Data discovery
Where files actually live, including the local desktops, personal drives and shadow cloud accounts that were never part of the plan.
Data Management
Most businesses cannot answer two basic questions: where is our sensitive data, and who has access to it. We build a file structure people can navigate, permissions granted by role, retention that is actually decided, and the data loss prevention basics that come with licenses you already own.
Overview
When people cannot find the current version of a document, they make a new one. That is how a business ends up with a proposal template in five places, three of them wrong, and a shared drive where the top level has forty folders and no logic.
Good structure is not about tidiness. It is about reducing the number of decisions a person makes to find or save something. We design around how work actually flows through your business, by client, by project, by department, by year, whichever matches how your staff already think, and keep the top level small enough to scan. Then we agree naming conventions and where the boundary sits between personal OneDrive, team content and company-wide reference material.
Almost every environment we assess has permission drift. Access granted to an individual during an urgent request in 2022, folders inheriting rights nobody intended, a group called Staff that includes two contractors and a former employee, and one folder everyone can reach because fixing it properly seemed hard at the time.
We rebuild permissions on role-based groups. Access is granted to a group, groups map to job functions, and joining or changing a role changes access automatically. Sensitive areas, payroll, HR files, client financials, medical records, get explicit restricted access with a documented list of who is in it. Then we run periodic reviews, because permissions drift again the moment nobody is watching. The identity side of this is covered on our Active Directory page.
Most small businesses keep everything forever because nobody ever decided otherwise. That has three costs. It grows storage and backup expense every year. It makes finding anything harder. And in a dispute or a breach it expands your exposure, because data you no longer needed is still data you have to account for.
Retention is a business decision informed by regulation, not an IT preference. We work out what your industry requires you to keep and for how long, what you actually want to keep for practical reasons, and what should go. Then we implement it with retention policies in Microsoft 365 or on the file system, with archiving for anything that must be kept but does not need to be in the working set.
Data loss prevention basics come free with common Microsoft 365 tiers and are almost never enabled. Simple policies can flag or block a message containing what looks like a credit card number or a social security number, warn a user before they share a sensitive document externally, and log when a large volume of files is downloaded. That last signal is one of the more reliable early indicators of both a departing employee and a compromised account.
Shared drive or SharePoint is the question we get asked most, and the honest answer is that it depends on your files and your people. Large working files, CAD assemblies and video projects still favor local storage. Documents, spreadsheets and anything collaborative favor SharePoint, which brings versioning, co-authoring and access without a VPN. Many clients end up with both, deliberately. Our Microsoft 365 page and microsoft365.orcait.io cover the platform, and moving between them is on data migration.
If people cannot find the current version in two clicks, they will make a sixth copy of it.Orca IT, Gilbert AZ
What We Do
Six pieces of work, usually delivered together as a single project.
Where files actually live, including the local desktops, personal drives and shadow cloud accounts that were never part of the plan.
A top level people can scan, naming conventions, and clear boundaries between personal, team and company-wide content.
Role-based groups replacing individual grants, restricted areas for sensitive content, and a documented access model.
What to keep, for how long, and where. Implemented in policy rather than left as an unwritten assumption.
Policies that flag sensitive data leaving the business, warn on external sharing and alert on unusual bulk downloads.
Scheduled checks that group membership still matches your staff list and that nobody has accumulated access they no longer need.
| Content | Better home | Reason |
|---|---|---|
| Documents and spreadsheets | SharePoint | Versioning, co-authoring and access without a VPN |
| Large CAD or video files | Local storage | Latency and file size make cloud editing painful |
| Personal working files | OneDrive | Individually owned, recoverable, transfers cleanly when someone leaves |
| Department records | SharePoint site | Permissions map to a group rather than a folder tree |
| Application data | Server | Databases and line-of-business software expect local storage |
| Archive and old projects | Archive storage | Kept for obligation, out of the working set, cheaper to store |
How It Works
We map every location holding business data, including local machines and personal cloud accounts nobody declared, and measure volume and age.
A structure built around how your work flows, with naming conventions, a permission model by role and a retention decision per data type.
Content moved into the new structure, duplicates resolved, permissions applied through groups, retention and DLP policies switched on.
Scheduled access reviews and a short internal guide so new staff learn the structure instead of inventing their own corner of it.
Copying a messy drive into SharePoint gives you a messy SharePoint that is harder to fix. Design first, move second.
For documents and collaborative files, usually yes, because you gain versioning, co-authoring and access without a VPN. For large working files such as CAD assemblies and video, local storage is still faster and less frustrating. Many businesses end up with both, split deliberately by content type.
Long enough to satisfy your industry obligations and your practical needs, and no longer. Keeping everything forever costs storage, makes searching harder and increases what you have to account for in a dispute or breach. We help you set a policy per data type rather than defaulting to infinite.
We export effective permissions across your shares and SharePoint sites and reconcile them against your staff list and job roles. The common findings are direct grants to individuals, groups containing people who left, and inherited permissions that were never intended.
DLP policies detect sensitive information such as card numbers or social security numbers and can warn or block when it leaves the business. Basic policies are included in common Microsoft 365 tiers. For any business handling financial, medical or client personal data, the basics are worth switching on.
With discovery and a design, not with moving files. Map where everything is, agree a top-level structure around how work flows, decide the personal versus team boundary, then migrate into it. Reorganizing in place while people are working is the version that fails.
Explicit restricted access with a named group, inheritance broken so nothing leaks in from a parent folder, access reviewed on a schedule, and alerting on access changes. Sensitive areas should never rely on being buried deep in a tree that everyone can technically browse.
That is usually the largest gap we find, and it is both a backup risk and a security one. We redirect known folders to OneDrive so desktop and documents content is protected and recoverable automatically, then work through the local files that never made it to a share.
Yes. Discovery, design, permission work, retention and migration are all remote tasks, so we deliver data management for clients across all 50 states. Only physical storage changes need someone in the room, which for us means the Phoenix metro.
Where it lives, who can reach it, and what should have been archived years ago.
Talk to Your Pod
A data review maps where your files actually live, who has access to each area, what is duplicated and what should have been deleted years ago. It is usually the first step toward a structure people stop fighting.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.