Ask anyone in a mid-sized company where the current version of the supplier agreement lives and watch what happens. They will check the shared drive, then the document library, then search their mail, then ask in a chat channel, and the answer, when it arrives, will be a file attached to a message from four months ago with a name ending in the word final. Document sprawl across Drive, SharePoint and chat is not a storage problem. Storage is nearly free. It is an authority problem: nobody can tell which copy is the one that counts. Every organisation I have worked with has arrived here the same way, and none of them did anything stupid. The file server came first. Then a cloud drive, because people needed documents on the move. Then a collaboration suite with its own document libraries, because that is what the email platform included. Then chat, which quietly became the largest repository of all, because attaching a file to a message is the fastest way to give someone a document and nobody ever deletes a conversation.
The four costs, in the order they are felt
Wasted time. Minutes per search, several searches a day, across everyone. This is the cost people complain about and the least important of the four. Wrong version acted upon. A quotation sent with last year's pricing, a policy applied after it was superseded, a specification built to a draft. This is the cost that actually shows up in money, and it never gets attributed to document management because it gets attributed to the person who used the wrong file. Permission drift. Every modern repository makes sharing a link the default act. Over three years that produces thousands of documents shared with people who have left, with external parties whose projects ended, or with anyone holding the link. Nobody has ever audited it, and the exposure is invisible until something appears somewhere it should not. Retention and discovery exposure. If you cannot say what you hold or where, you cannot delete what you are obliged to delete, cannot produce what you are required to produce, and cannot answer a data subject request properly. Sprawl converts a governance obligation into an archaeology project.
The trap: a taxonomy nobody will use
The instinctive response is to design a company-wide classification scheme and migrate everything into it. This fails reliably, and the reason is worth understanding: you are asking every employee to learn and apply a filing structure that serves the organisation's interests rather than their own, every time they save a file, forever. It is unenforceable. What works is governing containers rather than documents. Decide which repository is authoritative for each category of content, give each container an owner, attach a retention rule and a permission class to the container, and stop caring about how people organise files inside it. Three rules people can remember beat forty they cannot. That means answering four questions in writing. Where do contracts live. Where do finished policies live. Where does project work in progress live. And what is chat for, which is the one everybody avoids.
Chat is a repository, whether you govern it or not
The honest position is that chat attachments are the largest ungoverned content store in most companies. They are searchable by participants only, retained under whatever default the vendor set, permissioned by conversation membership rather than by any deliberate decision, and invisible to every governance process the organisation runs. The workable rule is simple and needs to be stated explicitly: chat is for moving a document, not for keeping it. Anything that will still matter next month goes into a governed container and gets linked, not attached. Sending links rather than files has the additional benefit of eliminating the version problem at source, because a link always resolves to the current document while an attachment is a permanent fork.
Practical Guidance for a Content Governance Review
- Inventory the repositories first, including the ones nobody approved. File servers, cloud drives, document libraries, chat, personal drives, the departmental system somebody bought with a card. You cannot govern what is not on the list.
- Declare one authoritative home per content category. Contracts, policies, finance records, project documents, client deliverables. Write it on one page and publish it.
- Give every container an owner and a retention rule. Owner is a named person. Retention is a number of years with a legal or statutory basis, not a guess.
- Audit external sharing across all repositories. Every link shared outside the organisation, every guest account, every anyone-with-the-link document. Expect an uncomfortable number and expect several genuine surprises.
- Switch the culture from attachments to links. It solves version control and permission drift simultaneously and costs nothing but repetition.
- Deal with the file server explicitly. Migrate what is live, archive what is not, and set a shutdown date. A file server left running as a safety net will still be running in five years.
- Sample rather than survey. Take twenty documents that matter and trace each one: where it lives, who owns it, who can see it, how long it is kept. Twenty traced documents tell you more than a full inventory report.
- Review external access quarterly and permissions annually. Sprawl is a flow, not a stock. A one-off clean-up without a recurring review returns to its previous state within eighteen months.
Locate the copies
Include drives, document libraries, email, chat and physical originals.
Declare the home
Name the authoritative container for this content category.
Assign ownership
Identify the person responsible for the container and paired language versions.
Check access and retention
Review external sharing and the applicable retention basis.
Link and review
Share links to the governed copy and revisit permissions.
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
The Regional Angle
Three things make this harder in the Gulf than the generic advice suggests, and the first is legal rather than technical. Regional business runs bilingually, and the two languages are not equivalent copies. Contracts, employment agreements, corporate documents and government submissions frequently exist in an Arabic version and an English version, and in most local courts the Arabic text governs in the event of conflict. That turns the abstract question of which version is authoritative into a concrete legal one, and I have seen organisations negotiate energetically against an English draft while the Arabic text that will actually be enforced sat unreviewed in a different folder. Any regional content governance design has to pair language versions explicitly, mark which one controls, and keep them together in the same governed container. Second, this region retains a strong attachment to the physical document. Trade licences, attested certificates, notarised powers of attorney, stamped commercial documents, original bills of lading and certificates of origin all carry legal weight in their physical, stamped form, and the scanned copies circulating in the systems above are conveniences rather than records. That produces a dual estate: a physical set held in somebody's safe, and an uncontrolled population of scans in drives, mail and chat. The governance rule that works is to treat the scan as a pointer, recording where the original physically sits and who holds it, and to keep the register of originals as carefully as the digital library. Third, the trade and logistics document flow. Shipping documents, customs paperwork, delivery notes and approvals move between exporters, freight forwarders, clearing agents, banks and customers at speed, and a great deal of that traffic happens over personal messaging on personal phones because it is the only channel everyone shares. The consequence is that a meaningful portion of a regional company's transaction evidence lives on devices it does not own, belonging to staff who may leave the country, with no export capability and no retention control. This is worth naming as a specific risk rather than a general one, because the exposure is highest exactly where the document has evidentiary value in a dispute. Two shorter points. Multi-entity groups reproduce every policy, template and contract per entity, which multiplies sprawl and makes the authoritative version question harder; the fix is a group container for the master and entity containers only for what is genuinely entity-specific. And residency now bears on the repository choice: with regional cloud regions coming online and sector rules tightening, the location of the document library is a decision to make deliberately rather than discover during an audit.
The objection worth taking seriously
The objection I hear most often from technology leaders is that governance programmes are where content goes to die. They begin with an inventory, produce a policy document, appoint owners who did not ask to be owners, and end eighteen months later with a shared drive that looks identical and a folder of governance artefacts nobody reads. Meanwhile the people doing the work route around whatever was imposed, exactly as they routed around the file server, because their incentive is to finish a task rather than to maintain an estate. The more interesting objection is that search has made filing obsolete. If the platform can index every repository, understand natural language queries and surface the most recently edited version, the organising work becomes unnecessary and the sensible response to sprawl is to buy better search rather than to impose structure. There is something to this: search genuinely has improved, and it is more likely to be used than any taxonomy. Both arguments are correct about structure and wrong about the actual problem. Search answers where is the document. It does not answer which one is authoritative, who is allowed to see it, how long we must keep it, or whether it should already have been deleted. Those four questions are the substance of governance and no indexing improvement addresses any of them. That is also the answer to the first objection: the programme fails when it tries to reorganise everything, and succeeds when it does the four narrow things that search cannot, which is why the recommendation here is containers, owners, retention and a sharing audit rather than a taxonomy. That work is measured in weeks, and unlike a migration it survives contact with people who are busy.
Common Questions
Should we consolidate onto one platform?
Fewer is better, but consolidation is a long project and governance is not conditional on it. Declare the authoritative home per content category first; you can reduce the platform count afterwards, from a much better position.
What do we do with twenty years of file server content?
Migrate what has been opened in the last two years, archive the rest to cheap storage with an index, and set a deletion date consistent with your retention rules. Do not migrate everything; you would only be relocating the problem.
How do we stop people attaching files in chat?
Make the alternative easier and say the rule out loud. Link sharing that works for everyone in the channel, plus a repeated expectation from managers. Policy alone will not do it.
What should we expect over the next twelve months?
Expect the collaboration platforms to keep adding governance tooling into the tiers most organisations already pay for, which will remove the cost excuse. Expect external sharing audits to become a standard question in client security questionnaires. And expect the first regional organisations to be caught out by retention obligations they cannot evidence, which will move this from a productivity topic to a compliance one.
Content Governance Review — we trace the documents that actually matter through your estate, find who can still see them, and give each one an owner, a home and a retention rule.
