Every Microsoft 365 tenant can store documents. Governing them is a different problem, and the platform gives you the pieces rather than the answer.
Here is what “governed” turns out to mean in practice, in the order the problems arrive.
Retention has to survive reorganisation
Retention labels attach to content and are enforced by policy, which works until somebody restructures a site. Teams get merged, a department is renamed, a project archive moves. The documents move with it.
Retention that was applied by location does not follow. Retention applied by label does, provided the label was applied in the first place, which brings you to the second problem.
The question to ask of any retention scheme is what happens when the site it lives in is reorganised by somebody who has never heard of it. If the answer depends on that person knowing, it is not governance.
Metadata nobody fills in is not metadata
Content types and managed metadata work. They also require the person saving a document to classify it correctly, at the moment they are trying to finish something else.
Optional fields are left empty. Required fields with a free-text box collect noise. Required fields with a short controlled list collect real values, and the list has to be short enough to choose from without thinking, which means somebody has to do the work of deciding what the categories are before any of it is built.
That work is not a SharePoint task. It is a records conversation with the people whose documents these are, and it is the part most implementations skip because it does not look technical.
The useful test: if you cannot name the five values a field will hold, the field will not be filled in.
Permissions drift as people move
Break inheritance once and you have created a permission set that will be wrong within a year. People change teams. Projects end. Somebody leaves and their direct grants stay.
Permissions granted to groups survive that; permissions granted to individuals do not. Every direct grant is a small future incident, and they accumulate quietly because nothing reports them and nobody reviews a library that is working.
Sensitivity labels help, because they travel with the file rather than with its location, and because they are enforced when the file leaves the tenant. They also cost a policy design, and a label taxonomy that nobody can explain is worse than none, for the same reason as the metadata.
Access reviews are the part that makes it real
The three problems above have the same shape: the configuration is correct on the day it is made and decays afterwards. Nothing in the platform tells you it has decayed.
So governance is not a configuration. It is a configuration plus a recurring review with an owner, and the review is what separates a tenant that is governed from one that was configured once. That means somebody’s name against each library, a schedule, and a report that is short enough to actually read.
If nobody owns the review, the design does not matter.
What we built
We solved this repeatedly for clients, each time reassembling the same pieces: the label taxonomy, the content types, the group structure, the review cadence, and the reporting that makes the review possible.
365BOX is what we built after the third time. It is a SharePoint intranet product that brings structured file management and governed document handling to Microsoft 365, with the parts above already assembled and the decisions above still yours to make.
It does not remove the records conversation. Nothing does. It removes the six weeks of building the same scaffolding around it.