Governance and retention

Role-based access, classification, retention and legal hold that actually run — because access granted case by case for ten years leaves nobody able to say who can see what.

office 620822 1920

What information governance has to enforce

  • Role-based access models

    Access derived from role and organisational position rather than granted individually, so joining, moving and leaving are handled by the model instead of by memory.

  • Permission auditing and reporting

    A straight answer to who can see a given site or document, and what a given person can reach — which most estates cannot currently produce.

  • Classification and sensitivity labels

    Labels applied automatically from context where possible, driving encryption, sharing limits and retention rather than merely displaying a word.

  • Retention, archiving and disposal

    Retention periods defined per category and executed on schedule, including the disposal step that most organisations define and never run.

  • Legal hold and eDiscovery

    The ability to freeze and produce a defined set of content, tested before it is needed rather than during a dispute.

  • Activity logging

    Access and change history retained long enough to be useful, and queryable by the people who need to ask.

Don’t see your challenge here? Talk to us about your project

Model the permissions first, or the new system inherits the old problem

Where access has been granted individually for a decade, nobody can state who can see what. Migrating that structure faithfully into a new platform reproduces the problem with a newer interface and a fresh budget.

Modelling access by role before content moves is the one intervention that reliably prevents it. It is also the point at which a surprising amount of long-forgotten access gets discovered and removed.

Role-derived
Access follows position, not individual grants.
Answerable
Who can see what, reported on demand.
Automatic labels
Classification from context where possible.
Disposal runs
The step most policies define but never execute.
Hold tested
Legal hold proven before it is needed.
Logged
Access history retained and queryable.

Document governance in a public-sector setting

Building Enterprise Estonia's document management system meant treating retention and access as requirements rather than as configuration to be finished later: in a public body, who could see a document and how long it is kept are questions with statutory answers, and the system has to be able to give them.

Common questions

Is this a project or an ongoing activity?

Both. The modelling and clean-up are a project; permission review, ownership confirmation and disposal are recurring. We automate as much of the recurring part as possible, because manual governance reliably lapses.

Can you audit what we have before we commit?

Yes, and it is usually the right first step. A permission and content audit frequently changes the scope of what people thought they wanted, generally by reducing it.

What about content we are not allowed to delete?

Legal hold and statutory retention are modelled explicitly and take precedence over ordinary disposal rules. The system should make it impossible to delete something under hold, rather than relying on anyone remembering.

Let's talk about your information estate

Tell us what people cannot find today and which system nobody wants to own. We will come back with an honest read on whether the answer is search, governance or migration — and what a realistic first phase looks like.

Rando Siimon Profile Image

Rando Siimon

Business Development Manager