Microsoft Teams
Every New Team Creates
More Than A Chat Channel
Creating a team quietly creates a SharePoint site, a group mailbox, a shared calendar and a set of permissions. Left ungoverned, an organization ends up with hundreds of them, most abandoned, each holding files nobody is tracking. Governing that sprawl is the work.
A team brings a SharePoint site, a group, a mailbox, a calendar and a permission set into existence together, usually without the creator realising.
Teams created for a single project persist indefinitely unless a lifecycle policy is configured, and almost nobody deletes one voluntarily.
External participants added for a piece of work commonly retain access long after the work concluded, because no process removes them.
Nobody Makes A Bad Decision, And It Still Goes Wrong
Every individual act of creating a team is sensible. The accumulated result is an estate nobody can describe.
Duplicates Nobody Can See
Without a naming convention or a check at creation, several teams appear for the same purpose. Files divide between them, conversations fragment, and staff cannot tell which is authoritative.
Abandoned But Retained
A team created for a bid two years ago still holds the documents. Its members have moved on, nobody is watching it, and the content it contains is still discoverable and still exposed in a breach.
Guests Who Never Left
Contractors and client contacts are added easily and removed rarely. The access remains until somebody performs a review, and in most organizations that review has never been run.
Four Decisions That Prevent Most Of It
None of these is difficult. They are simply rarely made before the estate has already grown.
Who May Create A Team
Allowing everybody to create teams is defensible for a small organization and usually not for a large one. The alternative is a short request process, which adds a little friction and removes most duplication.
Naming And Classification
A convention applied at creation makes the estate searchable, and sensitivity labels attached to a team carry down to the files inside it, which is how protection follows content rather than being applied afterwards.
Expiry And Renewal
A lifecycle policy asks the owner periodically whether the team is still required. Unanswered teams are archived rather than deleted, which keeps the content recoverable while clearing the estate.
Guest Access Review
A periodic report of external members, put in front of team owners rather than IT, is the only reliable way to remove access that should have ended. The owner knows; the administrator cannot.
An Estate You Could Describe To An Auditor
The measurable outcome is that every team has a named owner who has confirmed recently that it is still needed, and that the organization can produce a list of which external people can reach which content.
That matters beyond tidiness. It is the difference between answering a data protection request in an afternoon and spending a fortnight searching, and it substantially reduces the volume of material exposed if a single account is compromised.
How Much Governance Is Enough
| Organization | Sensible position | Priority |
|---|---|---|
| Under 30 staff | Open creation, periodic tidy | Guest review |
| 30 to 200 staff | Naming convention and expiry | Lifecycle policy |
| Over 200 staff | Request process and labelling | Creation control |
| Regulated sector | Classification and retention | Sensitivity labels |
| Heavy external collaboration | Formal guest lifecycle | Access reviews |
Count Your Teams, Then Count The Active Ones
The gap between those two numbers is the governance problem, and it is usually larger than anybody in the organization expects.
Review Your Teams EstateGet in touch with Your Company
Questions about this solution? Reach us directly.