Orca IT Solutions

Data Management

Know where your data lives and who can see it

Most businesses cannot answer two basic questions: where is our sensitive data, and who has access to it. We build a file structure people can navigate, permissions granted by role, retention that is actually decided, and the data loss prevention basics that come with licenses you already own.

🛡 Role Based Access Retention Decided💰 Structure People Use DLP Basics Enabled

Overview

Structure is a productivity problem before it is a security one

When people cannot find the current version of a document, they make a new one. That is how a business ends up with a proposal template in five places, three of them wrong, and a shared drive where the top level has forty folders and no logic.

Good structure is not about tidiness. It is about reducing the number of decisions a person makes to find or save something. We design around how work actually flows through your business, by client, by project, by department, by year, whichever matches how your staff already think, and keep the top level small enough to scan. Then we agree naming conventions and where the boundary sits between personal OneDrive, team content and company-wide reference material.

Permissions that reflect reality

Almost every environment we assess has permission drift. Access granted to an individual during an urgent request in 2022, folders inheriting rights nobody intended, a group called Staff that includes two contractors and a former employee, and one folder everyone can reach because fixing it properly seemed hard at the time.

We rebuild permissions on role-based groups. Access is granted to a group, groups map to job functions, and joining or changing a role changes access automatically. Sensitive areas, payroll, HR files, client financials, medical records, get explicit restricted access with a documented list of who is in it. Then we run periodic reviews, because permissions drift again the moment nobody is watching. The identity side of this is covered on our Active Directory page.

Retention, and the cost of keeping everything

Most small businesses keep everything forever because nobody ever decided otherwise. That has three costs. It grows storage and backup expense every year. It makes finding anything harder. And in a dispute or a breach it expands your exposure, because data you no longer needed is still data you have to account for.

Retention is a business decision informed by regulation, not an IT preference. We work out what your industry requires you to keep and for how long, what you actually want to keep for practical reasons, and what should go. Then we implement it with retention policies in Microsoft 365 or on the file system, with archiving for anything that must be kept but does not need to be in the working set.

Data loss prevention basics come free with common Microsoft 365 tiers and are almost never enabled. Simple policies can flag or block a message containing what looks like a credit card number or a social security number, warn a user before they share a sensitive document externally, and log when a large volume of files is downloaded. That last signal is one of the more reliable early indicators of both a departing employee and a compromised account.

Shared drive or SharePoint is the question we get asked most, and the honest answer is that it depends on your files and your people. Large working files, CAD assemblies and video projects still favor local storage. Documents, spreadsheets and anything collaborative favor SharePoint, which brings versioning, co-authoring and access without a VPN. Many clients end up with both, deliberately. Our Microsoft 365 page and microsoft365.orcait.io cover the platform, and moving between them is on data migration.

If people cannot find the current version in two clicks, they will make a sixth copy of it.Orca IT, Gilbert AZ

What We Do

Data management engagements

Six pieces of work, usually delivered together as a single project.

Map

Data discovery

Where files actually live, including the local desktops, personal drives and shadow cloud accounts that were never part of the plan.

Structure

File architecture

A top level people can scan, naming conventions, and clear boundaries between personal, team and company-wide content.

Access

Permission rebuild

Role-based groups replacing individual grants, restricted areas for sensitive content, and a documented access model.

Retention

Retention and archiving

What to keep, for how long, and where. Implemented in policy rather than left as an unwritten assumption.

DLP

Data loss prevention basics

Policies that flag sensitive data leaving the business, warn on external sharing and alert on unusual bulk downloads.

Review

Periodic access review

Scheduled checks that group membership still matches your staff list and that nobody has accumulated access they no longer need.

Shared drive or SharePoint, by content type

ContentBetter homeReason
Documents and spreadsheetsSharePointVersioning, co-authoring and access without a VPN
Large CAD or video filesLocal storageLatency and file size make cloud editing painful
Personal working filesOneDriveIndividually owned, recoverable, transfers cleanly when someone leaves
Department recordsSharePoint sitePermissions map to a group rather than a folder tree
Application dataServerDatabases and line-of-business software expect local storage
Archive and old projectsArchive storageKept for obligation, out of the working set, cheaper to store

How It Works

From sprawl to structure

01

Discover

We map every location holding business data, including local machines and personal cloud accounts nobody declared, and measure volume and age.

02

Design

A structure built around how your work flows, with naming conventions, a permission model by role and a retention decision per data type.

03

Migrate and apply

Content moved into the new structure, duplicates resolved, permissions applied through groups, retention and DLP policies switched on.

04

Review

Scheduled access reviews and a short internal guide so new staff learn the structure instead of inventing their own corner of it.

Structure before migration

Copying a messy drive into SharePoint gives you a messy SharePoint that is harder to fix. Design first, move second.

Get a Free Assessment

Data management questions

Should we move our shared drive to SharePoint?

For documents and collaborative files, usually yes, because you gain versioning, co-authoring and access without a VPN. For large working files such as CAD assemblies and video, local storage is still faster and less frustrating. Many businesses end up with both, split deliberately by content type.

How long should we keep old files?

Long enough to satisfy your industry obligations and your practical needs, and no longer. Keeping everything forever costs storage, makes searching harder and increases what you have to account for in a dispute or breach. We help you set a policy per data type rather than defaulting to infinite.

How do we find out who has access to what?

We export effective permissions across your shares and SharePoint sites and reconcile them against your staff list and job roles. The common findings are direct grants to individuals, groups containing people who left, and inherited permissions that were never intended.

What is data loss prevention and do we need it?

DLP policies detect sensitive information such as card numbers or social security numbers and can warn or block when it leaves the business. Basic policies are included in common Microsoft 365 tiers. For any business handling financial, medical or client personal data, the basics are worth switching on.

Our folder structure is chaos. Where do we start?

With discovery and a design, not with moving files. Map where everything is, agree a top-level structure around how work flows, decide the personal versus team boundary, then migrate into it. Reorganizing in place while people are working is the version that fails.

How do we handle sensitive folders like payroll or HR?

Explicit restricted access with a named group, inheritance broken so nothing leaks in from a parent folder, access reviewed on a schedule, and alerting on access changes. Sensitive areas should never rely on being buried deep in a tree that everyone can technically browse.

What about files on people's desktops?

That is usually the largest gap we find, and it is both a backup risk and a security one. We redirect known folders to OneDrive so desktop and documents content is protected and recoverable automatically, then work through the local files that never made it to a share.

Can you do this for a business outside Arizona?

Yes. Discovery, design, permission work, retention and migration are all remote tasks, so we deliver data management for clients across all 50 states. Only physical storage changes need someone in the room, which for us means the Phoenix metro.

Map your data before you move it

Where it lives, who can reach it, and what should have been archived years ago.

Talk to Your Pod

Talk to Your Pod

Can you say who can open the payroll folder?

A data review maps where your files actually live, who has access to each area, what is duplicated and what should have been deleted years ago. It is usually the first step toward a structure people stop fighting.

(602) 677-0779

Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced

Same-day response No long contracts Flat, honest pricing Five-star service

Get your free IT consultation

A few details and your pod gets right back to you, usually the same business day.

Spam-protected with a quick CAPTCHA. Your message goes straight to our team in Gilbert. We only use your details to help with your request. Never sold, never shared.