The spreadsheet isn't wrong. It's unanswerable.
Almost every heat-treat shop runs its compliance on a spreadsheet at some point, and for a while it is the right tool. It is fast, everyone can read it, and it holds the numbers. The spreadsheet does not fail because someone fat-fingers a formula. It fails because of what it is — a grid of current values with no memory of how they got there — and that failure only becomes visible when an auditor asks a question the grid has no shape to answer.
There are four such questions. A shop that has been audited has met at least one.
1. “Show me the state on the day this load ran”
An auditor picks a job from a year ago and asks whether the furnace was compliant on the day it ran — which SAT was in force then, which calibration applied, what the furnace was qualified for under the survey current at the time.
A spreadsheet holds one row per instrument, and that row gets overwritten every time a new SAT is performed. The value that was true a year ago is gone; the cell now holds today’s value. There is no place in the grid for “this, until that date, then this.” You can bolt on a history tab, but a history tab maintained by copy-paste is a history of what somebody remembered to copy. Reconstructing a past date honestly needs append-only records or a snapshot frozen at the point of use, and a spreadsheet is neither by default — it is a live surface that forgets as it updates.
2. “Prove this ‘Pass’ is a measurement, not an opinion”
A cell that says Pass says nothing about where the word came from. A system accuracy test is
arithmetic — a reading, a test-thermocouple correction, a comparison against tolerance — and the
result should fall out of the numbers.
SAT and TUS both compute their verdicts from readings.
In a spreadsheet, Pass is whatever was typed or whatever a formula produced from cells that can
themselves be typed over. Nothing distinguishes a computed pass from a pass a tired technician
entered at 2am, and nothing prevents the second. The workbook cannot show its work, because the work
and the answer occupy the same cell.
3. “What stopped the overdue furnace?”
This is the one that reframes the problem. A spreadsheet is a record. A record describes; it does not prevent. When a furnace’s SAT comes due, the spreadsheet does not turn red and refuse — a cell can be conditionally formatted, but formatting is a suggestion, and a load can be built on an overdue furnace with the spreadsheet none the wiser, because the spreadsheet was never in the path of building the load.
The honest answer to “what stopped it” is “nothing did; we noticed afterward.” Compliance that lives beside the work instead of in the path of the work can only ever document a mistake after it ships. That is the structural gap, and no amount of formulae closes it, because a workbook has no way to be asked before a load exists.
4. “Which version of this produced that number?”
Spreadsheets sprawl. There is the master, the copy on the quality manager’s desktop, the one emailed to a customer, the one with the formula somebody fixed but did not push back. When an auditor points at a number, the question “which version of the workbook, with which formulae, produced this” often has no answer, because the artifact and the logic that made it are the same mutable file with no version anyone can name.
“Just add more tabs” doesn’t fix any of this
The instinct is to patch each question with structure: a history tab for #1, locked cells for #2, a macro for #3, a shared drive for #4. But every patch is still maintained by the same hands that were the point of failure, and none of them changes the thing underneath — a spreadsheet is a current-state grid that people edit, and compliance is a question about past state that has to be enforced and derived, not edited.
At that point you are building a database inside a spreadsheet, badly, and the honest move is to let the load be a real object with its own frozen evidence — which is the whole argument for load-centric software and the reason heat treat breaks the generic tools it is handed.
The test
Before you trust a spreadsheet through your next audit, run the audit against it yourself:
Pick a load from a year ago. From the workbook alone, name the SAT that was current when it ran — not the current one — and prove its pass came from the readings.
If that takes a query, you have a system. If it takes archaeology across tabs and old email attachments, you have a filing cabinet that happens to do arithmetic, and the auditor will find the seam faster than you will.
None of this is an argument that spreadsheets are bad tools. They are excellent at what they are — current values and fast math. Compliance is a different job: past state, reconstructed on demand and enforced at the point of use. The spreadsheet fails the audit not by being wrong but by being asked to be something it never was.