SharePoint Site Disposition Matrix | Keep, Archive, Retain, Restore or Delete | R.A.H.S.I. Framework™ Analysis
🛡️ Need implementation, not just insights? Let’s secure the highest-risk sites before Copilot expands.
🛡️ Read Complete Article |
🛡️ Let’s Connect |
An inactive SharePoint site is not automatically a deletion candidate.
It may contain operational knowledge, regulated records, unresolved ownership, excessive permissions, historical evidence or recoverable business value.
The correct governance question is not simply:
Is this site old?
It is:
Which controlled disposition is defensible for this site?
A mature SharePoint lifecycle programme requires more than a binary choice between keeping and deleting a site. It requires a structured decision model that separates operational relevance, preservation, compliance, recovery and permanent disposal.
The five-way SharePoint disposition matrix
| Disposition | Use when | Required validation |
|---|---|---|
| Keep | The site remains active and operationally relevant | Purpose, owner, usage, access and business dependency |
| Archive | The site is inactive but must remain recoverable | Ownership, archive suitability, dependencies and compliance status |
| Retain | Content is subject to legal, regulatory or policy obligations | Retention policy, label, hold, duration and disposition requirements |
| Restore | Archived or deleted content must return to active use | Recovery basis, ownership, permissions and renewed business purpose |
| Delete | No continuing value or preservation obligation remains | Retention clearance, owner approval, dependency review and evidence |
1. Keep
A site should remain active when it supports a current business process, project, service, department or knowledge requirement.
A defensible Keep decision should confirm:
- A valid business purpose
- At least one accountable owner
- Legitimate and reviewed permissions
- Current usage or operational dependency
- Appropriate sensitivity and sharing controls
- A future review date
Keeping a site should not mean excluding it from governance. Active sites still require recurring ownership, permission and lifecycle validation.
2. Archive
A site should be archived when it is no longer required for daily use but its content, structure, metadata, permissions or historical context must remain recoverable.
Microsoft 365 Archive moves inactive SharePoint content into a colder storage tier. An archived site no longer consumes the tenant’s active SharePoint storage quota and is no longer directly accessible to users.
However, its content can remain available for supported search, Microsoft Purview compliance and eDiscovery scenarios. When reactivated, the site generally returns with its previous permissions, lists, pages, files, folder structure and metadata.
Archive should therefore be understood as:
Preservation without continued operational access.
It is not deletion, backup or a replacement for Microsoft Purview retention.
3. Retain
Retention is a compliance decision rather than a site-activity decision.
Use Retain when content must be protected because of:
- Legal obligations
- Regulatory requirements
- Contractual commitments
- Records-management rules
- Internal information-governance policies
- Litigation or investigation holds
Microsoft Purview retention policies and retention labels can support three principal outcomes:
- Retain content
- Delete content
- Retain content and then delete it
A retention obligation can continue even when users delete content or when the associated site is archived or deleted.
For that reason, a site should never be approved for permanent deletion merely because it is inactive.
4. Restore
Use Restore when archived or deleted content must return because of:
- Renewed operational demand
- Business continuity
- Audit or investigation
- Legal discovery
- Accidental deletion
- Security-incident recovery
- Regulatory examination
An archived site can be reactivated through the SharePoint admin centre or supported administrative tooling.
A deleted site may also be recoverable during Microsoft’s available recovery window. Microsoft 365 Backup provides a separate recovery capability for supported workloads and recovery scenarios.
Restoration should not end when the technical recovery completes. The restored site should also undergo:
- Owner confirmation
- Permission review
- Sharing validation
- Sensitivity assessment
- Business-purpose confirmation
- Lifecycle reclassification
Recovery without governance can recreate the same risk that existed before the site was removed.
5. Delete
Deletion should be used only when the organisation can demonstrate that:
- The site has no continuing business purpose
- No legal hold applies
- No retention policy or label prevents deletion
- No regulatory or contractual preservation requirement remains
- No active process depends on the site
- Ownership and stakeholder reviews are complete
- Recovery requirements have been considered
- The decision has been approved and recorded
Deleting a site is not ordinary storage housekeeping.
It is a governed disposition decision that can ultimately lead to permanent and irreversible data removal after applicable retention and recovery periods expire.
The R.A.H.S.I. disposition sequence
DISCOVER
Identify:
- Inactive sites
- Ownerless sites
- High-storage sites
- Overshared sites
- Sensitive content
- Permission exposure
- External sharing
- Retention and hold conditions
- Business and technical dependencies
SharePoint Advanced Management capabilities, inactive-site policies, ownership policies, site attestations, data-access governance reports and policy-comparison reports can support this discovery layer.
VALIDATE
Request confirmation from the accountable owner, business representative, records team, compliance function or legal authority.
Validation should establish:
- Whether the site is still needed
- Who is responsible for it
- Whether its access remains appropriate
- Whether any content must be retained
- Whether another system depends on it
- Whether restoration may reasonably be required
CLASSIFY
Assign one primary disposition:
- Keep
- Archive
- Retain
- Restore
- Delete
Some sites may require combined controls. For example, a site may be archived while its content remains governed by retention requirements.
APPROVE
Record:
- Decision owner
- Business rationale
- Compliance assessment
- Technical dependencies
- Exceptions
- Approval date
- Review date
- Supporting evidence
EXECUTE
Apply the relevant operational control:
- Leave active and remediate
- Archive through Microsoft 365 Archive
- Apply or validate Purview retention
- Reactivate an archived site
- Restore a deleted site or backup
- Delete the site
- Confirm permanent disposition when eligible
REASSESS
Lifecycle governance must be continuous.
Use recurring inactivity policies, site-ownership policies, site attestations, permission reports and policy comparison to detect:
- Sites that become inactive
- Ownership gaps
- Permission drift
- External-sharing changes
- Retention conflicts
- Sites that no longer match their approved disposition
The strongest SharePoint lifecycle programme is not the one that deletes the greatest number of sites.
It is the one that makes the most defensible decisions.
Every site should have:
- A known purpose
- An accountable owner
- A justified access model
- A defined lifecycle state
- A recorded disposition decision
- Evidence explaining why that decision was made
The SharePoint Site Disposition Matrix converts uncontrolled site sprawl into a governed decision system—ensuring that operational knowledge remains available, historical value remains preserved, regulated information remains protected, recoverable content can be restored and obsolete data is defensibly deleted.

aakashrahsi.online
Top comments (0)