Skip to content

Field note / collaboration governance

Every tenant grows sharing links and guest accounts nobody remembers approving.

External sharing controls, Teams guest access, SharePoint site sprawl, and retention housekeeping get lumped into "Microsoft 365 administration" more often than they get an actual owner. Pulled out as their own lane, they become a reviewable, qualifiable piece of work instead of a vague promise.

Four places sprawl actually hides

Name the area before naming the fix.

See the general Microsoft 365 fulfilment lane this extends →

External sharing

Links nobody reviewed since creation

Files or folders shared outside the organization, anonymous access grants, and guest permissions nobody has reviewed since they were created.

Teams guest access

Guests who outlived the project

External participants added to a channel or team for one project, still present long after it ended.

SharePoint site sprawl

Sites nobody owns anymore

Sites created for a single initiative that outlived its purpose, with ownership nobody can name today.

Retention and housekeeping

Defaults nobody revisited

Default retention settings left unreviewed, and mailbox or site content nobody has decided whether to keep.

Boundary table

How a governance review differs from routine administration.

QuestionWhy the public bands cannot answer itWhere it gets answered
What does a governance review actually check?Scope depends on which of the four areas above the client wants reviewed and how large the tenant already is.Named explicitly in the service boundary record.
Does this change existing sharing without approval?Removing access or changing a retention default can break something a client still depends on.Findings are reported for approval before anything changes, same as a baseline finding.
How is this different from general M365 administration?General administration covers day-to-day tasks; this lane is a periodic structural review of sharing, guest access, and site sprawl specifically.Scoped as its own recurring or one-time review, named in the agreement.
Does this cover retention for legal or regulatory reasons?Retention settings are a technical configuration; whether a specific retention period satisfies a legal obligation is a separate question.See the Law 25 and PIPEDA compliance-context page for that boundary.

A representative review pattern

Nothing changes until a decision owner approves it.

  1. Inventory what exists - external shares, guest accounts, and sites older than an agreed threshold.
  2. Flag what looks unowned - access or content nobody can attribute to a current owner.
  3. Report findings for a decision - nothing is removed or changed without the client's or partner's approval.
  4. Apply approved changes - access is revoked or retention is adjusted only against a named decision.
  5. Record what changed - an audit-style record the partner can point to if a client asks what happened.

This is a process description, not a claim about a specific tenant's current sprawl.

What not to promise yet

A review is a snapshot, not a permanent state.

  • A one-time cleanup that stays clean without a recurring review
  • Removal of access without a named approver
  • A guarantee that sprawl cannot recur between reviews
  • Legal sign-off on a retention period
  • Coverage of a tenant nobody has actually inventoried yet

This lane assumes Microsoft 365 - see what changes on Google Workspace →

Related decision

Governance findings and baseline findings travel the same path.

Both are written down with a decision owner attached - never actioned silently.

Review the security baseline lane

Bring one tenant question - not a full sharing export.

Naming one area of concern (external sharing, guest access, or site sprawl) is enough for an initial fit review.

Discuss a governance review