StillAdvisory
Data Governance Implementation System
Auto-saving
01 · Overview & Method

From scattered files to governed records

A portable system for designing and building an organization's data governance — the structure, the groups, the permissions, and the habits that keep it clean. Work through the tabs in order. Everything you type saves automatically and exports as one file per client.

The five principles

  • 01
    Shared ownership, not personal storage. i Records live in org-owned spaces, never an individual's drive.
  • 02
    Access by role, through groups — never by name. i
  • 03
    Least privilege. i Smallest access that still lets someone work.
  • 04
    Decide the rules, then build, then pilot, then roll out. i
  • 05
    Never "done" — maintained. i

How the build flows

STAGE 1 · SET UP 1 · Authority & AccessAdmin keys · vendor agreement 2 · InventoryMap every file & personal drive 3 · Approve architecture ✋GATE — client signs the blueprint STAGE 2 · CORE RECIPE — repeat per department (4–6) Department Container"03 Finance" — the file home Access Groupfinance-dept — the people list ADD GROUP Sensitive sub-area? → its own LOCKED sub-container + smaller group Payroll inside Finance · patient data · board minutes · donor PII STAGE 3 · ROLL OUT (7–9) → STAGE 4 · HARDEN & HAND OFF (10–14) 7 · Pilot ONE dept ✋GATE — prove it small first 8 · Migrate allOnly after the pilot 9–12 · Connect & hardenApps · docs · security 13–14 · Train & back upGo live · test a restore ONGOING LOOP · quarterly access review → on/off-boarding → test the restore Feeds corrections back into the recipe. This is what keeps it real after handoff.
The two gates you never skip

Sign-off gate (Phase 3): the client approves the blueprint before you build. Pilot gate (Phase 7): you prove the recipe on one low-risk department before migrating everyone.

How to use this tool

1 · Discover

Fill Client Setup, Roles, Inventory and Discovery Questions during your meetings.

2 · Design

Build the structure in Access Designer — departments, sub-areas, groups, permissions. Check it in the Permission Matrix.

3 · Build & hand off

Work the 14-Phase Tracker, then export the PDF report as the client's record.

02 · Read this first

The stages explained, in plain English

Every stage of the method, written so anyone can follow it — no jargon. For each one: what it means, what you actually do, and how you know you are finished. Click a stage to open it.

The whole thing in one paragraph

You are moving an organization out of scattered personal folders into one shared, organized, locked filing system that the organization owns. First you get permission and see what they have. Then you agree the filing structure and who is allowed to see what. Then you build it empty, test it on one small department, and only after that move everybody. Finally you write it down, lock it down, train people, and set up a backup — then hand it over with a routine that keeps it clean.

Words people trip over

WordWhat it actually means
ContainerA department's file home — one shared space owned by the organization, not by a person. In Google it is a Shared Drive; in Microsoft a Site; in Dropbox a Team Folder.
GroupA named list of people, like "Finance team". You give the space to the group, not to individuals — so adding someone to the list gives them access automatically.
Permission / access levelHow much someone can do: look only, add and edit, or full control including deleting and adding people.
Least privilegeGive each person the smallest access that still lets them do their job. If a leaked password only reaches a little, it only damages a little.
Locked sub-areaA separate, private space inside a department for confidential things like payroll. It has its own small group. People in the department who are not in that group cannot see it at all.
MigrationMoving the files from where they live now into the new structure.
PilotA test run with one small department, to catch problems while they are still small.
RetentionThe rule for how long each kind of record is kept before it is archived or deleted.
OffboardingThe checklist you run the moment someone leaves, so all their access is removed everywhere.
Access reviewA regular check — every three months — of who can see what, removing anyone who should not still be there.
PHIProtected Health Information — patient details like diagnosis or treatment. Legally the most sensitive data an organization can hold.
BAABusiness Associate Agreement — a contract with the software vendor that legally allows patient health data to be stored in their tool.
02 · Client Setup

Engagement details

Identify the engagement. These details appear on the cover of the exported PDF report and name your export file.

How saving works

Everything you type saves in this browser automatically. Export downloads one JSON file for this client — that file is your portable record. Import it any time to carry on, on any computer.

03 · Roles & Authority

Who owns what

Fill this before any build begins. The most important — and most often empty — is the Operational Owner: the client-side person who owns the system after you hand it over.

RoleWhat they doAssigned to
Executive Sponsor iSays yes, unblocks politically, owns the mandate.
Operational Owner iOwns the system day-to-day after implementation ends.
Workspace Administrator iHolds platform admin keys; grants access.
Implementation Lead iRuns the engagement end to end.
Technical Architecture iDesigns and builds structure, groups, permissions.
Department Reviewers iConfirm their area's structure and access.
Word-trap — "admin" means three different things

Super Admin (whole platform) ≠ Container Manager (one department) ≠ Group Manager (one people-list). A Department Lead needs the last two, never the first. Call them "Department Lead," never "admin," or someone will hand over the keys to everything.

04 · Phase 2

Current-state inventory

You cannot move what you have not counted. Log every place the organization keeps records today — including personal drives, which are where the real risk sits.

The risk question

For every row marked personal drive: if that person left tomorrow, would the organization lose it? Those are your migration priority — not the tidy shared folders.

05 · Discovery

Questions to ask

The quality of these answers decides whether the project succeeds. Record what the client actually says — answered questions appear in the exported report; blank ones are left out.

Authority & inventory

Architecture & permissions

Rollout, handoff & safety

06 · Phase 3

Information architecture

The organization's filing structure. Numbered so it always sorts the same for everyone, and so a file name tells you instantly which area it belongs to. Adjust the names to match this client, then get it signed off before building.

#Department containerNotes for this client
Sign-off gate — Phase 3

This is the blueprint. Do not build anything until the client has approved this list. Rebuilding a structure after files have moved into it is the most expensive mistake in the whole method.

07 · Phases 4–5

Access designer

Design the real structure: each department gets a container and a group; anything confidential inside it gets its own locked sub-container with a smaller group. This is how someone in Finance can work all day in Finance and still never see payroll.

The rule this solves

Being in a department does not mean seeing everything in it. A locked sub-container is a separate space with its own smaller group — people not in that group cannot see it at all, not even the file names. Never rely on hiding a file inside a space everyone can browse; that always leaks.

Permission levels — what each one can do

LevelSee filesAdd / editDelete & reorganizeAdd / remove people
ManagerYesYesYesYes
ContributorYesYesNoNo
ViewerYesNoNoNo
No accessNo — cannot even see it existsNoNoNo
Always two Managers

One person who can add and remove people is a single point of failure — when they are on leave, nothing moves. Give every container a primary and a backup Manager, and let the quarterly review catch anything they change.

08 · Verification

Permission matrix

Everything you designed, in one table you can read across. This is what you review with each department head — and what you hand to the Workspace Administrator to build from.

Departments
0
Total spaces
0
Locked spaces
0
Groups needed
0
Check these before you build

Every space has two Managers · every locked space has a genuinely smaller group than its parent · nobody has Manager who only needs Contributor · every group name follows one pattern.

09 · Phase 10

Naming standard

Build the file-naming rule, watch it assemble live, then write it into the client's documented standards. Consistent names are what make "anyone can find anything" actually true.

Rules that come with it

  • ·
    Start with the two-digit department code so files sort by area.
  • ·
    Use ISO dates (YYYY-MM-DD) so they sort in date order automatically.
  • ·
    No spaces. One separator, everywhere.
  • ·
    Versions as v01, v02 — zero-padded so they sort right. Never "final-final".
  • ·
    Never put personal or health details in a file name — names are visible in searches, links and notifications.
10 · Delivery

14-phase tracker

The safe order of operations. Tick each phase as it completes and note the date or blocker — this becomes your status report.

0 of 14 phases complete

#PhaseWhat it really meansStatus / date
11 · Platform

Platform & tool mapping

One tool per job, and the same architecture expressed in whichever platform this client uses. The shape holds everywhere; only the names change.

One tool per job

Digital Headquarters i

Official records and knowledge.

Project Management i

Tasks and execution — not records.

Business Applications i

CRM, accounting, donor DB, HRIS.

Executive Intelligence i

Reporting and dashboards.

Backup & Recovery i

Independent backup + recovery plan.

The rule

When two systems disagree, one is the record of truth and the other is a copy. Decide which, per app.

Same architecture, three platforms

ConceptGoogle WorkspaceMicrosoft SharePointDropbox Business
Department containerShared DriveSite / Document LibraryTeam Folder
Locked sub-container iA second Shared DriveA separate Site or library with broken inheritanceA separate Team Folder
Access groupGoogle GroupMicrosoft 365 / Security GroupDropbox Group
ManagerManagerOwner / Full ControlFolder Admin
ContributorContributorEdit / ContributeEditor
ViewerViewerReadViewer
Classification labelsDrive labelsSensitivity labels (Purview)Naming convention
Retention & holdsGoogle VaultPurview retentionGovernance add-ons
Data-loss preventionDrive DLPPurview DLPContent controls
Enforced strong login2-Step VerificationEntra ID MFATwo-step + SSO
Edition decides your toolkit

Retention, data-loss prevention and advanced labels exist only on higher editions. Confirm the client's exact edition before promising any of them — otherwise the plan changes or they upgrade.

12 · Phase 12

Sensitive data & compliance

For a health or patient-serving organization this is decided on day one, not assumed. Classify first; lock the most sensitive data hardest.

The vendor agreement (BAA) i

To hold protected health information under HIPAA, the organization must sign the vendor's Business Associate Agreement and use only the services it covers. Confirm before any health data moves.

Classify on day one i

Separate donor, patient/family, and board/financial data. Patient data gets its own locked container with the smallest group.

Record the decisions

Covered entity vs business associate

A fundraising foundation is often not a HIPAA covered entity — but it becomes a business associate the moment it receives patient health data from a hospital, or runs programs collecting diagnoses or treatment details. Raise it so it gets decided, in writing, not assumed.

13 · Ongoing

The governance loop

What keeps the system healthy after you leave. Three habits, run forever — the difference between a folder structure and real governance.

Quarterly access review i

Audit every group. Remove who should not be there. Pay special attention to locked spaces.

On / off-boarding i

Join → add to groups. Leave → remove; access vanishes everywhere at once.

Test the restore i

Actually recover a file. Prove the safety net works before you need it.

Handoff record

The question that outranks all others

"What happens to this system 12 months after we walk away?" If the client cannot answer that, the governance is not real yet — it is just a folder structure.