App Garden

Calculation Sign-Off and Lock

Excel will not tell you the calculation changed after it was checked.

Sign off a calculation, lock it, and let anyone prove later that the logic is the one you signed. Three buttons: Check, Sign & lock, Verify. Verifying is free for everyone, forever.

What actually happens today

Somebody builds a calculation. Somebody else checks it. The checked version is printed, signed, dated and filed. Then the file carries on being used — and nothing about the printout says anything about the file. A formula edited a fortnight later leaves no mark, and the signature in the quality file goes on looking exactly as authoritative as it did.

The usual answer is sheet protection. That stops the accidental overwrite and nothing else. The other usual answer is a change log everyone forgets to fill in.

What this does

1. Check

Before you can sign, the pane shows you what is in the calculation: values typed over formulas, hardcoded rates buried inside formulas, #REF! errors, references to workbooks that are not being signed, and calculation cells left unprotected. You can sign anyway — it is your judgement — but you cannot sign without having seen them, and what the checks found is written onto the record.

2. Sign & lock

Records who, which role, the date, the revision, and a fingerprint of the calculation logic. Protects every cell except the ones you have marked as inputs. Writes a printable Sign-off sheet for your quality file.

The record lives inside the workbook, so it survives being saved, copied and emailed. On Pro it is also countersigned by App Garden, which means the record itself cannot be edited afterwards — change the name, the date or the revision and the countersignature stops verifying.

3. Verify

Anyone opens the file and presses Verify. Green: logic unchanged since J. Smith, Checked, 10 September 2026, Rev B. Red: 14 changes to the calculation since it was signed — with the cells listed, and what each one used to say.

Verify is free, for anyone, forever. No licence key, no account, no network. If somebody sends you a signed workbook, you install the add-in and check it, and you are never asked for a card.

Three fingerprints, not one

A calculation template is signed once and used many times, so typing a number into it must not turn the record red. It does not:

Formulas are fingerprinted in R1C1, so inserting a row above the calculation is not read as rewriting every formula below it. Number formats, column widths, comments and calculation mode are deliberately not in the fingerprint, and the pane says so.

The lock is convenience. The fingerprint is the control.

Excel's sheet protection is trivially removed — the password is a weak hash and every free tool on the internet will strip it in seconds. Anybody telling you otherwise is selling you something.

So this add-in does not claim to prevent changes. It claims to detect them. Protection stops the accidental overwrite; the fingerprint catches the deliberate one, and it catches it whether the sheet was protected or not.

This is not Part 11 software, and does not pretend to be

Calculation Sign-Off and Lock is a sign-off record and tamper evidence. It is not a 21 CFR Part 11 or EU Annex 11 electronic signature: there is no per-user access control and no full audit trail, and the signer's name is typed rather than verified.

If you are in a regulated GxP environment, you want ExcelSafe or something like it, and it will cost you roughly four thousand dollars. This is for everyone below that line — ISO 9001 engineering calculation checking, finance model sign-off, non-GxP labs, consultancy deliverables — where the current control is a printout, a biro and hope.

Your workbook never leaves your machine

Everything is computed inside Excel. When you countersign, the add-in sends three things and nothing else: your licence key, an anonymous install id, and the record hash — a 64-character one-way fingerprint that cannot be turned back into your workbook. No formula, no value, no sheet name, no file name.

Verifying makes no network request at all.

Price

£6 a month or £60 a year. The free tier verifies without limit and signs three local records a month. Records signed by a lapsed subscriber go on verifying forever — there is no code path that could stop them. Prices and checkout.

Getting started

  1. Install the add-in and open the pane from the Home tab.
  2. Select the cells people type into, and press Add the selected cells.
  3. Press Run pre-sign checks and read what comes back.
  4. Type your name, pick your role, press Sign this calculation.

The full guide.

Support

support@appgarden.co.uk. Replies are from a person, usually within a working day.