Most people compare these two on features and pick the longer list. The more useful question is which problem you have right now. If you can't say, today, which accounts from the last three departures are still open, no amount of automation helps — you'd be automating against a list you don't have. Building that list needs no vendor and no integration work. Wiring a platform into every app you own needs both.
So the order tends to matter more than the choice. Get the record right, then buy the thing that acts on it.
What each one is for
- An access tracker spreadsheet is a record. It lists every system a person can reach, scores the still-open items by sensitivity and days open, and splits a role change into what to grant, revoke, and hand over before the account closes. It answers “what's still open, and what do I close first?” It never holds a password, access key or recovery code — it records that access exists, not how to use it.
- IT onboarding / identity-management software can act. Working through a directory or single sign-on — usually one it provides — it can create and disable accounts across every connected app in one action, discover accounts it was never told about, and log every change for an audit. It answers “turn this person's access on or off, automatically, across everything we've connected.” That is a real capability a spreadsheet has no version of.
When a tracker spreadsheet is exactly right
- Your accounts are separate logins. There's no directory or single sign-on for a platform to work through, so there's nothing wired together for it to switch off yet.
- You handle a handful of changes a month. A few joiners, movers, and leavers — not a steady stream.
- You want a record the team can read. A file anyone can open and understand, rather than a console only one person knows.
- Equipment and hand-over matter to you. The laptop coming back and who inherits shared files are often handled by a separate tool on the platform side, if at all.
- You'd rather own a file. No vendor, no per-seat bill, no renewal date.
At this size, the spreadsheet isn't a lesser version of the platform — it's doing the part of the job that's actually yours to do by hand. It's the middle leg of the joiner-mover-leaver process — the role change, where the old access has to come off — that a plain checklist tends to lose. The templates for HR & team leads hub collects the rest of the toolset.
When you may want a full platform instead
- Your apps are already wired to one directory. Single sign-on gives the software something real to switch off in one action.
- You need access revoked, not just recorded. A spreadsheet can tell you an account is still open; it can never close it for you.
- You need to find accounts you forgot about. Discovery only works against a connected system — a spreadsheet only knows what somebody typed into it.
- You need audit logs and approval workflows. A formal security review usually wants evidence a platform generates on its own.
- You're managing access for a few hundred people or more. Past a certain headcount, working through this by hand stops scaling.
These are not small advantages, and a spreadsheet has no answer to any of them. Even then, the equipment and the hand-over problem don't go away — a laptop still has to come back, and shared files still need a new owner before an account closes. Whether a platform covers those depends on the product; on many stacks they live in a separate asset tool, or in a spreadsheet.
Access tracker spreadsheet vs IT onboarding software, side by side
| What matters | Access tracker spreadsheet (owned workbook) | IT onboarding / identity software |
|---|---|---|
| What it is | A ranked record of who has access to what | A platform that can grant and revoke access itself |
| Cost | One-time, low — you own the file | Ongoing subscription, typically per user |
| Revoking access | Tells you what to close and in what order | Can switch it off directly, where connected |
| Discovering forgotten accounts | Only knows what you've recorded | Can find accounts you didn't know existed |
| Equipment & hand-over | Tracks unreturned equipment and who inherits shared files | Often a separate asset tool |
| Audit logs & approvals | A dated record you maintain by hand | Generated automatically, built for a formal review |
| Setup | Open it and start entering people — same day | Connect your apps to a directory or single sign-on first |
| Data ownership | Yours to keep — your own drive or Google account; keep it access-controlled | Hosted in the vendor's platform |
| Best for | A company with no IT department, a handful of changes a month | A company with a directory, changing access at volume |
The honest middle ground: which one comes first
Plenty of companies grow into identity software eventually, and that's the right move once the apps are connected and there are enough joiners, movers, and leavers that working through them by hand stops scaling. When that day comes, the platform does something the spreadsheet never could — it revokes. The mistake is only the order: paying a per-seat fee to automate deprovisioning across a pile of unconnected logins, before the connecting work that makes the automation real. The spreadsheet's job — make sure nothing gets forgotten, say what to do first — is the discipline that makes the eventual move a smooth handoff instead of a scramble to reconstruct who has access to what.
Track access either way
Whichever stack you end up on, somebody still has to know what's still open and what to close first. Running one person right now? The free single-person onboarding & offboarding checklist has 18 common systems already filled in and the hand-over-first flag set. No signup.
Once you're tracking more than one person at a time, the Onboarding & Offboarding Equipment & Access Tracker is the full version, and it ships with a Start Here guide, a printed Systems Quick Reference, and a Handover & Recovery Forms pack — an equipment return receipt, an ownership handover sign-off and a first-day setup sheet. Keep the finished file restricted to the people who run the process. Own the record; add a platform once the apps are connected for it to act on.
Frequently asked questions
- What's the difference between an access tracker spreadsheet and IT onboarding software?
- An access tracker spreadsheet is a record: it lists every system a person can get into, ranks the still-open items by how sensitive the system is and how long they've sat open, and works out the grant, revoke and hand-over list for a role change. IT onboarding or identity-management software is a platform that connects to your actual applications — usually through a directory or single sign-on it provides — so it can switch access on and off itself instead of only recording that somebody should. One tells you what to do and in what order; the other does it. The catch is that the platform's advantage arrives with the connecting: until your applications are wired to it, somebody is still opening each app by hand, which is why the record is usually the piece a small company can put in place first.
- Can a spreadsheet replace identity or IT onboarding software?
- If your job is knowing who has access to what, surfacing the recorded items nobody closed, and handing off ownership before an account is disabled, a spreadsheet covers it. It also carries two things identity software often leaves to another tool — physical equipment coming back, and who inherits shared files before an account closes. What a spreadsheet cannot do is revoke access itself, find accounts nobody ever typed in, or generate an audit trail for a formal review. Those are real limits, not small ones. If your apps are wired to one directory and you're changing access for a few hundred people, the software earns its cost. If you have a pile of separate logins and a handful of changes a month, the spreadsheet is doing the whole job.
- How much does an access tracker spreadsheet cost vs IT onboarding software?
- An owned access tracker is a single low one-time cost — you keep the file and reuse it for every joiner, mover, and leaver with nothing recurring. IT onboarding and identity-management platforms are typically priced per user per month, and the subscription is only part of the cost: connecting each of your applications to the platform is the work that makes the automation real, and how much work that is depends on your apps and the platform. Paying per seat before that work is done buys the subscription rather than the automation, because a person is still going into each unconnected app by hand.
- Do we need IT onboarding software if we don't have an IT department?
- You may well want one eventually — but the order matters. A platform can bring its own directory and single sign-on; what it cannot bring is your applications already connected to it. How much work that connecting is depends on your apps and the platform — some are a few clicks, others are a project — but it is work somebody has to do. Until it's done, the platform's headline advantage — switching access off everywhere in one action — reaches only the apps you've wired up, and somebody is still working through the rest by hand. A tracker spreadsheet fits that reality now: it makes sure nothing gets forgotten and tells you what to close first. The habits it builds — one record, ranked by risk, checked on every departure — are also what make a later move to identity software straightforward rather than a fresh start, because you already know every system that will need connecting.