JOURNAL
Published on
WHEN A SPREADSHEETBECOMES A RISK
The spreadsheet is never the problem. The day it became the record is.
THE ANSWER
A spreadsheet becomes a business risk when it stops being a calculation. It becomes the record: the only place a figure exists. The list of people who can open it is no longer checked. The formulas decisions rest on haven’t been reread in months. The limit isn’t technical: nobody answers for the file.

AI-generated image
IN SHORT
Write at the top who answers for the file.
Wrong formulas don’t stop: they answer anyway.
Need per-row permissions and the sheet is done.
THE POINT
THE SPREADSHEET ISN’T THE PROBLEM
I use spreadsheets every day. I have no intention of talking you out of them. The risk doesn’t start there. It starts the day the file stops being a working copy and becomes the original. The only place recording who has paid, who is late, how much was ordered. (From then on it is a system handled like a document.)
WHERE IT BREAKS
THE LIMITS OF SPREADSHEETS AT WORK
None of these risks announces itself with an error on screen. That is why they stand for years.
Access is a list nobody rereads
A sheet is shared in a second and almost never unshared. The people who can open it include consultants who left, colleagues who moved role, whoever a link reached. Edit rights get granted to avoid a conversation.
Versions multiply on their own
One downloaded attachment, and there are two files. Neither announces that it is the old one. When somebody asks which is the latest, the file is doing a job that isn’t its own.
Formulas age without warning
A formula written 2 years ago keeps returning a result even after the range it sums stopped one row short. It doesn’t break: it answers. In a program something stops and somebody notices.
The file has become the system
Status columns, colours that mean something, one row per case, a second sheet counting the first. It is a program written where nobody programs. The documentation is one person’s memory.

AI-generated image
WHAT TO DO
LOWER THE RISK, KEEP THE FILE
None of these steps needs a project, a budget or me. They are an afternoon, and they change the file’s risk category.
Name the owner
One person answers for that file: who has access, what the columns mean, when it gets archived. A file with no owner is a file nobody answers for.
Reread the list of who can open it
Remove the open links, remove people no longer on that process, leave edit rights with those who use it. Everyone else reads.
Separate the data from the calculation
Raw data in one sheet, formulas and summaries in another that reads it. A badly pasted row then spoils one thing only.
Lock what must not be touched
Protect the calculated columns and the headers. Validation on the fields that must have a shape — dates, statuses, amounts — removes half the mistakes.
Freeze a copy at regular intervals
A read-only copy, with the date in its name, kept somewhere else. It answers what last month looked like without consulting anyone’s memory.
Write at the top what it means
Two lines: what the file holds, who updates it, what must not be done to it.
THE SIGNALS
WHEN THE SPREADSHEET IS DONE
Two people decide on the same row
Not a technical limit: shared sheets handle simultaneous work well. Two people decide differently on the same case and neither knows. A sheet has no way of saying that a row already belongs to someone.
Somebody needs permissions a sheet can’t give
The moment one person must see their own cases and not everybody else’s, the spreadsheet is finished. Row-level permissions don’t exist. Separate files do, and separate files drift apart.
The same value is corrected twice
If changing an address means changing it here and in the main system, one of the two falls behind. It isn’t how careful people are. It is how many times a day you ask them to be.
The file holds data that shouldn’t travel
Full client records, third-party financial detail, information given for one purpose. The right question isn’t whether the sheet is secure, but whether you could say who has had access these past 6 months.
A spreadsheet doesn’t break: it answers anyway, with the wrong number.
QUESTIONS
- So should I stop using spreadsheets?
- No, and anyone who says otherwise is selling something. A spreadsheet is right for a calculation, for a short-lived list, for trying an idea. The line is the moment it becomes the only place a value exists.
- Does an online sheet differ from one on a laptop?
- On these risks, barely. Sharing and history are more comfortable online, and one fewer copy on a laptop is one fewer exposure. But the missing owner and the unread formulas are identical.
- Isn’t version history enough?
- It shows what changed; it doesn’t stop the change. And it gets consulted after somebody has spotted a problem. If the error returns a plausible number, nobody goes looking.
- Where do I start, if time is short?
- The access list, and the owner’s name written at the top of the file. Both take a quarter of an hour. They remove the part of the risk that has nothing to do with the sheet.
Once a spreadsheet has stopped being a spreadsheet, replacing it isn’t a large program. It is the smallest piece that holds the data and the permissions. The sheet keeps doing the sums on top.