Sage and Viewpoint Reports Gone Rogue: Controlling Exports

Job cost and payroll reports often leave your accounting system as spreadsheets. Learn how to control exports, shared files, and who can run sensitive reports.

3 min readBy Ironfield Cyber Team

Accounting and job cost systems are usually well protected at the login screen. Then someone exports a report to a spreadsheet and the data goes everywhere: email attachments, shared drives, personal laptops, and cloud folders. Payroll rates, margin data, customer lists, and vendor bank details end up in files that no longer have any of the controls of the original system.

This is not a hypothetical edge case. It is how sensitive information commonly leaves a business, whether by innocent sharing or deliberate misuse. This article explains how to control report exports in systems such as Sage and Viewpoint, and in other accounting platforms, without making work impossible.

Start by Identifying Sensitive Reports

List the reports that expose information you would not want broadly shared:

  • Payroll registers and employee pay rates
  • Job cost and margin reports
  • Vendor lists with bank or tax information
  • Customer and contract details
  • Bid and estimate summaries
  • Employee personal data, such as addresses and identification numbers

Ask department heads which reports they run, and why. You may find that people run broad reports when a narrow one would do.

Control Who Can Run and Export

Role-based permissions

Most accounting platforms allow you to restrict access to reports and the ability to export by role. Review which roles can run sensitive reports, and whether export to spreadsheet, PDF, or email is enabled. Limit access to those who need it for their jobs.

Separate duties

Avoid giving one person the ability to maintain vendors, release payments, and export vendor banking details. Separation of duties makes fraud harder and mistakes more visible.

Review regularly

Run a quarterly review of who has access to sensitive reports, in the same spirit as a user access review. Remove permissions that are no longer needed.

Use Logging and Alerts

Check whether your system records report execution and exports. If so, review logs for unusual patterns such as large exports late at night or by someone who does not usually run them. Where possible, create alerts for exports of especially sensitive data.

Limit Where Exports Can Go

Technical controls can reduce the spread:

  1. Data loss prevention rules in Microsoft 365 can warn or block when files contain patterns such as Social Security numbers or bank account numbers.
  2. Sensitivity labels can mark and protect files, restricting who may open or share them.
  3. Restricted sharing settings in SharePoint and OneDrive can prevent anonymous links to sensitive folders.
  4. Controls on removable media can block copying data to unmanaged USB drives.
  5. Managed devices only policies can prevent access to sensitive files from unmanaged personal computers.

Not every business needs every control. Start with the most sensitive data and expand.

Create a Safe Home for Exported Files

People export reports because they need to analyze them. Provide a secure place to do it, such as a protected folder with limited access, rather than leaving files on desktops and downloads folders. Give them templates and dashboards so they rely less on ad hoc spreadsheets.

Set Simple Rules

Communicate a few clear expectations:

  • Do not email payroll or personal data in plain attachments.
  • Delete exported files when you are done with them.
  • Never store sensitive exports on personal devices or personal cloud accounts.
  • Share only with people who need the information.
  • Report if you accidentally send sensitive data to the wrong person.

Handle Offboarding

When employees leave, review their recent exports and downloads, especially in the weeks before departure. Check mailbox forwarding and cloud sharing. Disable access promptly and collect devices. Exit procedures should include a reminder of data ownership obligations.

Reduce the Need for Exports

Often exports exist because built-in reporting is awkward. Invest in better standard reports, dashboards, or controlled business intelligence tools so that managers can see what they need inside governed systems. Fewer exports means less data to protect.

Consider Spreadsheet Hygiene

Spreadsheets themselves can hide risks, such as hidden sheets with sensitive data or links to other files. Before sharing externally, remove unnecessary tabs and metadata, or convert to PDF when editing is not needed.

Testing Your Controls

Pick a sensitive report and trace what happens after export. Where does the file go, who can open it, and is it logged? You may be surprised. Ironfield Cyber can help review report permissions, configure data protection in Microsoft 365, and set practical rules that protect payroll and job cost data without slowing finance down.