Independent IFS Cloud practice · Manufacturing
The spreadsheet that runs the factory: shadow-IT risk in IFS Cloud and how to close it
Key takeaways
- Almost every plant has a desktop spreadsheet that bridges the gap between what IFS was configured to do at go-live and how the operation actually runs three years later.
- It is dangerous not because it is a spreadsheet, but because it has no backup, no access control, no audit trail and exactly one person who understands it.
- It survives because it works — right up until the author is away, the laptop dies, or someone sorts one column without selecting the rest.
- The fix is not banning spreadsheets. It is moving the specific logic they carry into a structure IFS Cloud can back up, secure and log — and staying update-safe while doing it.
Every manufacturing site has one. A spreadsheet that is not on the network. It lives on a desktop. It has a dozen tabs, and one person understands the columns that actually drive the numbers everyone downstream relies on. It tracks the things IFS does not track, or tracks in a way that no longer matches how the floor works. It bridges the gap between what was configured at go-live and what the operation turned into over the following three years. The spreadsheet works perfectly — until the author is on leave, or the laptop dies, or someone sorts column F without selecting the whole range. A spreadsheet that runs a factory is not a tool. It is a liability wearing a familiar face, and the familiarity is exactly what makes nobody question it. This article covers why it exists, what it actually risks, and how to bring its logic into IFS Cloud without a disruptive rebuild.
1.Why does the shadow spreadsheet exist?
At go-live, IFS was configured to match the operation as it existed on that date. The operation did not stand still. New product lines arrived, a quality step got added, a customer started demanding a report nobody had asked for before — and every one of those changes needed either a proper configuration change or a workaround. A configuration change needs budget, approval and a project slot. A workaround needs Excel and an afternoon.
A power user who understands both the process and a spreadsheet formula solves the gap locally, inside their own authority, without asking anyone. It works, so it stays. Three years later nobody remembers it was meant to be temporary, and the plant now depends on a file that IT does not know exists, finance cannot audit, and only one person can actually maintain.
2.What does the shadow spreadsheet actually risk?
The risk rarely shows up as a single dramatic failure. It shows up as an accumulation of small exposures that only become visible the day one of them triggers.
- Bus-factor risk. One person understands the formulas, the macros and the exceptions baked in over the years. When they leave, the knowledge leaves with them.
- No backup. A file that lives on one desktop is one hardware failure away from disappearing, taking years of undocumented logic with it.
- Silent drift from the system of record. The spreadsheet and IFS quietly disagree, and decisions get made on whichever number was open on screen.
- No access control or audit trail. Anyone with the file can edit any cell, and nothing records who changed what or when.
The spreadsheet does not fail when it breaks. It fails long before that, the moment everyone stops noticing it is the thing actually running the shop floor.
3.How do you find where this is happening?
You will not find a shadow spreadsheet by querying IFS Cloud — by definition it lives outside it. What you can do is instrument the boundary: use Quick Reports and Custom Fields to see what people are actually pulling out of IFS and what fields get manually annotated after export, because that is where a gap between the system and the shop floor tends to surface first. A short, direct conversation with each cell or line supervisor — “what do you keep track of that IFS does not show you?” — usually surfaces the rest within a day.
The comparison covered in Quick Reports, Custom Fields and Custom Events is the right lens here: each shadow spreadsheet column is really an unmet requirement for one of those three tools, and knowing which one it maps to tells you how hard the fix actually is.
4.Desktop spreadsheet versus systematic extension
The comparison is not spreadsheet versus no spreadsheet. It is an uncontrolled file versus the same logic captured inside a structure IFS Cloud actually manages.
| Desktop spreadsheet | Systematic extension | |
|---|---|---|
| Backup | Whatever the laptop policy is | Standard system backup |
| Access control | Whoever has the file | Role-based, as configured |
| Audit trail | None | Logged change history |
| Single point of failure | One person, one device | None — part of the platform |
| Alignment with source data | Manually re-entered, drifts | Reads live IFS data |
None of this requires ripping the spreadsheet out overnight. It requires identifying which of its columns actually matter and giving each one a proper, supported home — a Custom Field where a value needs to live on the record, a Quick Report where it needs to be seen, a Custom Event where it needs to trigger something. That is the same Clean Core discipline covered in Clean Core in IFS Cloud SCM.
5.How do you migrate it safely?
Treat the spreadsheet as a specification, not an enemy. Its author has already solved the problem once; the job is to give that solution a supported home.
- Inventory what it actually tracks. Sit with the owner and list every column that drives a real decision, separately from the ones that are just notes.
- Map each column to a tool. Decide, column by column, whether it belongs as a Custom Field, a Quick Report, or a Custom Event trigger.
- Build against the owner, not around them. They know the exceptions nobody wrote down; involve them and you keep that knowledge instead of losing it a second time.
- Run the two in parallel. Let the spreadsheet and the new structure operate side by side for a cycle before anyone deletes the old file.
- Retire it once it agrees. Cut over only after a full cycle shows the two sources matching, and keep a read-only copy of the old file for reference.
Because the replacement is built with standard Custom Fields, Quick Reports and Custom Events inside the IFS Extensibility Framework, it is update-safe — no core modification for the next release to break, and no more single laptop standing between the floor and a working process.
6.Frequently asked questions
What if the spreadsheet owner resists handing it over?
Frame it as protecting their work, not replacing it. Most owners built the spreadsheet because nobody gave them a proper tool, and they are often the most relieved once the logic is safely captured somewhere it cannot be lost with one hardware failure.
How long does migrating one spreadsheet take?
It depends on how much of it turns out to be logic versus notes. A spreadsheet with three or four columns that actually drive decisions can often move to Custom Fields and a Quick Report within a couple of weeks, parallel run included.
Does this mean banning spreadsheets entirely?
No. A spreadsheet used for genuine one-off analysis is not the risk. The risk is a spreadsheet that has quietly become a permanent, single-person system of record for something IFS should be tracking and backing up.
Is this update-safe?
Yes. The migration uses standard Custom Fields, Quick Reports and Custom Events inside the IFS Extensibility Framework — no core modification, so nothing here is broken by the next R1/R2 release.
7.About the author
Dariusz Myśliwiec — 25+ years in ERP and supply chain, 17+ on IFS (Apps 7.5–10 and IFS Cloud). IFS Certified Associate Consultant. PRINCE2® 7. Independent practice based in Kraków, delivered remotely across Europe and globally — you talk to the consultant who builds it, not a sales layer.
Selected clients: Fugro · LGC · BVI Medical · Betafence (PRÆSIDIAD) · Barlinek · NGK Ceramics · Newag · Oleofarm.
IFS is a registered trademark of IFS AB; this practice is not affiliated with IFS AB.
Find out what your floor is really running on
If you suspect a spreadsheet is quietly load-bearing somewhere in your operation, a short discovery pass will tell you exactly which columns matter. On a 30-minute call I’ll map a safe path to bring it inside IFS Cloud — fixed price, parallel run before anything is retired.
