Skip to content
IT White GloveManaged IT support · Advisory · Canada
Menu

Collaboration governance guide · Canada · EN / FR

Who governs Teams, SharePoint, and file sharing once anyone can create a site?

Ce guide est aussi tenu en français. Gouvernance Teams et SharePoint →

Turning on Microsoft Teams or a similar collaboration platform is a five-minute setting. What happens after—dozens of teams and sites created by whoever needed one that week, external links no one remembers granting, a former employee’s shared folder still live—is a governance gap, not a feature gap.

The decision to enable

Decide who can create a team or site, who reviews external sharing and guest access, and who closes an abandoned site—before sprawl becomes the default state.

Decide who can create a site, and who cleans one up

Letting anyone create a team or site removes a bottleneck; it also means sites get created for a single meeting, a short project, or a one-time question and are never closed. Name who can create a new site, what naming or approval step applies, and—just as important—who is responsible for archiving or deleting one once its purpose has passed.

  • Who can create a new team, channel, or site without approval
  • Whether a naming or classification standard applies before creation
  • Who owns closing a site once its project or purpose has ended

Review external sharing as a decision, not a default setting

A link shared “anyone with the link can view” is convenient in the moment and invisible afterward—no one revisits it once the immediate need has passed. Confirm what external sharing is currently allowed by default, who can grant broader access, and how existing external links are found and reviewed rather than assumed to be harmless.

  • What the default external-sharing setting actually permits today
  • Who can grant an exception broader than the default
  • How an existing external or guest link would actually be found and reviewed

Track guest access the way you track employee access

A guest account added for one project quietly outlives the project far more often than an employee account outlives its employment, because no offboarding process is watching it. Apply the same review discipline to guest and external accounts as to departing staff—confirm what each guest can still reach, and on what schedule that access is checked.

Connect collaboration sprawl to what it actually exposes

An orphaned site or an old external link is not a policy violation in the abstract—it is personal, client, or financial information sitting somewhere no one is actively watching. Treat a collaboration sprawl review as part of the same privacy and access-control discipline that already applies to systems and file servers, not a separate, lower-priority housekeeping task.

Decision frame

What leadership should be able to verify.

These criteria do not produce a score. They expose the questions that need resolution before a responsible decision.

CriterionUseful signalLeadership question
CreationWho can create a team or site, and under what standard, is named.Could anyone list every team or site created in the last quarter, and why?
External sharingThe default sharing setting and its exceptions are known, not assumed.What does “anyone with the link” actually allow today?
Guest accessGuest and external accounts are reviewed on the same cadence as staff access.Which guest accounts from finished projects can still reach something?
ClosureAn owner exists for archiving or deleting a site once its purpose ends.Who actually closes a site when the project it supported is done?

Practical scenarios

The same discipline applied to different decisions.

A departed employee’s project site is still shared externally

Situation: A discovery during an access review shows a SharePoint site created two years ago by an employee who has since left, still shared with an external partner who no longer has an active engagement.

Useful response: Treat this as the access-control gap it is—confirm what the external party could actually reach, remove access, and use the finding to test whether site ownership transfers when an employee leaves, rather than treating it as an isolated cleanup task.

Boundary: This guide does not investigate a specific data exposure or determine what, if anything, was accessed.

Dozens of Teams channels exist with no clear owner

Situation: An audit finds far more active teams and channels than the organization has active projects, several with no members who can explain their current purpose.

Useful response: Assign an owner to review and either confirm, merge, or archive each one on a fixed timeline, and use the exercise to decide a lighter-weight creation standard going forward rather than repeating the same cleanup in another year.

Boundary: This guide does not perform the archiving itself or recommend a specific governance tool.