run on fixed schedules, so a user who changes roles in January may not be reviewed until Q3. Six months of inappropriate access is not a control — it is a gap.
  5. Remediation evidence is incomplete or absent. When a reviewer marks a row for revocation, what follows is usually an email, a ticket that may or may not be tracked, and no structured record of what was done or when. A review that cannot demonstrate remediation outcomes is not audit-ready — it is audit theater.
  6. Review decisions are disconnected from SoD risk. The most dangerous combinations — vendor master plus payment run, production order creation plus confirmation — only become visible when access is mapped across roles and modules simultaneously. For a breakdown of the conflicts a review should catch, see The 10 Most Dangerous SAP Access Conflicts in Manufacturing.

What does a completed spreadsheet review actually prove?

A completed spreadsheet proves that a list was distributed, rows were marked, and the sheet was filed. It does not prove that reviewers understood what they approved, that conflicts were identified, that revoked access was actually removed, or that the review covered the full user profile.

An auditor is looking for a governed process: a triggered or scheduled campaign, access presented with business context and risk indicators, decisions captured in workflow, revocations tracked to completion with timestamps, exceptions documented with rationale, and the full record retained as exportable evidence. A spreadsheet produces the first item on that list at best.

Why is manufacturing harder than most industries?

Manufacturing amplifies every weakness in spreadsheet-based reviews because its identity estate is more complex and more dynamic than in most industries.

Multi-plant operations mean frequent role changes. Employees move between plants, take temporary supervisory roles, and cover for absent colleagues — changing access requirements faster than a quarterly cycle can track.

Contractor populations are large and transient. Non-employee workforces need the same rigor as employees — defined sponsors, time-bound grants, reviews triggered at contract end. Spreadsheets treat them as just more rows.

SAP environments are deep and cross-functional. The real risk lives at the authorization-object level, in combinations spanning procurement, finance, production, quality, and HR. A list of role names cannot surface that depth.

Audit scope has expanded. Auditors now test access governance across SAP, Active Directory, ServiceNow, HR systems, and plant applications — and expect one coherent evidence trail, not disconnected system-by-system artifacts.

What does a meaningful access review process look like?

The alternative is not more spreadsheets with better formatting. It is a governed process in which reviews are triggered by events — joiner, mover, leaver, plant transfer, contractor expiration — as well as scheduled campaigns. Reviewers see access with business context: what the role does, what risk it carries, whether it conflicts with the user's other access. Revocations are tracked to completion with timestamps. Exceptions are documented with rationale, not silently carried forward. And the entire record lives in a single audit trail that needs no manual reconstruction.

This is what teams operating under SOX ITGC, ISO 27001, or internal risk governance need to demonstrate: not a completed spreadsheet, but a defensible evidence trail.

For the full picture of manufacturing identity governance beyond access reviews — including the evidence gap argument and the seven-step framework — the white paper The Audit Was Never Just SAP covers the complete model. The OpenIAM manufacturing identity governance solution page covers how a unified platform supports this process.

Frequently asked questions

What is a user access review in manufacturing?

A periodic or event-driven process in which managers confirm that each user's access across SAP, plant systems, and directory services is still appropriate for their current role. It should surface SoD conflicts, flag expired accounts, and produce a documented decision for every item in scope.

Why do spreadsheet access reviews fail in manufacturing environments?

They present role names without risk context, run on fixed schedules that miss lifecycle events, review systems in isolation, and produce no structured evidence of remediation. Completed spreadsheets prove only that a list was distributed — not that inappropriate access was identified and removed.

How often should manufacturing companies run access reviews?

On two tracks: scheduled campaigns at least annually (quarterly for high-risk and privileged access), and event-driven reviews triggered by plant transfers, role changes, terminations, and contractor expirations. Schedules alone mean access that becomes inappropriate in January may not be caught until Q3.

How should SAP SoD violations appear in access reviews?

Each item should be flagged with its SoD conflict status — whether the role, combined with the user's other access, creates a violation — and its risk rating. The reviewer's decision then becomes a documented risk judgment, not a blind approval of a role name.

What evidence does an auditor expect from an access review?

The full chain: campaign scope and trigger, reviewer identity and decision for each item, remediation actions for revoked items, timestamps confirming when access was removed, and documented exceptions with rationale. A spreadsheet satisfies none of this without a governed workflow behind it.

How do automated access reviews improve compliance outcomes?

They present access with SoD conflict context, trigger reviews from HR lifecycle events in real time, track remediation to completion with timestamps, cover SAP and non-SAP systems in a single campaign, and retain every decision in an exportable audit trail.