Purview labels as records discipline on the tenant you already license

Organizations that run Microsoft 365 E5 or G5 already hold Microsoft Purview's advanced records and labeling capabilities. Many use a small part of them. When a governance project finally starts, it often begins in the admin portal: create a retention policy, publish a few labels, call it done.

The portal is the easy part. The tools implement a decision. They do not make it. Someone still has to decide what the organization keeps, how long, what happens at the end, and who is accountable for each call.

This note is about treating retention and sensitivity labels as records discipline: a short file plan, labels people can use, owners who review before anything is deleted, and why that same work matters when Copilot arrives.

Two kinds of labels, two different questions

Purview uses two label families that are easy to confuse:

  • Sensitivity labels answer how should this be handled? They can mark content, apply encryption, and, on sites and Teams, control settings such as privacy and external sharing.

  • Retention labels and policies answer how long does this live, and what happens at the end? They can keep content for a period, delete it, trigger a review before deletion, or mark an item as a record so it cannot be edited or removed casually.

Retention policies apply broadly to locations, such as all SharePoint sites. Retention labels apply to specific items or libraries. Most organizations need both: a broad baseline policy, and labels for the categories where the rules differ.

Start from a file plan, not the admin portal

Before anyone configures anything, write the file plan. It does not need to be long. For each record category that matters, such as HR files, financial records, contracts, and published policies, capture:

  1. Category — named in the language divisions already use.

  2. Owner — the role accountable for the category.

  3. Retention trigger — when the clock starts: creation, last modification, or an event such as a contract ending.

  4. Retention period — taken from the organization's records schedule and legal requirements, never guessed.

  5. End-of-period action — delete, review, or keep as a record.

The periods are not an IT decision, and they are not a consultant's decision. They come from the organization's records schedule and whoever interprets it, often a records manager working with counsel.

Use what the license already includes

On E5 and G5, several capabilities that make retention practical are already licensed:

  • Default retention labels on SharePoint libraries, so authors do not have to label every document by hand.

  • Auto-applying retention labels based on sensitive information or keywords.

  • Disposition review, so a named reviewer approves deletion at the end of a retention period.

  • Record labels that lock declared records against casual edits and deletion.

Check the Microsoft Purview service description for your specific plan before you design around a feature. The point is not to use everything. It is to stop paying for capability while the file plan lives in a binder.

Keep sensitivity labels few and plain

A sensitivity label only works if people choose the right one. A short set, named plainly, with a sensible default, beats a detailed taxonomy nobody reads. Make labeling mandatory only where it earns the friction.

One setup step matters: enable sensitivity labels for Office files in SharePoint and OneDrive, so those services can process labeled and encrypted content for search, coauthoring, and other features.

The payoff: Copilot works inside the same boundaries

This work is records discipline first. It also pays off if and when the organization turns on Microsoft 365 Copilot.

  • Copilot works within the permissions each person already has. It does not grant new access.

  • Encrypted content needs the right usage rights. When a sensitivity label applies encryption, Microsoft documents that the user needs both VIEW and EXTRACT rights for Copilot to return that content.

  • Labels travel with generated content. Copilot in Word, PowerPoint, and Outlook can apply the source file's sensitivity label to new content drafted from it.

  • Data loss prevention can exclude labeled items from Copilot processing where the organization decides it should.

  • Retention policies can cover Copilot interactions themselves, so prompts and responses are kept or deleted on a schedule the organization sets.

There is a quieter benefit too. Content that has reached the end of its retention period and been disposed of is no longer there to be found, by people or by AI. A working disposition process keeps the pool of content current.

Who carries it

  • Records owner — owns the file plan, the periods, and the categories.

  • Compliance administrator — configures labels and policies to match the file plan, and nothing beyond it.

  • Division content owners — confirm categories for their content and act as disposition reviewers.

  • IT — enables labeling for SharePoint and OneDrive and monitors behavior.

  • Counsel — advises on periods and on holds when litigation or a records request applies.

Where this comes from

For anyone who has run records management in OpenText and SAP landscapes, none of this is new. File plans, disposition, holds, and declared records are the same disciplines. Microsoft 365 gives them a different set of controls. The work is still deciding what to keep and naming who decides.

A short checklist

  • Is there a written file plan with an owner for each category?

  • Do the retention periods come from the records schedule, not from defaults?

  • Are default library labels and disposition review in use where the license allows?

  • Is the sensitivity label set short enough that people choose correctly?

  • If Copilot is turned on later, would this plan hold without changes?

If you want help with the file plan

McCloy Data helps organizations on Microsoft 365 turn Purview into working records discipline, with the retention habits we bring from OpenText and SAP content work. If governance is on your list for a tenant you already license, we would welcome a brief conversation.

McCloy Data

Thought leadership on OpenText, SAP, and practical content and finance automation - from the McCloy Data team.

https://www.mccloydata.com
Next
Next

Practical AI in OpenText VIM: name what the model may change