People-First Purview (Strategy): Records Management
- E.C. Scherer
- Jun 6
- 4 min read
Records Management is a communication problem before it's a compliance problem.
Most records management programs I encounter are technically functional and operationally invisible.
The retention labels exist. The policies are configured. The compliance team signed off. And the people whose files are actually being governed have no idea any of it is happening. Until something disappears.
That's the failure mode nobody plans for.
We spent the last two posts working through Data Lifecycle Management: what it does, how to configure it, when to reach for retention policies versus retention labels.
If you haven't read those, start there. This post builds on that foundation, but it shifts from mechanics to something harder to configure.
Shared understanding.
Records management requires people to make decisions.
The Difference Nobody Explains
DLM and records management live in the same part of the Purview compliance portal. They share vocabulary. They share configuration surfaces. So it's understandable that most organizations treat them as the same thing with different settings.
They aren't.
DLM is largely automatic. You define what happens to content based on age, location, or label, and Purview handles it. The user doesn't need to do anything. In many cases, the user doesn't know a retention policy exists.
Records management requires human judgment at the end of the lifecycle. When a retention label marks something as a record and the retention period expires, someone has to decide whether to delete it, keep it longer, or transfer it. That decision point is called disposition review.
It only works if the person doing the review understands what they're deciding.
Most of the time, they don't.
I've seen disposition review queues sit untouched for months. Not because the reviewers were negligent, but because nobody ever explained what a disposition review was, why it was in their queue, or what the stakes were. They opened the interface, saw a list of file names and retention labels they didn't recognize, and closed it.
The policy worked. The user experience was not what anyone intended.
Mandatory Brain Break

Calliope Hummingbird / Selasphorus calliope
The smallest breeding bird in North America, and one of the longest migratory journeys relative to body size of any bird on the continent. This one is hovering with wings fully extended, likely assessing a feeding site before committing. At rest, the magenta streaks on a male's gorget look almost brown until the light catches them right.
Records Are a Commitment
When you declare something a record in Purview, you're making a specific promise.
This content will be preserved. It won't be modified. At the end of its retention period, someone will make a deliberate decision about its fate.
That's different from "we kept this file for seven years and then deleted it." The distinction matters for legal holds, for audit defensibility, and for regulated industries where the difference between a retained file and a declared record is the difference between passing an audit and explaining yourself to a regulator.
It also matters because records carry user-visible restrictions. A record can't be edited. In some configurations, it can't be moved. Users who encounter a file they can't edit, without any context about why, will either panic or route around it.
Neither response helps anyone.
One licensing note before moving on: as of this blog post, records management in Purview requires Microsoft 365 E5 or the E5 Purview add-on.
Designing for the Reviewer, Not the Auditor
Disposition review is where records management programs succeed or collapse. Most programs are designed for the auditor.
The auditor wants to see that a process exists. The reviewer needs to understand what they're deciding. Those are different design requirements.
An auditor is satisfied by a queue with entries and a completion rate. A reviewer needs to know: what is this file, why is it in my queue, what does it mean to approve disposition, and what happens if I get it wrong?
None of that context comes from Purview. You have to build it, in training, in documentation, in the label names themselves.
A retention label called "Legal - 7yr - Record" is more useful to a reviewer than one called "RL-LEGAL-007."
The other thing reviewers need is a clear answer to the question they won't ask out loud: what happens if I approve deletion of something I shouldn't have? That fear, left unaddressed, is why queues go untouched. If reviewers don't know the answer, they default to doing nothing.
Doing nothing in a disposition queue is not safe. It just delays the same decision indefinitely.
Mandatory Brain Break

American Black Bear / Ursus americanus
She had three cubs with her. When my car appeared, the cubs went one direction, and she held eye contact for several seconds before running in the other direction. She wasn't fleeing. She was redirecting.
Fun fact: Black bears in the Rockies are frequently brown, cinnamon, or blonde!
Before You Touch the Portal
The most common mistake in records management rollouts is starting in the compliance portal.
Before you configure a single retention label as a record, you need answers to three questions.
What content qualifies as a record in your organization, and for which regulatory framework?
Who is responsible for disposition review, and do they have enough context to do it?
What happens operationally when a user encounters a file they can't edit?
If you can't answer those, you're not ready to configure records management. You're ready to have a conversation with Legal, HR, and whoever owns your business continuity program.
That conversation is harder than opening the portal. It's also the only thing that makes the portal useful.
The next post covers the mechanics: structuring retention labels for records, configuring disposition review workflows, and where adaptive scopes help versus where they add complexity. But the mechanics only matter if the program behind them was designed for the people who have to live with it.