Skip to content
Pro IT NW

Identity / Sub-service 05

You already own the governance tools.
They are mostly switched off.

Microsoft Purview, sensitivity labels, DLP and retention are sitting in a licence most mid-market tenants already pay for and have never configured. We design the classification scheme, turn the controls on, and clean up the SharePoint permissions underneath — senior-led and vendor-neutral, so if the answer is 'use what you own', that is what we will tell you.

Service detail

Microsoft data governance, done as engineering rather than as a policy document

Governance fails when it ships as a PDF nobody enforces. The deliverable here is a configured tenant — labels published, DLP policies live and tuned, retention applied, permissions cleaned — plus the written scheme behind it so your team can maintain it after we leave.

What we do

  • Data inventory — where sensitive content actually lives across SharePoint, OneDrive, Exchange and Teams
  • Sensitivity labels — a taxonomy sized to how your business really handles documents, then published
  • Microsoft Purview DLP — policies that stop the damaging flows without alert fatigue
  • Retention and lifecycle — what to keep, what to let go, and defensible disposal
  • SharePoint governance — site creation, sharing rules, guest lifecycle, and permissions that stay clean
  • Audit, eDiscovery and reporting — configured before someone urgently needs it

Where tenants usually are when they call

  • Purview is licensed and largely unconfigured — capability already paid for, not switched on
  • Labels exist but nobody applies them, because the taxonomy was designed for an org chart
  • DLP is either off, or so noisy the alerts are ignored — which is functionally the same thing
  • Sharing links and guest accounts have accumulated for years with no review
  • A Copilot rollout, an insurance questionnaire, or an auditor turned a slow problem into a deadline

How we work

  • Senior-led — you get the engineer who does the work, for the whole engagement
  • Vendor-neutral — no resale, no partner-tier incentives steering the recommendation
  • Fixed-fee against a written scope, agreed before you commit
  • Assessment first — you can act on the findings yourself, and some clients do
  • USA-wide delivery from Seattle

FAQ

Common questions about Microsoft Purview and data governance.

What does a Microsoft data governance consultant actually do?

For a Microsoft-stack organisation, data governance work is mostly four things: knowing where sensitive data lives, classifying it so tools can act on that classification, controlling where it can go, and being able to prove all three later. In practice that means a data inventory across SharePoint, OneDrive, Exchange and Teams; a sensitivity-label taxonomy in Microsoft Purview that people will actually apply; DLP policies that block the genuinely damaging flows without generating alerts everyone learns to ignore; retention that satisfies both the legal team and the storage bill; and audit and eDiscovery configured before anyone needs them. The consulting part is not clicking through Purview — it is deciding what your classification scheme should be, which is a business question with a technical implementation.

What are sensitivity labels and how many should we have?

Sensitivity labels are Microsoft Purview's classification layer. A label tags content as Confidential, Internal, Public and so on, and can carry enforcement with it — encryption, watermarks, access restrictions that travel with the file even outside your tenant. On how many: fewer than you think. Three or four labels people apply consistently are worth more than twelve that produce a wall of dropdown options nobody reads. Most failed label rollouts fail on taxonomy, not technology — the scheme mirrors an org chart instead of mirroring how content is actually handled, and users default to whatever is first in the list. We design the taxonomy against your real document flows, publish a small set, then extend once the habit exists.

Is Microsoft Purview enough on its own, or do we need a third-party tool?

For most mid-market organisations already licensed for Microsoft 365 E5 or the compliance add-ons, Purview is enough and the honest answer is that you are probably paying for capability you have not turned on. Third-party governance tooling earns its place when you need cross-cloud coverage Purview does not reach, permissions reporting at a scale and granularity Purview reports awkwardly, or automated remediation at volume. We are vendor-neutral — no resale, no partner-tier incentive — so if the answer is 'use what you own', that is what we will tell you, and it is the cheaper recommendation for us to make.

What is SharePoint governance, and where do most tenants get it wrong?

SharePoint governance is the set of rules and controls determining who can create sites, who can share what with whom, what happens to a site when its project ends, and how any of that is enforced rather than merely documented. Where tenants get it wrong is almost never malice — it is years of people solving a Friday-afternoon problem with an 'Anyone in the company' link, plus site sprawl from self-service creation with no lifecycle. The result is thousands of shares nobody has looked at since, broken inheritance nobody meant to create, and guest accounts belonging to people who left. That is survivable right up until you point Copilot at it.

How do you scope and price this work?

Fixed fee against a written scope, senior-led, with the scope agreed before you commit. Governance work sizes on tenant complexity rather than headcount — the number of sites, how much content sits outside managed locations, how many regulatory obligations are in play, and whether there is an existing classification scheme to extend or a blank sheet. Most engagements start with an assessment that produces the inventory and the recommended taxonomy, then a scoped implementation. You can stop after the assessment and hand it to your own team, which some clients do.

Do we need this if we are not turning on Copilot?

Copilot makes governance urgent; it does not make it necessary. The reasons that existed before Copilot still apply — a departing employee with a decade of access, a guest account that outlived its project, a regulator or insurer asking where regulated data sits and who can reach it, or an eDiscovery request that needs answering in days. Copilot simply converts a quiet, tolerable risk into a fast, visible one. If Copilot is not on your roadmap, the work is the same work on a calmer timeline.

Related

Find out what your tenant is actually exposing.

Tell us your tenant size and which compliance obligations are in play. Two-business-day response with scope and timing.