Skip to main content
Category: Systems and Technology

SharePoint

Also known as: Microsoft SharePoint
Simply put

SharePoint is a Microsoft web-based platform that organizations use to store, organize, and share files and other content, typically accessed through a web browser. It is commonly used to build internal company websites (intranets) and to support document management and collaboration among staff. It functions as a shared workspace where content can be uploaded, managed, and distributed within an organization.

Formal definition

SharePoint is a browser-based collaborative platform developed by Microsoft, used primarily for document and content management, file sharing, and the construction of corporate intranets. It organizes content within sites, which may be defined structurally through configurations such as site definitions that specify lists, features, and other components. It should be noted that SharePoint is a content and collaboration technology rather than a dedicated records management system; while it may be configured or extended to support recordkeeping controls such as classification, retention, and disposition, the evidence provided does not describe such capabilities, and whether a given deployment maintains records with the requisite authenticity, reliability, integrity, and usability depends on how it is configured and governed by the organization.

Why it matters

SharePoint is widely deployed across organizations as a platform for storing, organizing, and sharing content, which means that a substantial volume of an organization's information, and potentially its records, may reside within it. Because it functions as a shared workspace and document repository, content held in SharePoint often includes material that has evidential value about business activities. For records and information governance professionals, this makes SharePoint significant not because it is a records management system, but because it is frequently where records are actually created, captured, and stored, whether or not the organization has treated it deliberately as a recordkeeping environment.

The central concern is that SharePoint is a content and collaboration technology rather than a dedicated records management system. Whether content held in SharePoint qualifies as an authoritative record, one that can be relied upon for its authenticity, reliability, integrity, and usability, depends heavily on how a given deployment is configured and governed. Without deliberate configuration and governance, SharePoint environments can accumulate duplicated files, drafts, and transitory information alongside genuine records, making it difficult to distinguish authoritative records from copies and working material. This can create risk when an organization needs to demonstrate what happened, respond to legal or access obligations, or apply consistent retention and disposition.

For these reasons, information governance officers and records managers often need to assess how SharePoint is being used within their organizations rather than assume it either does or does not meet recordkeeping requirements. The platform can, in principle, be configured or extended to support controls such as classification, retention, and disposition, but such capabilities are a matter of organizational implementation. Treating SharePoint's presence as equivalent to a managed recordkeeping regime is a common misunderstanding that professionals in this field will want to correct.

Who it's relevant to

Records managers
Records managers are likely to encounter SharePoint as a place where records are created, captured, and stored in practice. They typically need to determine whether a given deployment is configured and governed in a way that distinguishes authoritative records from drafts, copies, and transitory information, and whether recordkeeping controls such as classification, retention, and disposition are being applied.
Information governance officers
Because SharePoint often holds a broad range of organizational content, information governance officers may need to consider it within their wider accountability framework spanning policy, risk, privacy, and value. Their concern typically extends beyond recordkeeping to how content across SharePoint sites is managed, secured, and governed overall.
Compliance and legal teams
Where content relevant to legal or regulatory obligations resides in SharePoint, compliance and legal staff may need to locate, preserve, and produce material held there. The reliability of such content as evidence depends on how the deployment is configured and governed, which is a relevant consideration when addressing obligations that vary by jurisdiction and sector.
IT and platform administrators
Those responsible for configuring and administering SharePoint sites shape whether the platform can support recordkeeping controls at all. Their decisions about site structure, features, and configuration influence whether content held in SharePoint can be managed with the authenticity, reliability, integrity, and usability that records require.

Inside SharePoint

Content storage and organization
SharePoint provides sites, libraries, and lists that store documents and other content, together with metadata columns used to describe and organize items. These structures support document management functions but do not, on their own, constitute records management controls unless configured for that purpose.
Metadata and classification features
The platform supports applying metadata, content types, and taxonomy terms to content, which can be used to classify items and align them with a records classification scheme. The effectiveness of classification depends on how the organization designs and governs these features rather than on the platform alone.
Retention and disposition capabilities
Through configuration, often in conjunction with broader Microsoft governance tooling, SharePoint can support retention and disposition actions across the content lifecycle. Note that disposition may encompass destruction, transfer, or continued retention depending on organizational policy, and these outcomes must be defined by the organization rather than assumed as defaults.
Access controls and permissions
SharePoint offers permission structures that govern who can view, edit, or manage content, which contribute to protecting the integrity and usability of records. Access control is one component supporting recordkeeping but is distinct from the full set of controls needed to maintain records as reliable evidence.
Versioning and audit features
The platform can track versions of content and maintain activity histories, which may support demonstrating authenticity and integrity. Whether these features satisfy recordkeeping requirements depends on configuration, governance, and applicable standards or obligations in the relevant jurisdiction and sector.

Common questions

Answers to the questions practitioners most commonly ask about SharePoint.

Is SharePoint a records management system?
Not inherently. SharePoint is primarily a collaboration and document management platform, and out-of-the-box it functions closer to a shared workspace for creating, storing, and co-authoring content than to a dedicated recordkeeping system. It can support records management functions when configured for that purpose, but conflating the base platform with a compliant records management solution is a common error. Whether it meets records management requirements typically depends on how it is configured, governed, and supplemented, and on the standards or regulatory expectations applicable in a given jurisdiction and sector.
Does storing a document in SharePoint make it an authoritative record?
Not by itself. Placing content in SharePoint does not automatically confer the properties that distinguish a record from mere information, such as authenticity, reliability, integrity, and usability over time. A document library may hold drafts, working copies, and transitory material alongside content that has been formally captured and managed as a record. Establishing that an item is an authoritative record generally requires deliberate capture, classification, and controls over change and disposition, rather than simply the fact of storage.
How can records be distinguished from working documents within SharePoint?
Organizations often use features such as content types, metadata, dedicated libraries, and declaration or in-place records mechanisms to differentiate managed records from ordinary working documents. The specific approach depends on organizational policy and configuration. The general aim is to apply appropriate controls, such as restricting modification and governing disposition, to items intended to serve as records, while leaving collaborative and transitory content under lighter management. There is no single mandated method, and effectiveness depends on how consistently the chosen model is applied.
How are retention and disposition typically handled in SharePoint?
Retention and disposition are usually managed through retention policies or labels and related governance controls, which can be scoped to sites, libraries, or content types. It is worth noting that disposition is not synonymous with destruction; depending on policy, it may involve destruction, transfer, or retention for permanent preservation. Configuring these controls to reflect approved retention schedules, and ensuring the outcomes are defensible, generally requires alignment between the platform configuration and the organization's records authority and applicable requirements.
Can legal holds be applied to content held in SharePoint?
SharePoint environments commonly provide mechanisms to preserve content in place so that it cannot be altered or deleted while a hold is in effect. The scope, triggering, and administration of such holds depend on organizational policy and on legal obligations that vary across jurisdictions and matters. A hold typically overrides ordinary retention and disposition actions for the affected content. Organizations should confirm that preservation actually captures the relevant content and metadata, since coverage depends on how the platform and its holds are configured.
What governance considerations arise when using SharePoint for recordkeeping?
Practical considerations often include establishing consistent classification and metadata, controlling permissions and versioning, defining what will be captured and managed as a record, and ensuring disposition is authorized and documented. Because SharePoint spans collaboration and recordkeeping uses, governance typically needs to address the boundary between transitory content and records, as well as integrity and auditability of managed items. The appropriate configuration depends on organizational policy and on the records management and information governance requirements applicable in the relevant jurisdiction and sector.

Common misconceptions

SharePoint is inherently a records management system.
SharePoint is primarily a content collaboration and document management platform. It can be configured to support records management functions, but managing records as authoritative evidence across their lifecycle typically requires deliberate design, additional configuration, and governance. Without these, content held in SharePoint may function as working information or copies rather than as controlled records.
Storing a document in SharePoint makes it an authoritative record.
Placing content in SharePoint does not by itself confer the properties that distinguish a record, such as authenticity, reliability, integrity, and usability. A stored item may be a draft, a copy, or transitory information. Whether it becomes an authoritative record depends on capture, classification, and control processes defined by the organization, not on storage location alone.
Enabling SharePoint's retention settings satisfies all retention and disposition obligations.
Configured retention features can support retention and disposition, but they do not automatically ensure compliance. Statutory and regulatory retention requirements vary by jurisdiction and sector, and disposition may include transfer or permanent preservation rather than only destruction. Retention rules must be derived from the organization's approved retention schedule and legal obligations.

Best practices

Define whether SharePoint is intended to function as a document management environment, a records management environment, or both, and configure and govern it accordingly rather than assuming records controls exist by default.
Design metadata, content types, and taxonomy to align with the organization's records classification scheme so that classification is consistent and supports retention and disposition decisions.
Derive retention and disposition rules from the organization's approved retention schedule and applicable legal obligations, recognizing that requirements depend on jurisdiction and sector and that disposition may involve destruction, transfer, or continued preservation.
Use access controls, versioning, and audit capabilities deliberately to help protect the authenticity, integrity, and usability of records, and document how these configurations support recordkeeping requirements.
Distinguish authoritative records from drafts, copies, and transitory information within the environment, and establish processes for capturing content as records at the appropriate point in its lifecycle.
Establish supporting policies, roles, and periodic reviews so that platform configuration remains aligned with evolving organizational, legal, and regulatory requirements over time.