A finance director asks for the signed supplier agreement from three years ago. Your team knows it exists, but it could be in a project site, a Teams channel, an email attachment or an old shared folder. That is the moment a SharePoint records management guide becomes useful. Good records management is not about making every document hard to edit. It is about making the records that matter easy to find, protected for the right period and disposed of when that period ends.
For small and mid-sized organisations, SharePoint and Microsoft 365 can provide a sensible, proportionate records management approach without buying another document repository. The hard part is deciding what a record is, who owns it and what should happen to it over time.
What records management means in SharePoint
A document is simply a file or item someone has created or received. A record is a document that provides evidence of a business decision, transaction, commitment or obligation. Signed contracts, HR case files, approved policies, financial records and formal project decisions are common examples.
Not every working draft needs to be treated as a record. If it is, staff will either work around the process or create so much administrative overhead that nobody can maintain it. The aim is to apply control where the business, legal or regulatory risk justifies it.
SharePoint provides the storage location, permissions, version history, search and metadata. Microsoft Purview retention features provide the rules that say how long content is kept and whether it can be deleted, changed or reviewed for disposal. Together, they allow teams to manage records where people already work rather than asking them to copy files into a separate archive.
That said, SharePoint is not a substitute for deciding your policy. Technology can enforce a retention label. It cannot tell you whether invoices should be retained for six years, seven years or longer because of a particular contract, investigation or sector requirement. That decision needs input from finance, HR, operations and, where necessary, legal advisers.
Start with the records that create the greatest risk
Trying to classify every document across every site is usually where records programmes stall. Begin with a small number of categories that are clearly important and occur often enough to justify a consistent approach.
For many SMEs, the first set includes contracts and supplier agreements, employee records, finance and tax documentation, health and safety evidence, controlled policies, and customer or project records. Each category needs a named business owner. IT can configure the controls, but it should not be left to guess what constitutes an approved policy or when a project file is ready for disposal.
For each category, agree four practical decisions:
- What makes this item a record rather than a draft or routine working document?
- Where should staff create and store it?
- How long must it be retained, and what event starts that period?
- What should happen at the end: deletion, formal review or transfer to another controlled location?
A contract may need to be retained from its expiry date rather than from the date it was signed. An employee record may have different retention requirements depending on whether the individual is a current employee, leaver or candidate. These details are why a simple file plan is more useful than a generic statement that all content should be kept for a set number of years.
Design the SharePoint structure before applying labels
Retention labels work best when users have a clear place to save information. A common mistake is to build a central records library and expect every department to manually move finished documents into it. This can work for a narrow set of highly controlled files, but it often creates duplicate copies and breaks the connection between a record and the work around it.
In most cases, retain records in the relevant SharePoint site or document library. HR records belong in an access-controlled HR area. Procurement records should sit with procurement. Approved corporate policies may live in a central policy library that staff can read but only authorised owners can update.
Use separate libraries when access rules, content types or retention needs are materially different. Do not create a new site for every record category unless there is a genuine security reason. More sites mean more owners, more permission reviews and more places for staff to look.
Metadata should support retrieval and reporting, not become a form-filling exercise. A contracts library might use supplier name, contract type, start date, expiry date and contract owner. A policy library may need policy area, approval date, review date and document owner. If users cannot reliably choose a value, remove the field or make the process simpler.
Content types are particularly useful where a library contains several controlled record classes. They make the right metadata and retention label available for each type of item. For a straightforward library containing one type of record, a default label and a small number of columns may be enough.
Apply retention labels with care
A retention label is the core control for a managed record. It can retain content for a defined period, prevent deletion during that period and trigger a disposition review when the period ends. Depending on the rule, it can also mark the item as a record, which limits changes to the content and its metadata.
The choice between retaining, declaring as a record and locking down completely depends on the business process. A signed agreement should not be casually overwritten. A live policy, however, may need controlled revisions over time. In that case, version history, approval and permissions may do more of the work until a superseded version reaches the point at which it becomes a retained record.
Avoid applying blanket retention to every SharePoint site from day one. It sounds safe, but it can make clean-up difficult, increase storage costs and leave staff searching through outdated material. Start with labels for the record categories in your file plan, test them in a controlled site, then extend them once the process is understood.
For records where the retention clock starts from a known date, event-based retention can be appropriate. Contract expiry, employee departure or project closure are examples. It is more accurate than retaining everything from its creation date, but it relies on somebody or an automated process recording the event consistently. If that discipline is not in place, a simpler fixed-period rule may be safer initially.
Permissions, versions and retention solve different problems
These controls are often confused. Permissions decide who can see or edit content. Version history lets teams recover an earlier version after an error. Retention governs how long content must be kept and what can happen when that period ends.
A restricted library is not automatically a records archive. Equally, a retention label does not make a document confidential. For example, an HR library may require limited membership, carefully managed site owners and regular access reviews. The retention rule then ensures that the required files are not deleted too early, even by someone with ordinary edit rights.
Keep permissions group-based wherever possible. Granting individuals access one by one becomes difficult to audit and nearly impossible to maintain when people change roles. Site owners should understand that they are responsible for access decisions, not simply a convenient route for adding colleagues.
Build the process around normal work
The strongest records process is usually the least visible one. Staff should save a contract into the contracts library, select a small amount of meaningful information and follow a familiar approval route. They should not have to interpret a retention schedule every time they upload a file.
Use defaults where the library contains one record type. Use required metadata only where it is genuinely needed. Use document templates and approval processes for controlled documents such as policies. A simple Power Automate flow can notify an owner when a policy review date is approaching or prompt a contract owner to confirm an expiry date.
Before rolling out, test the process with real users and realistic scenarios. Ask them to find a current agreement, identify the approved version of a policy and save a new record correctly. If they need a page of instructions to complete routine work, the design needs further work.
Plan for disposal and legal holds
Keeping records forever is not a neutral option. It creates clutter, increases the volume of information that could be requested or exposed, and makes useful records harder to find. Disposal should therefore be an intentional part of the policy, not an afterthought.
For sensitive categories, configure disposition review so a responsible person can check records before they are deleted. They may confirm disposal, extend retention or identify an exception. This is particularly useful where a dispute, audit or ongoing commercial relationship means standard deletion is no longer appropriate.
A legal hold or investigation requirement takes priority over normal disposal. Your organisation should know who can request a hold, who approves it and how affected content is identified. This is a governance process as much as a Microsoft 365 setting.
A sensible rollout plan
A phased rollout reduces both risk and resistance. Start with one department and one or two record categories where the ownership and retention needs are clear. Configure the library, metadata, labels and permissions, then test retrieval and disposal before expanding.
Track practical measures: how long it takes to find a requested record, how many files are stored outside the agreed location, whether required metadata is complete and whether access reviews are happening. These measures reveal whether the process is working better than a document count ever will.
Records management does not need to turn SharePoint into a locked filing cabinet. Done properly, it gives people a clearer place to work, gives managers confidence that evidence is protected, and gives the business a credible answer when someone asks for a document that should be there.