Skip to main content

Records Retention in the Age of Cloud, Collaboration Tools & Hybrid Work

Records Retention in the Age of Cloud, Collaboration Tools & Hybrid Work
By Steve Golden, CRM

Ask any records manager in the room when their retention schedule was last meaningfully updated, and the room goes quiet. Their reaction..and their pause, is the whole problem in a single moment.

Most retention schedules were built for a world that no longer exists. File cabinets. Shared drives. A defined, knowable set of repositories that Records Management actually knew about. Today, the records we're responsible for governing are scattered across Microsoft Teams, Slack, Google Workspace, SharePoint, OneDrive, and a roster of other platforms that were often procured without us in the room. According to the AIIM 2025 Industry Watch Report, roughly 80% of enterprise data now exists in unstructured formats. That's not a projection. That's today.

The Platform-Specific Challenges Are Real

Each major collaboration platform carries its own governance complexity, and they don't all behave the same way.

In Microsoft 365, Teams chats and files are actually two separate governance objects. Chats are stored in Exchange Online and require their own retention policies. Files shared in those same conversations live in SharePoint or OneDrive. Microsoft Purview is the unified governance framework that can address all of it — but only when configured deliberately. And here's something many practitioners may not have caught: legacy SharePoint in-place records management and Record Center site templates were deprecated in January 2025 and fully retired in April 2026. If your Microsoft governance approach relied on those features, that approach no longer exists. There's also the Copilot dimension: Microsoft Copilot surfaces all accessible content, which means redundant, obsolete, and trivial data isn't just a compliance liability anymore — it's a productivity one.

Slack, for example, presents a different kind of problem. Its native retention features are essentially binary at the channel level: preserve everything or preserve nothing. There's no granular, custodian-level hold capability natively. And individual users can set personal message deletion preferences that override organizational policy — a fact that tends to surprise practitioners when they first encounter it. Meanwhile, according to Everlaw's 2026 Guide to Slack eDiscovery, roughly 1 in 17 Slack messages contains PII or PHI. The governance stakes in that environment are not trivial.

Google Vault can govern Google Workspace, but it requires deliberate, intentional configuration. It does not govern itself.

The Hyperlink Problem

One of the most underappreciated gaps in collaboration governance is what I call the Hyperlink Problem. In Teams and Slack, documents are routinely shared as links rather than attachments. A Teams channel may have a Purview retention policy applied to it. A user posts a link to a SharePoint document. That document later gets deleted from SharePoint. The conversation is retained. The document it referenced is gone. Retaining the conversation and retaining the document are two completely separate governance acts, and most retention policies don't address both.

The Three-Party Standoff

Even when the technology exists to govern these platforms, organizational dynamics frequently get in the way. IT wants shorter retention to control storage costs and reduce security exposure. Legal wants longer retention to cover litigation risk. Records Management is trying to enforce what the schedule actually says. None of these positions is wrong — each group is optimizing for legitimate goals. But without a governance structure to resolve the tension, retention decisions default to whoever made the loudest argument at the last meeting.

The records manager's strategic value in this dynamic is as the convener — the person who can bring evidence-based, schedule-grounded policy to the table and hold it there. That's not a soft skill. That's the job.

What Defensibility Actually Requires

Three things need to happen organizationally. Retention schedules need to be updated to explicitly address collaboration platforms by name — not just "electronic records" as a catch-all. Legal hold processes need to be adapted for each platform, because placing a hold in Exchange Online does not place a hold in SharePoint, and neither covers Slack. And Records Management needs a seat at the procurement table before a new collaboration tool is deployed to thousands of employees.

That last point is worth sitting with. A program that acknowledges its gaps in writing is legally more defensible than one that claims to be comprehensive but isn't. Documented exceptions, evidence of reasonable effort, consistent application of written policy — that's what defensibility looks like in practice.

A defensible program isn't one that got everything right. It's one you can explain under oath.
As CRMs, this is precisely the territory our credential was designed to prepare us for. The platforms have changed. The obligation to govern them hasn't.