SharePoint 2013/2016 – Information Management Policies – Part 1

Thu, 03/09/2017 - 10:48

In an ever increasing litigious world, it is more important than ever for organizations to have clear policies for managing information. It’s no longer an option in your information management system to avoid having clear policies and procedures for how information is regulated. Policies that govern who can access your information, what they can do with the information, the retention periods of records, and the auditability of information must be in place. Regulators and examiners have very specific guidelines about how retention and auditing must be implemented.

SharePoint provides very useful tools for regulating the creation, interaction, and disposition of content using Information Management Policies. These Information Management Policies are a set of rules that are assigned to content within SharePoint. These rules will define the retention schedule, auditability, and barcodes (Labels were deprecated in 2013).  These policies can be defined for multiple content types within a site collection, a list, a library, or folder (location-based retention policy). Policies can be created at the Site Collection and used within Content Types as well to enforce consistency.  Policies can be deployed across site collections for enterprise-wide policy deployment.

These policies provide a structured way for content owners and administrators to define the relevant retention policies and apply them consistently across all relevant information.  These policies help keep users from having to think about when to apply policies as they are applied automatically once defined.   Management of these policies is not complicated.  The configuration is GUI driven and is included in the SharePoint interface.  The policies configuration is accessed in Permissions and Policies under Information Management Policies in a List or Library.

The following are the types of settings available when defining policy:

Retention   The Retention policy feature lets you define retention stages, with an action that happens at the end of each stage. For example, you could define a two-stage retention policy on all documents in a specific library that deletes all previous versions of the document one year after the document is created, and declares the document to be a record five years after the document is created.

The actions that can occur at the end of a stage include the following:


  • Moving the item to the Recycle Bin
  • Permanently deleting the item
  • Transferring the item to another location
  • Starting a workflow
  • Skipping to the next stage
  • Declaring the item to be a record
  • Deleting all previous drafts of the item
  • Deleting all previous versions of the item

    Auditing   The Auditing policy feature logs events and operations that are performed on documents and list items. You can configure Auditing to log events such as the following:
  • Editing a document or item
  • Viewing a document or item
  • Checking a document in or out
  • Changing the permissions for a document or item
  • Deleting a document or item

    Labeling   The label policy feature has been deprecated and should not be used in SharePoint Server 2013.

    Barcode   The Barcode policy feature enables you to track physical copies of a document by creating a unique identifier value for a document and inserting a bar code image of that value in the document. By default, bar codes are compliant with the common Code 39 standard (ANSI/AIM BC1-1995, Code 39), and you can plug in other bar code providers by using the policies object model.


In the next blog post, I will discuss creating and implementing these policies.