From scattered files to governed records
A portable system for designing and building an organization's data governance — the structure, the groups, the permissions, and the habits that keep it clean. Work through the tabs in order. Everything you type saves automatically and exports as one file per client.
The five principles
- 01Shared ownership, not personal storage. i Records live in org-owned spaces, never an individual's drive.
- 02Access by role, through groups — never by name. i
- 03Least privilege. i Smallest access that still lets someone work.
- 04Decide the rules, then build, then pilot, then roll out. i
- 05Never "done" — maintained. i
How the build flows
Sign-off gate (Phase 3): the client approves the blueprint before you build. Pilot gate (Phase 7): you prove the recipe on one low-risk department before migrating everyone.
How to use this tool
1 · Discover
Fill Client Setup, Roles, Inventory and Discovery Questions during your meetings.
2 · Design
Build the structure in Access Designer — departments, sub-areas, groups, permissions. Check it in the Permission Matrix.
3 · Build & hand off
Work the 14-Phase Tracker, then export the PDF report as the client's record.
The stages explained, in plain English
Every stage of the method, written so anyone can follow it — no jargon. For each one: what it means, what you actually do, and how you know you are finished. Click a stage to open it.
You are moving an organization out of scattered personal folders into one shared, organized, locked filing system that the organization owns. First you get permission and see what they have. Then you agree the filing structure and who is allowed to see what. Then you build it empty, test it on one small department, and only after that move everybody. Finally you write it down, lock it down, train people, and set up a backup — then hand it over with a routine that keeps it clean.
Words people trip over
| Word | What it actually means |
|---|---|
| Container | A department's file home — one shared space owned by the organization, not by a person. In Google it is a Shared Drive; in Microsoft a Site; in Dropbox a Team Folder. |
| Group | A named list of people, like "Finance team". You give the space to the group, not to individuals — so adding someone to the list gives them access automatically. |
| Permission / access level | How much someone can do: look only, add and edit, or full control including deleting and adding people. |
| Least privilege | Give each person the smallest access that still lets them do their job. If a leaked password only reaches a little, it only damages a little. |
| Locked sub-area | A separate, private space inside a department for confidential things like payroll. It has its own small group. People in the department who are not in that group cannot see it at all. |
| Migration | Moving the files from where they live now into the new structure. |
| Pilot | A test run with one small department, to catch problems while they are still small. |
| Retention | The rule for how long each kind of record is kept before it is archived or deleted. |
| Offboarding | The checklist you run the moment someone leaves, so all their access is removed everywhere. |
| Access review | A regular check — every three months — of who can see what, removing anyone who should not still be there. |
| PHI | Protected Health Information — patient details like diagnosis or treatment. Legally the most sensitive data an organization can hold. |
| BAA | Business Associate Agreement — a contract with the software vendor that legally allows patient health data to be stored in their tool. |
Engagement details
Identify the engagement. These details appear on the cover of the exported PDF report and name your export file.
Everything you type saves in this browser automatically. Export downloads one JSON file for this client — that file is your portable record. Import it any time to carry on, on any computer.
Who owns what
Fill this before any build begins. The most important — and most often empty — is the Operational Owner: the client-side person who owns the system after you hand it over.
| Role | What they do | Assigned to |
|---|---|---|
| Executive Sponsor i | Says yes, unblocks politically, owns the mandate. | |
| Operational Owner i | Owns the system day-to-day after implementation ends. | |
| Workspace Administrator i | Holds platform admin keys; grants access. | |
| Implementation Lead i | Runs the engagement end to end. | |
| Technical Architecture i | Designs and builds structure, groups, permissions. | |
| Department Reviewers i | Confirm their area's structure and access. |
Super Admin (whole platform) ≠ Container Manager (one department) ≠ Group Manager (one people-list). A Department Lead needs the last two, never the first. Call them "Department Lead," never "admin," or someone will hand over the keys to everything.
Current-state inventory
You cannot move what you have not counted. Log every place the organization keeps records today — including personal drives, which are where the real risk sits.
For every row marked personal drive: if that person left tomorrow, would the organization lose it? Those are your migration priority — not the tidy shared folders.
Questions to ask
The quality of these answers decides whether the project succeeds. Record what the client actually says — answered questions appear in the exported report; blank ones are left out.
Authority & inventory
Architecture & permissions
Rollout, handoff & safety
Information architecture
The organization's filing structure. Numbered so it always sorts the same for everyone, and so a file name tells you instantly which area it belongs to. Adjust the names to match this client, then get it signed off before building.
| # | Department container | Notes for this client |
|---|
This is the blueprint. Do not build anything until the client has approved this list. Rebuilding a structure after files have moved into it is the most expensive mistake in the whole method.
Access designer
Design the real structure: each department gets a container and a group; anything confidential inside it gets its own locked sub-container with a smaller group. This is how someone in Finance can work all day in Finance and still never see payroll.
Being in a department does not mean seeing everything in it. A locked sub-container is a separate space with its own smaller group — people not in that group cannot see it at all, not even the file names. Never rely on hiding a file inside a space everyone can browse; that always leaks.
Permission levels — what each one can do
| Level | See files | Add / edit | Delete & reorganize | Add / remove people |
|---|---|---|---|---|
| Manager | Yes | Yes | Yes | Yes |
| Contributor | Yes | Yes | No | No |
| Viewer | Yes | No | No | No |
| No access | No — cannot even see it exists | No | No | No |
One person who can add and remove people is a single point of failure — when they are on leave, nothing moves. Give every container a primary and a backup Manager, and let the quarterly review catch anything they change.
Permission matrix
Everything you designed, in one table you can read across. This is what you review with each department head — and what you hand to the Workspace Administrator to build from.
Every space has two Managers · every locked space has a genuinely smaller group than its parent · nobody has Manager who only needs Contributor · every group name follows one pattern.
Naming standard
Build the file-naming rule, watch it assemble live, then write it into the client's documented standards. Consistent names are what make "anyone can find anything" actually true.
Rules that come with it
- ·Start with the two-digit department code so files sort by area.
- ·Use ISO dates (YYYY-MM-DD) so they sort in date order automatically.
- ·No spaces. One separator, everywhere.
- ·Versions as v01, v02 — zero-padded so they sort right. Never "final-final".
- ·Never put personal or health details in a file name — names are visible in searches, links and notifications.
14-phase tracker
The safe order of operations. Tick each phase as it completes and note the date or blocker — this becomes your status report.
0 of 14 phases complete
| ✓ | # | Phase | What it really means | Status / date |
|---|
Platform & tool mapping
One tool per job, and the same architecture expressed in whichever platform this client uses. The shape holds everywhere; only the names change.
One tool per job
Digital Headquarters i
Official records and knowledge.
Project Management i
Tasks and execution — not records.
Business Applications i
CRM, accounting, donor DB, HRIS.
Executive Intelligence i
Reporting and dashboards.
Backup & Recovery i
Independent backup + recovery plan.
The rule
When two systems disagree, one is the record of truth and the other is a copy. Decide which, per app.
Same architecture, three platforms
| Concept | Google Workspace | Microsoft SharePoint | Dropbox Business |
|---|---|---|---|
| Department container | Shared Drive | Site / Document Library | Team Folder |
| Locked sub-container i | A second Shared Drive | A separate Site or library with broken inheritance | A separate Team Folder |
| Access group | Google Group | Microsoft 365 / Security Group | Dropbox Group |
| Manager | Manager | Owner / Full Control | Folder Admin |
| Contributor | Contributor | Edit / Contribute | Editor |
| Viewer | Viewer | Read | Viewer |
| Classification labels | Drive labels | Sensitivity labels (Purview) | Naming convention |
| Retention & holds | Google Vault | Purview retention | Governance add-ons |
| Data-loss prevention | Drive DLP | Purview DLP | Content controls |
| Enforced strong login | 2-Step Verification | Entra ID MFA | Two-step + SSO |
Retention, data-loss prevention and advanced labels exist only on higher editions. Confirm the client's exact edition before promising any of them — otherwise the plan changes or they upgrade.
Sensitive data & compliance
For a health or patient-serving organization this is decided on day one, not assumed. Classify first; lock the most sensitive data hardest.
The vendor agreement (BAA) i
To hold protected health information under HIPAA, the organization must sign the vendor's Business Associate Agreement and use only the services it covers. Confirm before any health data moves.
Classify on day one i
Separate donor, patient/family, and board/financial data. Patient data gets its own locked container with the smallest group.
Record the decisions
A fundraising foundation is often not a HIPAA covered entity — but it becomes a business associate the moment it receives patient health data from a hospital, or runs programs collecting diagnoses or treatment details. Raise it so it gets decided, in writing, not assumed.
The governance loop
What keeps the system healthy after you leave. Three habits, run forever — the difference between a folder structure and real governance.
Quarterly access review i
Audit every group. Remove who should not be there. Pay special attention to locked spaces.
On / off-boarding i
Join → add to groups. Leave → remove; access vanishes everywhere at once.
Test the restore i
Actually recover a file. Prove the safety net works before you need it.
Handoff record
"What happens to this system 12 months after we walk away?" If the client cannot answer that, the governance is not real yet — it is just a folder structure.