First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/SharePoint Governance and Information Architecture Review
AssessmentConsulting

SharePoint Governance and Information Architecture Review

A fixed-price, read-only assessment of your SharePoint Online estate: we map every site, hub, and permission structure against how your business actually works, quantify sprawl, oversharing, and information-architecture debt with evidence, and hand you three artifacts — a target information architecture, a governance policy pack, and a prioritized remediation backlog with effort estimates. Nothing changes during the review; remediation is implemented under separate scope, by us or by your team. $2,450 fixed, 2 weeks, and you pay after you approve delivery.

Timeline 2 weeksService owner Roman SotnikSharePoint OnlineMicrosoft 365

What this engagement is

Every SharePoint tenant that has grown organically for five years looks the same from the inside: sites nobody owns, permissions broken by years of one-off shares, external sharing links that outlived the projects they were created for, and a site structure that mirrors an org chart from two reorganizations ago. Day to day, people route around it — they search, ask a colleague, or recreate the file. Then something makes the debt visible all at once. For more and more organizations, that something is Microsoft 365 Copilot: it grounds its answers in everything a user can technically reach, so twelve years of quiet oversharing turns into a salary spreadsheet summarized in a chat window. We wrote up the mechanics of that failure in our analysis of Copilot oversharing — this service is the consulting engagement behind it. The review is evidence, not opinion. We inventory the estate — sites, hubs, Microsoft 365 group connections, storage, and activity — and map it against your business structure. We analyze permissions and sharing: inheritance breaks, 'Everyone except external users' exposure, sharing-link accumulation, external access per site, and ownerless sites with no accountable human. We assess the information architecture itself: navigation, hub topology, site purpose overlap, and the naming chaos that makes search and Copilot grounding worse than they should be. Where your licensing includes SharePoint Advanced Management (included with Microsoft 365 Copilot licenses), we use its data access governance reports as an additional signal source. Everything is done read-only under time-bound access you approve — no settings change, no files open, no user notices the review happened. What you get is designed to be acted on. The findings report ranks issues by actual exposure, not by count. The target information architecture proposes a structure that matches how you work today — the same discipline we describe in how law firms should structure SharePoint, applied to your industry. The governance policy pack covers site provisioning, ownership, sharing defaults, and lifecycle rules, written to be adopted rather than admired. And the remediation backlog sequences the fixes with effort estimates, so you can execute with your own team, hand items to us as fixed-price or T&M follow-ons — for example Teams lifecycle cleanup or Purview-based protection for Copilot — or split the work. One boundary, stated plainly: this engagement changes nothing in your tenant. That separation is deliberate — an assessor with an implementation quota finds what the quota needs; ours finds what is there.

Success criteria

01Every site in the tenant is inventoried with ownership, activity, storage, sharing posture, and hub association — no sampling for the inventory layer.
02Oversharing exposure is quantified with evidence: which sites, which links, which broad-access grants, and who can reach what they should not.
03Ownerless and inactive sites are identified with counts and lists your admins can act on directly.
04The current information architecture is mapped and its gaps against your business structure are documented.
05The target IA is delivered and walked through with your stakeholders — structure, hubs, navigation, and naming standards.
06The governance policy pack is delivered: provisioning, ownership, sharing, external access, and lifecycle policies ready for your adoption.
07The remediation backlog is prioritized by risk and effort, with each item scoped tightly enough to be executed or quoted.
08Findings are presented live to your team, with the questions answered — not a PDF lobbed over a wall.

What you receive

Estate inventory workbook: every site with owner, activity, storage, group connection, hub membership, and sharing configuration.
Oversharing and permissions findings: broken inheritance, broad-access grants, sharing-link exposure, external sharing per site, and ownerless sites — ranked by exposure.
Information architecture assessment: current topology, purpose overlaps, navigation and naming findings, and search-impact notes.
Copilot-readiness read: which findings would surface in Copilot grounding and which must close before a responsible rollout.
Target information architecture: proposed hub and site structure, navigation model, and naming standards mapped to your business structure.
Governance policy pack: site provisioning and ownership policy, sharing and external-access defaults, and lifecycle rules — written for adoption.
Prioritized remediation backlog with effort estimates and a suggested sequence, each item executable by your team or quotable by ours.
Findings presentation: a working session with your IT and stakeholders to walk the evidence and agree next steps.

How the work unfolds

1. Kickoff and access

Scope confirmation, business-structure briefing, and read-only access established under granular, time-bound GDAP that you approve. Half a day of your time, total.

2. Estate inventory and data collection

Automated collection across sites, hubs, groups, permissions, sharing links, external access, and activity — read-only throughout, with SharePoint Advanced Management reports used where your licensing includes them.

3. Analysis

Permissions and sharing analysis, IA mapping against your business structure, ownerless and inactive site identification, and the Copilot-readiness read.

4. Design

Target IA, governance policy pack, and the remediation backlog — drafted, internally reviewed, and sequenced by risk and effort.

5. Findings session and handoff

Live walkthrough of the evidence and the roadmap with your team; artifacts handed over; follow-on scopes quoted only where you ask for them.

Prerequisites

A Microsoft 365 tenant with SharePoint Online in use — any licensing plan; deeper signal sources are used where your plan includes them.
Approval of a granular, time-bound, read-only GDAP access request — never standing global admin.
A 60–90 minute business-structure briefing: how your organization is actually divided, so the IA assessment measures against reality rather than the org chart.
A named contact in IT for access questions during collection.
Stakeholder availability for the findings session in week two.
Optional but valuable: your existing governance documents, if any exist, so the policy pack builds on what you have rather than ignoring it.

Who does what

IT Partner

  • Run the entire collection and analysis read-only, and confirm at closeout that no configuration was changed.
  • Quantify sprawl, oversharing, and IA debt with evidence, ranked by real exposure.
  • Deliver the target IA, governance policy pack, and prioritized remediation backlog.
  • Present findings live and answer the hard questions, including 'what would Copilot see today?'
  • Quote follow-on remediation only where you request it — the review stands on its own.

Your team

  • Approve the read-only access request and name the IT contact.
  • Give the business-structure briefing honestly — the assessment is only as good as the map of how you really work.
  • Attend the findings session with the people who can decide.
  • Decide the remediation path: your team, ours, or a split — there is no obligation in either direction.
  • Adopt (or consciously adapt) the governance policy pack; policies only work if someone owns them.

What's not included

Executing any remediation — permission fixes, site restructuring, sharing-link cleanup, and migrations are implemented under separate scope, fixed-price or T&M, only if you choose to engage us for them.
Microsoft Purview implementation — sensitivity labels, DLP, and auto-labeling are our Purview Data Governance for Copilot engagement; this review tells you whether and where you need it.
Teams lifecycle policy implementation — naming, expiration, and ownerless-team cleanup are the Microsoft Teams Governance and Sprawl Cleanup service; this review's findings feed it directly.
Intranet design and build — that is SharePoint Online Intranet Design and Deployment; run this review first if your estate is the reason the intranet keeps stalling.
Storage-cost analysis at file and version level — our SharePoint Storage Optimization assessment covers that, free for clients.
A full Copilot readiness program across licensing, adoption, and security — that is the Microsoft 365 Copilot Readiness Assessment; this review is the deep SharePoint layer of that picture.
Legal or regulatory compliance certification — we document where your configuration contradicts your stated policies; the compliance determination belongs to your counsel or auditor.

Limitations & technical notes

!The fixed price covers one Microsoft 365 tenant. The inventory layer covers every site regardless of estate size; the depth of per-site analysis is prioritized by exposure and agreed at kickoff, so a 4,000-site estate gets its riskiest corners examined first rather than a shallow pass over everything.
!This is a point-in-time assessment. Sharing links and permissions change daily; the governance policy pack is what keeps the picture from degrading again after remediation.
!Signal depth follows your licensing. SharePoint Advanced Management reports (included with Microsoft 365 Copilot licenses) and Purview signals are used where present; where they are not, collection relies on SharePoint admin reporting and PowerShell/Graph inventory — the findings stand either way, with the toolset noted in the report.
!We read configuration, permissions, and metadata — not the contents of your documents. Where content-level classification is the question, that is Purview territory and we will say so rather than guess.
!Remediation effort estimates in the backlog are planning-grade; any item you ask us to execute gets a firm written quote under its own scope before work begins.
!The review reports what the evidence shows. If the estate is healthier than you feared, the report will say that too — we do not manufacture findings to sell remediation.

Frequently asked questions

What exactly do we get for $2,450?

Four artifacts and a working session: the estate inventory workbook, the findings report covering oversharing, sprawl, and IA debt ranked by exposure, the target information architecture with a governance policy pack, and a prioritized remediation backlog with effort estimates — presented live to your team. The price is fixed, the duration is two weeks, and you pay after you approve delivery.

Do you fix the problems you find?

Not inside this engagement, and that is deliberate. The review is read-only; remediation is implemented under separate scope — fixed-price or T&M — only if you choose to engage us for it. The backlog is written so your own team can execute it too. Keeping assessment and implementation commercially separate means the findings answer to the evidence, not to a sales target.

Why does this matter for Copilot specifically?

Copilot grounds its answers in whatever the signed-in user can technically access — every overshared site, every 'Everyone except external users' grant, every forgotten sharing link becomes source material. Permission sprawl that was invisible for years surfaces in the first week of a pilot. The review quantifies exactly that exposure before you switch Copilot on, and the Copilot-readiness read in the report tells you which findings must close first. It pairs with our Copilot Readiness Assessment, which covers the licensing, adoption, and security layers.

Is this the right first step before an intranet project?

If your estate has grown organically for years, yes. An intranet built on top of structural chaos inherits it — navigation fights the sprawl, search returns the same duplicates, and the new home site becomes one more site nobody governs. The target IA from this review becomes the skeleton the intranet project builds on. If your estate is young and small, skip straight to the intranet engagement; we will tell you which situation you are in after one conversation.

What access do you need, and can you change anything?

Read-only administrative access granted through GDAP — Microsoft's granular, time-bound partner access model that you approve, scoped to what the review needs and nothing more. We never request standing global admin. The engagement makes no configuration changes, and we confirm that at closeout. No user sees a prompt, a banner, or any disruption.

Do you read our documents?

No. The review works on configuration, permissions, sharing links, and metadata — site structures, who can access what, which links exist, what is stale. File contents are never opened. Where the question is what sensitive content exists inside files — credit cards, health data, client matter files — that is content classification, which is Purview's job and a separate engagement we will point to honestly if your findings warrant it.

Our tenant is huge. Does the fixed price really hold?

Yes, with an honest mechanic: the automated inventory covers every site no matter the count, and the analysis depth is prioritized by exposure — riskiest and most-shared corners first — with the prioritization agreed at kickoff. What the fixed price buys is the full picture plus deep analysis where it matters most. If your estate genuinely needs deep per-site analysis across thousands of sites, we will say so at kickoff and you decide whether to extend scope — before work begins, never as a surprise invoice.

What licensing do we need for the review?

Any Microsoft 365 plan with SharePoint Online. The review adapts its toolset to what you own: tenants with Microsoft 365 Copilot licenses get SharePoint Advanced Management's data access governance reports folded in as an extra signal source, and Purview-licensed tenants get their audit signals used. No add-on licenses are required to complete the review, and we never make you buy licensing to receive findings.

What is 'information architecture debt' in practice?

The gap between how your SharePoint is structured and how your business actually works. Symptoms: sites named after long-finished projects still collecting files, three sites doing one department's job, navigation nobody uses because it reflects a 2019 reorg, and no naming convention, so search returns four plausible 'HR Policies' locations. It is not cosmetic — it degrades search relevance and Copilot grounding, and it is why findability complaints persist after every storage cleanup.

How much of our team's time does the review consume?

About half a day total for most organizations: the access approval, a 60–90 minute business-structure briefing at kickoff, an IT contact reachable for access questions during collection, and the findings session at the end. The collection and analysis run on our side. It is designed to be the least disruptive way to get an honest picture of the estate.

We already have governance documents. Will you just tell us to rewrite them?

No — send them at kickoff and the policy pack builds on what you have. The interesting finding is usually the gap between the written policy and the tenant's actual configuration: the policy says external sharing is restricted, the settings say otherwise. We document those contradictions specifically, because closing them is cheaper than authoring a new binder nobody reads.

What happens after the review?

You own everything we deliver and decide the path. Execute the backlog with your own admins using the effort estimates; hand specific items to us as separately quoted fixed-price or T&M work — Teams cleanup, Purview implementation, restructuring, or an intranet build on the target IA; or do both in parallel. There is no bundled obligation and no expiring discount — the review is designed to stand alone.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$2,450 per project
2 weeks
Book the governance review