Spreadsheets vs dedicated licence tracking: when to actually switch
Nobody sets out to run compliance on a spreadsheet forever. It is the obvious first tool — free, familiar, fast to set up — and for a small operation it genuinely works. The question worth asking periodically is not whether the sheet still exists, but whether it still describes reality. See tracking licence expiry without a spreadsheet for the specific ways it drifts.
Signals worth paying attention to
There is no fixed headcount at which a spreadsheet stops working — it depends on how many people touch it and how often things change. A handful of recurring signals are more reliable than a number.
- More than one person needs to update it, and versions have started to disagree with each other
- Cover decisions get made by people who do not have the sheet open
- An assessment or audit took longer than it should have because information had to be assembled from several places
- A near-miss happened — an officer nearly rostered with an expired licence — and it was caught by luck, not by the system
- Onboarding a new site or contract means rebuilding structure the sheet was never designed to hold
Any one of these on its own is manageable. Two or three together usually means the sheet has outgrown what a spreadsheet can be trusted to do reliably, regardless of how carefully it is maintained.
What actually changes when you switch
The value of dedicated tracking is not that it is more accurate than a well-kept spreadsheet — a well-kept spreadsheet can be perfectly accurate. It is that the information sits where the decision gets made, rather than in a separate file someone has to remember to open. See what to look for in security management software for what that should look like in practice.
The cost of switching too late
Switching late tends to mean switching under pressure — after an assessment finding, or after a near-miss makes the exposure obvious. Migrating licence records, screening files and training history is straightforward when done calmly, and considerably less so when it is done in response to a problem that has already happened.
Key takeaways
- A spreadsheet is a reasonable starting point, not a permanent failure
- Watch for signals — multiple editors, cover decisions made without it open, near-misses — rather than a fixed size threshold
- The value of switching is proximity to the decision, not raw accuracy
- Migrating calmly beats migrating after a finding forces the issue
The SecureOptix team
Written by people who work daily with security contractors on SIA licensing, screening and the records that hold up under an inspection.