Saturday, October 3, 2026

Where Should a Shared Document Live? A Data Governance Worked Example

Choosing where a document is stored does not decide who may use it, how long it should remain, or who manages those decisions.

Follow one hypothetical project draft from its storage choice through access, retention, and responsibility.

Data center fundamentals series

Does choosing a storage location settle the policy?

No. Suppose a project team needs to share a meeting draft. A shared file store on the organization’s network and an off-site cloud file service are both possible ways to make files available for collaboration. For this hypothetical example, the team chooses the cloud service—not as a recommendation, but to see what decisions remain.

A data center may restrict entry to its building and equipment areas. Those physical controls do not decide who may open this particular draft or when it should stop being kept.

The Fiber Optic Association — The FOA Reference For Fiber Optics - Data Centers -

IBM — What Is Cloud Storage? | IBM

IBM — What Is Data Storage? | IBM

Who may read or change the draft?

Assume team members need to edit the draft, while an external reviewer only needs to read it. The team must distinguish viewing from editing and name someone to approve the reviewer’s access. Whether those permissions can be configured separately depends on the chosen service and must be checked there.

Access also needs a review point. When the external review ends, the person responsible can decide whether the reviewer still needs access, then check the actual permission and how to change it. The team should not assume that the service removes access automatically.

Why keep the draft, and what happens to copies?

The team first needs to decide whether this is a working draft needed only for review or a record that must remain afterward. That purpose informs its retention condition; a general description of data storage cannot supply a legal retention period or deletion date for this hypothetical document.

If the organization uses backups or immutable snapshots, it must consider those copies separately. A backup provides a copy for recovery after data loss. An immutable snapshot is a point-in-time copy protected from change or deletion for a set or indefinite period.

Neither type of copy can be assumed to exist for this draft, and deleting the original cannot be assumed to delete its copies. The team must check its actual storage and retention settings.

Does the cloud provider take over these decisions?

Not under the general responsibility split IBM describes: the provider manages and secures the underlying cloud infrastructure, while the customer is responsible for securing its data and applications within it. In this example, the team still needs an internal owner for sharing approvals, permissions, and retention decisions.

The exact division of duties must be checked against the service and contract rather than inferred from where the file is stored.

What would the team record for this document?

The hypothetical team can turn the discussion into a short decision record. The middle column shows a proposed decision for this example, not a setting or rule that applies to every organization.

Storage

Hypothetical team record
Put the draft in the chosen cloud file service
Check before using it
Confirm the service and its available settings

Access

Hypothetical team record
Team members edit; the external reviewer reads; a named team owner approves access
Check before using it
Confirm that these permissions can be set and who currently has access

Access review

Hypothetical team record
Reconsider the reviewer’s access when the review ends
Check before using it
Confirm how to inspect and change that access

Retention and copies

Hypothetical team record
Decide whether the draft is needed after review; address any backups or snapshots separately
Check before using it
Check applicable obligations and the service’s retention and deletion behavior

Responsibility

Hypothetical team record
Assign an internal owner for sharing, access, and retention decisions
Check before using it
Check the service and contract for the actual provider–customer split

The useful result is not a universal retention period or a preferred storage location. It is a set of decisions the team can assign and verify: where the file lives, who can use it, why it remains, what copies may remain, and who is accountable for each answer.

Sources

Related reading