SharePoint Governance and Information Architecture Review
A fixed-price, read-only assessment of your SharePoint Online estate: we map every site, hub, and permission structure against how your business actually works, quantify sprawl, oversharing, and information-architecture debt with evidence, and hand you three artifacts — a target information architecture, a governance policy pack, and a prioritized remediation backlog with effort estimates. Nothing changes during the review; remediation is implemented under separate scope, by us or by your team. $2,450 fixed, 2 weeks, and you pay after you approve delivery.
What this engagement is
Every SharePoint tenant that has grown organically for five years looks the same from the inside: sites nobody owns, permissions broken by years of one-off shares, external sharing links that outlived the projects they were created for, and a site structure that mirrors an org chart from two reorganizations ago. Day to day, people route around it — they search, ask a colleague, or recreate the file. Then something makes the debt visible all at once. For more and more organizations, that something is Microsoft 365 Copilot: it grounds its answers in everything a user can technically reach, so twelve years of quiet oversharing turns into a salary spreadsheet summarized in a chat window. We wrote up the mechanics of that failure in our analysis of Copilot oversharing — this service is the consulting engagement behind it. The review is evidence, not opinion. We inventory the estate — sites, hubs, Microsoft 365 group connections, storage, and activity — and map it against your business structure. We analyze permissions and sharing: inheritance breaks, 'Everyone except external users' exposure, sharing-link accumulation, external access per site, and ownerless sites with no accountable human. We assess the information architecture itself: navigation, hub topology, site purpose overlap, and the naming chaos that makes search and Copilot grounding worse than they should be. Where your licensing includes SharePoint Advanced Management (included with Microsoft 365 Copilot licenses), we use its data access governance reports as an additional signal source. Everything is done read-only under time-bound access you approve — no settings change, no files open, no user notices the review happened. What you get is designed to be acted on. The findings report ranks issues by actual exposure, not by count. The target information architecture proposes a structure that matches how you work today — the same discipline we describe in how law firms should structure SharePoint, applied to your industry. The governance policy pack covers site provisioning, ownership, sharing defaults, and lifecycle rules, written to be adopted rather than admired. And the remediation backlog sequences the fixes with effort estimates, so you can execute with your own team, hand items to us as fixed-price or T&M follow-ons — for example Teams lifecycle cleanup or Purview-based protection for Copilot — or split the work. One boundary, stated plainly: this engagement changes nothing in your tenant. That separation is deliberate — an assessor with an implementation quota finds what the quota needs; ours finds what is there.
Success criteria
What you receive
How the work unfolds
Scope confirmation, business-structure briefing, and read-only access established under granular, time-bound GDAP that you approve. Half a day of your time, total.
Automated collection across sites, hubs, groups, permissions, sharing links, external access, and activity — read-only throughout, with SharePoint Advanced Management reports used where your licensing includes them.
Permissions and sharing analysis, IA mapping against your business structure, ownerless and inactive site identification, and the Copilot-readiness read.
Target IA, governance policy pack, and the remediation backlog — drafted, internally reviewed, and sequenced by risk and effort.
Live walkthrough of the evidence and the roadmap with your team; artifacts handed over; follow-on scopes quoted only where you ask for them.
Prerequisites
Who does what
IT Partner
- Run the entire collection and analysis read-only, and confirm at closeout that no configuration was changed.
- Quantify sprawl, oversharing, and IA debt with evidence, ranked by real exposure.
- Deliver the target IA, governance policy pack, and prioritized remediation backlog.
- Present findings live and answer the hard questions, including 'what would Copilot see today?'
- Quote follow-on remediation only where you request it — the review stands on its own.
Your team
- Approve the read-only access request and name the IT contact.
- Give the business-structure briefing honestly — the assessment is only as good as the map of how you really work.
- Attend the findings session with the people who can decide.
- Decide the remediation path: your team, ours, or a split — there is no obligation in either direction.
- Adopt (or consciously adapt) the governance policy pack; policies only work if someone owns them.
What's not included
Limitations & technical notes
Frequently asked questions
What exactly do we get for $2,450?
Four artifacts and a working session: the estate inventory workbook, the findings report covering oversharing, sprawl, and IA debt ranked by exposure, the target information architecture with a governance policy pack, and a prioritized remediation backlog with effort estimates — presented live to your team. The price is fixed, the duration is two weeks, and you pay after you approve delivery.
Do you fix the problems you find?
Not inside this engagement, and that is deliberate. The review is read-only; remediation is implemented under separate scope — fixed-price or T&M — only if you choose to engage us for it. The backlog is written so your own team can execute it too. Keeping assessment and implementation commercially separate means the findings answer to the evidence, not to a sales target.
Why does this matter for Copilot specifically?
Copilot grounds its answers in whatever the signed-in user can technically access — every overshared site, every 'Everyone except external users' grant, every forgotten sharing link becomes source material. Permission sprawl that was invisible for years surfaces in the first week of a pilot. The review quantifies exactly that exposure before you switch Copilot on, and the Copilot-readiness read in the report tells you which findings must close first. It pairs with our Copilot Readiness Assessment, which covers the licensing, adoption, and security layers.
Is this the right first step before an intranet project?
If your estate has grown organically for years, yes. An intranet built on top of structural chaos inherits it — navigation fights the sprawl, search returns the same duplicates, and the new home site becomes one more site nobody governs. The target IA from this review becomes the skeleton the intranet project builds on. If your estate is young and small, skip straight to the intranet engagement; we will tell you which situation you are in after one conversation.
What access do you need, and can you change anything?
Read-only administrative access granted through GDAP — Microsoft's granular, time-bound partner access model that you approve, scoped to what the review needs and nothing more. We never request standing global admin. The engagement makes no configuration changes, and we confirm that at closeout. No user sees a prompt, a banner, or any disruption.
Do you read our documents?
No. The review works on configuration, permissions, sharing links, and metadata — site structures, who can access what, which links exist, what is stale. File contents are never opened. Where the question is what sensitive content exists inside files — credit cards, health data, client matter files — that is content classification, which is Purview's job and a separate engagement we will point to honestly if your findings warrant it.
Our tenant is huge. Does the fixed price really hold?
Yes, with an honest mechanic: the automated inventory covers every site no matter the count, and the analysis depth is prioritized by exposure — riskiest and most-shared corners first — with the prioritization agreed at kickoff. What the fixed price buys is the full picture plus deep analysis where it matters most. If your estate genuinely needs deep per-site analysis across thousands of sites, we will say so at kickoff and you decide whether to extend scope — before work begins, never as a surprise invoice.
What licensing do we need for the review?
Any Microsoft 365 plan with SharePoint Online. The review adapts its toolset to what you own: tenants with Microsoft 365 Copilot licenses get SharePoint Advanced Management's data access governance reports folded in as an extra signal source, and Purview-licensed tenants get their audit signals used. No add-on licenses are required to complete the review, and we never make you buy licensing to receive findings.
What is 'information architecture debt' in practice?
The gap between how your SharePoint is structured and how your business actually works. Symptoms: sites named after long-finished projects still collecting files, three sites doing one department's job, navigation nobody uses because it reflects a 2019 reorg, and no naming convention, so search returns four plausible 'HR Policies' locations. It is not cosmetic — it degrades search relevance and Copilot grounding, and it is why findability complaints persist after every storage cleanup.
How much of our team's time does the review consume?
About half a day total for most organizations: the access approval, a 60–90 minute business-structure briefing at kickoff, an IT contact reachable for access questions during collection, and the findings session at the end. The collection and analysis run on our side. It is designed to be the least disruptive way to get an honest picture of the estate.
We already have governance documents. Will you just tell us to rewrite them?
No — send them at kickoff and the policy pack builds on what you have. The interesting finding is usually the gap between the written policy and the tenant's actual configuration: the policy says external sharing is restricted, the settings say otherwise. We document those contradictions specifically, because closing them is cheaper than authoring a new binder nobody reads.
What happens after the review?
You own everything we deliver and decide the path. Execute the backlog with your own admins using the effort estimates; hand specific items to us as separately quoted fixed-price or T&M work — Teams cleanup, Purview implementation, restructuring, or an intranet build on the target IA; or do both in parallel. There is no bundled obligation and no expiring discount — the review is designed to stand alone.