Hosted platform · SharePoint
From a saved workbook to a recorded decision
What happens between someone pressing Save and someone else being able to say the change is fine. This page follows it through our 15-sheet demo model, then answers the questions your own IT and audit people will ask you.
Step one
Connect the SharePoint library they already save to
Your Microsoft 365 admin grants SheetDelta access to the sites you name, and you pick which workbooks in them to watch. From then on, every new version of a watched workbook is captured and compared against the one before it.
The people who edit the model do nothing differently. They stay in Excel, they save to the same place, and they never upload a version. Reviewers are the only ones who open SheetDelta.
Versions of a connected workbook are stored and processed on the hosted platform. What that means for permissions, and what you would be granting, is below.
Step two
Decide how much review this workbook deserves
Set per workbook or per project. The working forecast and the model behind the board pack do not need the same treatment, and most files never need more than the first row.
Track-only
People editing
Keep editing and saving where they always did.
People reviewing
Version history and comparisons when someone wants them. Nothing to approve.
The file publishes
Immediately, as today.
Observe
People editing
Keep editing and saving. Review happens after the fact.
People reviewing
Discuss the change and record an optional approval.
The file publishes
Immediately, as today.
Four-eyes
People editing
Submit the change for review.
People reviewing
One approver other than the author, and open comment threads resolved. Reviewers are routed by which sheets the change touched.
The file publishes
Immediately. This setting records the decision; it does not hold the file.
Gate
People editing
Work through the staging copy, or accept that an unapproved save is reverted.
People reviewing
Two approvers, resolved comments, and the workbook’s own controls passing.
The file publishes
Only after approval, by SheetDelta.
If publication has to wait
The gate comes two ways. With staging, people edit a working copy and SheetDelta publishes it to the real file once it is approved, which means the published file needs SharePoint permissions that stop anyone editing it directly. With revert, SheetDelta picks up an unapproved save and restores the last approved version; that happens after the save, and a file someone has open or locked can defeat it. Gates are part of the intended Team Plus and Business tiers.
Step three
Read the change where it happened
The previous value sits above its replacement, in the cell it lives in. Formulas are compared as logic, so a block that moved reads as one change. Rows, columns, sheets, named ranges, charts, pivots, validations, styles and VBA modules are compared too, within the workbook content we parse.
-
What changed, cell by cell. The old value sits struck through above the new one, in the cells where they live. Formulas keep their highlighting. An edit that only changed a format carries an FMT badge so it does not inflate the count, and each sheet tab shows its own. The panel on the right groups the change into ranges and says what each one reaches.
Ask why Drivers!I14 became 2,500
Comment on the cell or the range, ask for changes, sign off. The thread belongs to the cell, so the reason is still there when someone comes back to the model in March.
SheetDelta records who authored a version and who opened, reviewed and approved a change. It does not attribute an individual cell to an individual person. A saved workbook carries no record of who typed which cell, so there is nothing in the file to recover it from.
-
Who changed it, and the argument about it. A comment lands on the cell it is about. Here a reviewer asks why FY29 subscription revenue is a typed-in 2,500 on Drivers!I14, and gets an answer in the thread. Whoever made the change describes it once, and the discussion stays next to the number.
Step four
See what is holding it up
A workbook can carry whatever rules its owners write for it, and a capex envelope, a churn policy, or a balance sheet that has to tie are just the ones our demo uses. SheetDelta re-checks them on every version and reports which held, which broke, and which it could not check. A broken one blocks sign-off. Findings from our risk catalogue sit beside them, and so do the approvals and open threads the review setting asks for.
-
Whether it is safe to sign off. A workbook can carry whatever rules its owners write for it. A capex envelope, a churn policy, a balance sheet that has to tie: SheetDelta re-checks them on every version and reports which broke, which held, and which it could not check. Two broken controls are holding this change up.
Nobody stops working while you review
Several changes to one workbook can be open at once. Each says whose it is, what state it is in, and who it waits on. A change whose published model has moved underneath it is marked as needing a refresh rather than quietly comparing against the wrong thing.
-
Every change to one model, and who it waits on. Four people editing the same workbook, without four copies called final-v2. Each change says whose it is, what state it is in, and who has to act next. One of them needs refreshing, because the published model moved underneath it.
And when two of them changed it
Combine reads both versions against the one they came from and proposes the changes by group: formulas and values, formatting, data validations, comments, and whole added or removed sheets. You approve each group. The engine then re-reads the file it produced with its own reader and checks it against what you approved, and if it cannot verify the result it does not hand you a file.
That check is about the combination, not about the model. It says the approved changes are in the output and nothing else is. It says nothing about whether the forecast is right.
What Combine checks, what it does not, and what happens when it fails →Step five
Keep the decision with the versions it was about
A signed-off review prints to one page: who opened it and when, the SHA-256 of both versions compared, what changed by kind and by sheet, and the decision. The comments and approvals behind it are retained and exportable.
Each version carries its SHA-256, so you can check whether the file in front of you is the one that was reviewed. We do not sign or seal the export itself, so treat it as a record from our system rather than as independent cryptographic proof. More about the review record
-
The record it prints to. Every signed-off review prints to one page: who opened it and when, the SHA-256 of both versions compared, what changed by kind and by sheet, and the decision. You can hand it to whoever asks what happened to the model.
Check what an assistant changed beyond what it said
An assistant that submits a version through the platform describes what it did. SheetDelta checks that description against the cells that moved and names the ones it did not mention. It signs in over OAuth under the permissions of the person who connected it, and its work lands in the same audit trail as everyone else's.
SheetDelta for AI agents →Before you connect a SharePoint library
The six things you will be asked by whoever has to approve this, answered at the level they will be asked at.
We cannot move these files. Other teams link to them.
Nothing moves. The workbooks stay in the SharePoint library they are in now, with the same URLs, and SheetDelta reads each new version from there. The one setting that changes where people type is the staging form of the publication gate, where authors work in a separate copy and SheetDelta writes the approved version back to the published file. That one is off unless you turn it on for a specific workbook.
What access are we giving you to SharePoint?
The background connector uses Microsoft Graph’s Sites.Selected model, so it can reach only the sites an admin has granted and never the rest of your tenant. Two things about that grant are worth knowing before you take it to IT. The grant is made per site collection and asks for the full control role on it, because that is what lets every later library- and file-level grant happen without elevated scope again. And during the grant session itself, the admin’s own delegated Sites.FullControl.All is used to list the sites; that token stays in memory for the length of the session and is never stored. The list of workbooks we watch is our setting inside that access, not the boundary of it.
Will everyone in SheetDelta see all of our workbooks?
For a workbook that came from SharePoint, we ask SharePoint, per person, per workbook: we hold no copy of your groups or permissions, so site groups, broken inheritance, item-level permissions, sharing links and guest access are all honoured by construction. Two exceptions you should know: organisation owners and admins are unrestricted, and a workbook someone uploaded directly has no SharePoint permissions to consult, so it is visible across your SheetDelta organisation. Answers are cached for five minutes, so a permission you revoke takes up to that long to bite. If we cannot get a delegated token at all, SharePoint-sourced workbooks are hidden and the page says so with the reason and the count, rather than showing an empty list. Per-user filtering is built; validating it against a live customer tenant is still ahead of us.
What happens if someone saves again while a review is open?
A review compares two captured versions, so a later save becomes another version to look at rather than something that quietly changes the review under you. If the published model moves while someone is working on a copy of it, that copy is marked as needing a refresh. If the published file changes between submission and publication, SheetDelta stops the publication and reopens the review. One limit to know today: when a change is returned to draft and resubmitted, approvals already given can still count toward the requirement, so treat a resubmission as needing a fresh look rather than assuming the platform will demand one.
Can we run it inside our own network?
Yes, including air-gapped. You provide the database and the object storage, and the whole platform runs in your environment, so no workbook leaves it. Self-hosted is sold directly on an annual contract with deployment support. to talk through your setup.
What do we keep if we stop using SheetDelta?
Your workbooks were never ours: they are in your SharePoint throughout, and the versions you care about are the ones your own library already holds. The review history, comments and decisions live in the platform and are exportable, so the thing to settle before you roll out is when you export and where you keep it. On the hosted platform, comparison and sign-off stop working if the service does. Self-hosted, you hold the database and the object storage yourself.
Pick the first workbook
One workbook, its owner, and the two or three people who would review a change to it. Decide whether that first one wants history only, an independent approver, or a gate. Most teams start at history only and never move.
Team is $29 per user per month, Team Plus and Business start at $49, and self-hosted is an annual contract sold directly. Pricing has the full comparison and where things stand.
Related: Excel version control, Excel audit trail, spreadsheet governance, and how this differs from xltrail.