Purview

Classification, protection and retention that are actually switched on, in an order that does not stop the business.

Engagement

Assessment + implementation. Rolled out in phases: pilot, simulation, then enforcement.

Who it is for

IT, security, privacy and records owners — and the executive who signed a policy that nothing currently enforces.

When people call us

A label scheme exists on paper and nowhere else, DLP has been in simulation for a year, retention is unassigned, or Copilot has made data protection urgent.

Purview is the part of the Microsoft estate most often bought, designed, and never switched on. A label taxonomy gets agreed in a workshop, DLP goes into simulation mode so nobody is disrupted, retention waits on a records decision that never comes, and eighteen months later the tenant is exactly as protected as it was before.

Simulation is where deployments go to stall

Simulation mode is the right first step and the wrong permanent state. It produces reports nobody owns, and it lets everyone believe the control exists. The work that moves a policy to enforcement is unglamorous: tune against real traffic, deal with the false positives, tell the affected teams what will change, then turn it on for a defined scope.

A label scheme people can actually use

Most schemes fail for the same reason: too many labels, drawn from a classification standard rather than from how people describe their own work. Three or four, clearly different from each other, with an obvious answer for the common case — and auto-labelling to catch what people do not tag themselves.

This is the layer under Copilot

Whether an assistant can surface a document is decided by permissions and labels. A Copilot rollout without this work does not fail loudly, it fails quietly, by answering someone’s question with a document they should never have seen. That is why we sequence labelling and permission remediation ahead of enablement rather than beside it.

Policy on paper and nothing enforcing it? Bring it to a briefing.

How far a deployment actually got

Designed, applied, enforced, watched.

Most Purview deployments stop at the second rung and are described as if they reached the fourth.

  1. 01Designed

    A label taxonomy agreed in a workshop. Real work, and worth nothing on its own.

  2. 02Applied

    Labels on content, mostly by rule rather than by hope, because manual tagging covers a fraction of an estate.

  3. 03Enforced

    DLP out of simulation for a defined scope, false positives dealt with first, affected teams told what changes.

  4. 04Operated

    Someone owns the alerts, tunes the policy, and fixes a label that is wrong. This is where deployments fail quietly.

The practice

01

Where you actually are

What is licensed, what is configured, what is enforced, and what is running in a mode that reports but does nothing.

02

Sensitivity labels

A scheme with three or four labels people can choose between without reading a manual, and what each one does to a document once applied.

03

Auto-labelling

Labels applied by rule rather than hope — client-side and service-side — because a scheme that depends on people remembering is a scheme that covers a fraction of the estate.

04

Data loss prevention

Policies tuned against your own traffic, moved out of simulation deliberately, with the false positives dealt with before enforcement rather than after the complaints.

05

Retention and records

Retention labels and policies mapped to the information architecture, so a policy applies to the estate rather than to a diagram of it.

06

Classification tuning

Sensitive information types and trainable classifiers adjusted to your content. Out-of-the-box classifiers generate noise that nobody will keep reading.

07

Protecting what Copilot can reach

Labels and permissions are what decide whether an assistant can surface a document. This is the control layer under a Copilot rollout, not a parallel project.

08

eDiscovery and audit

Search, hold and export that work when they are needed, verified before they are needed.

09

Ownership and operation

Who reviews alerts, who adjusts policy, and what happens when a label is wrong. Purview fails as an unowned deployment more often than as a configuration.

What you keep

The code and the data·Your existing relationships·Approval and control·The ability to stop·The off switchWhat that means

Start with a 45-minute briefing.

No pitch. We’ll map your situation against what actually works and tell you honestly where to start.