SharePoint Online is the backbone of intranets, document management, QMS and team workspaces in most Swiss enterprises. Without SharePoint governance, however, a tenant turns into an opaque data jungle within a few years – with high compliance risk under the Swiss FADP (nDSG), and a poor foundation for Microsoft 365 Copilot. This guide shows how Swiss enterprises set up SharePoint governance pragmatically in 2026.
What is SharePoint governance?
SharePoint governance is the set of rules, roles, processes and tools that define how SharePoint sites are created, operated and decommissioned in a tenant. It covers technical configuration as well as organisational accountability.
Without governance, typical issues are:
- Hundreds of orphaned sites from leavers
- Inconsistent permission models (mix of groups, individuals, external guests)
- "Everyone except external users" permissions that lead Copilot to wrong sources
- Version sprawl and storage cost explosion (see SharePoint Storage Monster)
- FADP/GDPR risk from missing classification of personal data
The five building blocks of a governance concept
1. Site lifecycle and provisioning
Define a clear process for how new SharePoint sites are created:
- Self-service vs. central provisioning – Swiss enterprises typically combine both: Teams and project sites via self-service, communication sites and QMS sites centrally.
- Site templates / designs per use case (project, team, department, extranet)
- Mandatory metadata at creation – sponsor, purpose, classification, retention, language (DE/FR/IT/EN)
- Naming convention – e.g.
proj-2026-cnext-intranet,dept-finance-en
2. Permission model
A solid permission model follows three rules:
- 1Always grant access via Microsoft 365 Groups or Entra ID security groups (never to individuals)
- 2Manage external guests in dedicated guest groups (with Conditional Access)
- 3At most three permission levels per site (Visitor, Member, Owner)
Critical: enable Restricted SharePoint Search as soon as Microsoft 365 Copilot is rolled out, to prevent Copilot from accessing misconfigured open-sharing content.
3. Sensitivity labels and DLP
Swiss enterprises need at least a 3-tier label taxonomy:
| Label | Use | Protection |
|---|---|---|
| Public | Marketing, public website content | None |
| Internal | Employee content, project files | Internal encryption |
| Confidential | HR, finance, contracts | Encryption + watermark |
| Strictly confidential | Board, M&A, patents | Double Key Encryption |
Auto-labelling for personal data (Swiss social security, IBAN, credit cards) and DLP rules prevent confidential data from being shared externally.
4. Retention and lifecycle
Microsoft Purview retention policies define how long content is kept and when it is auto-deleted – important for FADP Art. 6 (proportionality, purpose limitation). Typical retention for Swiss SMBs:
- Business correspondence: 10 years (Swiss Code of Obligations Art. 958f)
- Accounting records: 10 years
- HR files: 10 years after exit
- Project data: 7 years
- Marketing data: 3 years
- Temp/working folders: 90-day auto-delete
5. Roles and responsibilities
Define a clear RACI model:
- Tenant admin (CNEXT or in-house) – Global configuration
- SharePoint service owner (internal IT) – Tenant-wide policies, tooling
- Site owner (business) – Content and permissions of the site
- Information owner (business) – Classification and retention
- Data protection officer – DSAR oversight, audits
Tooling for SharePoint governance
Tools proven in Swiss projects:
- Microsoft Purview – sensitivity labels, DLP, retention, eDiscovery
- SharePoint Admin Center – site lifecycle, sharing policies, restricted search
- SharePoint Storage Monster – storage reports and cost optimisation (sharepoint-storage-monster.com)
- PnP PowerShell / Microsoft Graph – automated audits and reports
- Microsoft Syntex – automated classification and metadata extraction
Reporting and audits
At least quarterly, Swiss enterprises should produce:
- Site inventory with owner, classification, activity, storage
- Sharing report for external guests and open-sharing links
- Permission anomalies (sites granting access to individuals)
- Retention compliance (sites with no retention policy)
- Storage top-100 with optimisation suggestions
Rollout roadmap
CNEXT runs SharePoint governance rollouts in four phases:
- 1Discovery (1–2 weeks): tenant inventory, stakeholder interviews, baseline analysis
- 2Concept (3–4 weeks): governance document, RACI, naming, sensitivity-label concept
- 3Implementation (4–8 weeks): Microsoft Purview configuration, site templates, training
- 4Operations (ongoing): quarterly audits, reporting, continuous improvement
FAQ
Do we need SharePoint governance as a 50-person SMB? Yes. Small tenants grow uncontrolled the fastest. A lightweight governance (naming, three sensitivity labels, basic retention) is enough and costs only a few days.
How does SharePoint governance fit a Copilot rollout? Governance is a prerequisite for Copilot. Without clean permissions, Copilot returns wrong or confidential content to the wrong people.
Who owns governance in the organisation? Typically IT (tenant) and the business (site owner). Swiss enterprises often add the data protection officer as oversight.
What does a SharePoint governance project cost? Discovery from CHF 8,000, concept from CHF 15,000, implementation between CHF 25,000 and 80,000 depending on tenant size.
Conclusion
In 2026, SharePoint governance is no longer optional – especially for Swiss enterprises subject to FADP, planning Copilot, or facing high compliance requirements. CNEXT, a Microsoft Solutions Partner in Bern, guides Swiss companies through the full lifecycle – from concept and Microsoft Purview rollout to ongoing audits.

