Microsoft Purview Records Management Implementation
Microsoft Purview Records Management Implementation turns the retention schedule your organization already has on paper — legal, regulatory and operational — into a records program that Microsoft 365 actually enforces. In three weeks IT Partner converts that schedule into a Purview file plan (record classes with reference IDs, business functions, authority types and citations), builds the retention labels that declare records and — only where you decide a regulation demands it — regulatory records, applies them manually, automatically (sensitive information types, keywords, trainable classifiers) and on events such as a contract ending or an employee leaving, across SharePoint, OneDrive, Exchange and Teams; sets up multi-stage disposition review with your named reviewers; documents the proof-of-disposition export; shows you where Purview Audit holds the evidence a regulator or auditor asks for; and hands over a one-page records policy statement your organization can adopt. $4,950 fixed, quoted in writing before work begins, for one file plan of up to about 25 record classes — larger schedules are quoted. We are Microsoft 365 engineers, not a law firm: your counsel decides what a record is and how long it must be kept; we make the tenant enforce that decision and evidence it.
What this engagement is
Most organizations that come to us for this already own a retention schedule — a spreadsheet from counsel, a state or sector records schedule, a contract clause, a board policy that says 'contracts: seven years after expiry; personnel files: seven years after separation; project files: destroy three years after closure'. What they do not have is anything in Microsoft 365 that knows those rules exist. Documents sit in SharePoint libraries and OneDrive folders with no classification, mailboxes keep everything or nothing, Teams channels accumulate the records nobody declared, and 'delete' is a right-click away from any user. The classic SharePoint Records Center and in-place records management that older intranets relied on have given way to Microsoft Purview retention labels, and the question we hear most — 'how do we declare records in SharePoint now?' — has a precise answer: a file plan in the Records Management solution of the Microsoft Purview portal, and labels that travel with the item wherever it lives. The pressure is sharper now because of Microsoft 365 Copilot: what you keep is what Copilot can surface, so knowing what to retain and what to dispose of has become an AI-readiness question as much as a compliance one. Purview draws a line that matters, and this service sits on one side of it. Data lifecycle management — retention policies and ordinary retention labels — is hygiene: keep for so many years, then delete, applied broadly. Records management is declaration. A retention label that marks an item as a record blocks deletion and, when the record is locked, blocks content edits, while still allowing metadata changes and, in SharePoint, a controlled unlock-edit-relock through record versioning. A regulatory record label goes further: once applied, nobody — including a global administrator — can remove the label or delete the item before its retention period ends; the label itself cannot be deleted from the tenant; and the only permitted changes are extending the period or publishing it to more locations. Microsoft hides that option behind a PowerShell switch (Set-RegulatoryComplianceUI) precisely because it is irreversible, and we will not enable it without a written go/no-go from you. Around those labels sit the working parts of a records program: the file plan with its descriptors — reference ID, business function or department, category and sub-category, authority type, and the provision or citation that justifies each period — so an auditor can trace every label to a rule; auto-apply policies that label content by sensitive information type, keyword or searchable property, trainable classifier, or cloud-attachment sharing, and take up to seven days to reach existing content; event-based retention, where the clock starts when a contract ends or an employee leaves rather than when a file was created, raised in the portal or from your HR and contract systems through the Microsoft Graph records management API; static or adaptive scopes that decide where labels are published; disposition review in up to five stages with named reviewers or mail-enabled security groups, auto-approval windows, and the options to dispose, extend, relabel or add a reviewer; a disposed-items record Microsoft keeps for up to seven years as proof of disposition; and Purview Audit entries for every label applied, changed or removed and every disposition decision. The engagement runs in three weeks and starts with your schedule, not a template. Week one is the schedule-to-file-plan workshop: we read your retention schedule with the people who own it, group it into record classes (about 25 fit inside the fixed price), decide per class between an ordinary retention label, a record label and — rarely, and only where a regulation demands it — a regulatory record label, choose the retention trigger (created, modified, labelled, or an event), and decide which classes need a disposition review and who reviews. We verify that your licensing includes records management before building anything. Week two builds it: the file plan imported from a spreadsheet with the multi-stage disposition settings added in the portal afterwards (the import supports a single stage), labels published through static or adaptive scopes, auto-apply rules run against your pilot sites, event types defined, reviewer role groups created, and a pilot on the sites and mailboxes we agreed at kickoff so you see labels land before they go tenant-wide. Week three is disposition, evidence and handover: a first disposition review walked through end to end, the proof-of-disposition export procedure documented, the audit evidence searches written down, regulatory records enabled only if you signed the go/no-go, a one-page records policy statement drafted for your counsel to adopt, and your administrators trained to run the program without us. The boundaries are deliberate. Retention periods and the legal question of what is a record are your counsel's — we convert decisions into configuration and evidence them; we do not make them. Broad keep-or-delete hygiene across the tenant belongs to Microsoft Purview Data Lifecycle Management Implementation; the single regulated use case of SEC 17a-4 and FINRA books and records, with Preservation Lock and supervision, is FINRA and SEC 17a-4 Compliance for Microsoft 365; finding and producing content for a matter is Microsoft Purview eDiscovery Premium Implementation or Microsoft Purview eDiscovery Search Assistance; and governing what Copilot may surface from the content you keep is Microsoft Purview Data Governance for Microsoft 365 Copilot. Keeping the evidence current month after month is the Compliance Evidence and Audit Readiness Retainer.
Success criteria
What you receive
How the work unfolds
Kickoff with the schedule owner, the compliance or legal lead and IT; licensing verification; current-state review of retention policies, labels, holds and legacy records settings; the workshop that groups your schedule into record classes and decides label type, trigger, disposition behaviour and reviewers per class; file plan spreadsheet drafted, reviewed and signed.
File plan imported and descriptors set; multi-stage disposition added in the portal; label policies published through static or adaptive scopes to the pilot locations; auto-apply policies and event types configured; role groups and reviewers created; pilot run on the agreed sites and mailboxes with blocked-action tests; findings reviewed with you before anything goes tenant-wide.
Written go/no-go and, if signed, regulatory records enabled and applied to the classes the plan names; labels published to the full agreed scope; first disposition review run end to end with your reviewers; proof-of-disposition export and audit searches performed and documented; one-page records policy statement drafted; runbook delivered; administrator handover session; any temporary access removed.
Prerequisites
Who does what
IT Partner
- Facilitate the schedule-to-file-plan workshop and produce the signed file plan.
- Verify licensing and document current state before building anything.
- Build the file plan, labels, scopes, auto-apply rules, event types and disposition configuration to the signed plan, and pilot them before tenant-wide publication.
- Run the go/no-go and enable regulatory records only on written approval, never outside the signed file plan.
- Run the first disposition cycle with your reviewers and document the proof-of-disposition and audit procedures.
- Draft the one-page records policy statement and the runbook, deliver the handover, and remove any temporary access.
Your team
- Own every determination of what is a record, which citation applies and how long it is kept; supply the schedule and sign the file plan.
- Provide access, the location inventory, reviewer names and stakeholder time on the agreed schedule.
- Sign the regulatory-records go/no-go and acknowledge irreversibility in writing — or decline it, which is a perfectly good outcome.
- Staff the disposition reviews and keep reviewer assignments current as people change roles.
- Adopt the records policy statement with counsel's review, and maintain the file plan after handover or contract that separately.
- Buy any licensing the verification shows you lack, at Microsoft's list price.
What's not included
Limitations & technical notes
Frequently asked questions
What is the difference between this and Purview Data Lifecycle Management?
Data lifecycle management is retention hygiene: retention policies and ordinary retention labels that keep content for a period and then delete it, applied broadly so the tenant stops hoarding. Records management is declaration: a file plan that ties each record class to a citation, labels that make an item a record (deletion blocked, edits controlled) or a regulatory record (nothing can be undone), retention that starts on an event, a reviewed disposition rather than a silent deletion, proof of that disposition, and an audit trail. Most organizations need both; they are different work with different owners, which is why the hygiene programme is its own service — Microsoft Purview Data Lifecycle Management Implementation — and this one builds the records program on top of it.
What is a file plan, and why do you insist on citations?
The file plan is the Records Management view of your retention labels with descriptors attached to each: a reference ID, the business function or department that owns the class, category and sub-category, the authority type (a law, a regulation, a contract, an internal policy) and the provision or citation that sets the period. We insist on the citation because it is what an auditor traces: 'why is this kept seven years?' is answered by the label itself, not by whoever remembers. It also disciplines the workshop — a class nobody can cite is usually two classes, or none. The file plan is built in bulk from a spreadsheet and exported at the end as your baseline record.
What is the difference between a record and a regulatory record?
A record label blocks deletion for the retention period and, when the record is locked, blocks content edits; metadata can still be changed, users with the right permissions can change the label, and in SharePoint record versioning lets a record be unlocked, edited and relocked with the history kept. A regulatory record label removes every one of those escape hatches: once applied, nobody — not a global administrator, not Microsoft support — can remove the label, edit the item or delete it before the period ends, the label cannot be deleted from the tenant, and the only changes allowed to it are a longer period or more locations. Microsoft keeps the option hidden until an administrator enables it with PowerShell. In most file plans a handful of classes, if any, justify it.
Why do you require a written go/no-go before enabling regulatory records?
Because a scoping mistake with a regulatory record cannot be undone. A mis-applied auto-apply rule with an ordinary record label is an afternoon's correction; the same mistake with a regulatory label is content you will hold until the period expires, whatever it costs you in storage, discovery or embarrassment. So we build and pilot every class with ordinary record labels first, show you exactly which classes the signed file plan marks regulatory, put the irreversibility in writing, and enable the PowerShell switch and apply those labels only after you sign. Declining is a normal outcome — many records programs are complete without a single regulatory label.
How do we declare records in SharePoint today?
With a retention label that has 'mark items as a record' set, published to the site through a label policy. Users pick the label from the item's properties, a library or folder or document set can carry it as a default so everything inside is declared on arrival, and auto-apply policies can declare items by sensitive information type, keyword or trainable classifier. The classic Records Center site, in-place records management and the content organizer are not the way Microsoft builds this any more; the label travels with the item, which means a record in a Team's document library is as much a record as one in a dedicated site.
What is event-based retention and when would we use it?
Most retention periods in a real schedule do not start when a file is created — they start when a contract expires, an employee leaves, a project closes or a product is withdrawn. Event-based retention lets a label's clock start on that event: you define an event type, label items with an asset ID or keyword that ties them to a specific contract or person, and when the event is raised — in the Purview portal, or from an HR or contract system through the Microsoft Graph records management API — Purview synchronizes the date to the matching items, taking up to seven days. We define the event types your plan needs, document the asset-ID convention, and design the automation path; building the integration itself is quoted separately.
How does disposition review work, and who has to do it?
For any class you choose, the label sends items to a review at the end of their period instead of deleting them silently. Reviewers — individuals or mail-enabled security groups — are notified, see the item (which requires the Disposition Management role and the content-viewing permissions we assign), and choose to approve disposal, extend retention, apply a different label, or add another reviewer. Up to five stages can be chained so, for example, the records owner reviews first and legal signs off last; an auto-approval window of 7 to 365 days keeps items from stalling. We configure the stages you decide, run the first cycle with your reviewers, and leave them able to run every cycle after.
What is proof of disposition, and what will an auditor see?
When a record is disposed of through review, Purview keeps an entry in the disposed-items record — what it was, where it lived, who approved disposal, when, and any comment — for up to seven years, and the entries can be exported from the portal or, for large sets, by PowerShell. Alongside it, Purview Audit records who applied, changed or removed a label and who approved each disposition. We perform both exports with your team during the engagement and write the steps into the runbook, so an auditor's 'show me what you destroyed last year and who authorised it' is answered with a file, not a meeting.
Which licenses do we need?
Per Microsoft's licensing guidance at the time of writing, records and regulatory records, event-based retention, disposition review, auto-apply with trainable classifiers and adaptive scopes are covered by Microsoft 365 E5 (and A5/G5), Office 365 E5, the E5 Compliance add-on and the E5 Information Protection and Governance add-on; the Microsoft Purview Suite brings the compliance set to Business Premium and E3 tenants. Microsoft 365 E3 and Business Premium on their own give you retention policies and manual labels but not the records features. Week one verifies precisely what your subscriptions include and names any gap; buying a plan is your decision, and we will not recommend one your current licensing already covers.
How does this relate to Microsoft 365 Copilot?
Copilot answers from what your tenant keeps and what the user can reach. A records program settles the first half — what is retained, for how long, and what is disposed of on schedule — so Copilot is not confidently summarizing a superseded contract or a personnel file that should have been destroyed years ago. It does not settle the second half: who can reach what. That is permissions and sensitivity labelling, and it is the subject of Microsoft Purview Data Governance for Microsoft 365 Copilot. Organizations preparing for Copilot usually need both, in that order or the reverse depending on where the greater risk sits.
Will anything be deleted during the engagement?
Not by us, and not silently. Labels are published and auto-apply rules are piloted in ways that declare and retain; nothing is deleted until a retention period ends, and for any class with a disposition review nothing is deleted until your reviewers approve it. The first disposition cycle we run in week three is on items your reviewers judge, and every decision is theirs. If your schedule contains classes whose period has already expired for existing content, we show you what a review would present before any label that could trigger disposal is published.
How long does it take, and what does $4,950 cover?
Three weeks: schedule to file plan, build and pilot, disposition and handover. The fixed price covers one tenant and one file plan of up to about 25 record classes, licensing verification, the labels and scopes, auto-apply and event types, disposition review setup and a first cycle, the proof-of-disposition and audit procedures, the pilot, the one-page records policy statement, the runbook and the handover session — quoted in writing before work begins and, per our standard terms, paid after you approve delivery. Larger schedules, several entities, historical backfill and event integrations are priced in the quote, not discovered mid-project. Microsoft licensing is always separate.
We are a small organization on Business Premium. Is this for us?
It can be, with two honest caveats. Business Premium alone does not include the records features — you would add the Microsoft Purview Suite or an E5-level plan for the users in scope, and the licensing verification in week one is exactly where we confirm the cheapest route. And a records program is only worth building if someone will own it afterwards: run the reviews, keep the file plan current, raise the events. Where a small organization mainly needs to stop hoarding and delete on schedule, we will say that Data Lifecycle Management is the better first spend.
Can you automate events from our HR or contract system?
Yes, as a separately quoted piece of work once the program is live. Purview exposes event types and events through the Microsoft Graph records management API, so an employee's departure recorded in your HR system, or a contract's end date in your contract repository, can raise the retention event with the right asset ID without anyone opening the Purview portal. In this engagement we define the event types, fix the asset-ID convention and design the integration path; the flow or script itself is built afterwards so it is written against a file plan that has already settled.
What access do you need, and what happens to it afterwards?
Purview compliance roles for records management and disposition, plus SharePoint, Exchange and Teams administration where publishing labels needs it, granted for the three weeks and removed at handover. For organizations that buy their Microsoft licensing through IT Partner we normally work through the least-privilege delegated access already in place; otherwise a temporary role you grant and we ask you to revoke. We do not need, and do not ask for, standing global administrator rights — and enabling regulatory records is a single PowerShell command run only after your signed go/no-go.