Your input shapes our product. Suggest a feature now →
  1. Home
  2. Use Cases
  3. Manufacturing SharePoint Compliance Prep

SharePoint Compliance Prep: A Manufacturing IT Case Study

Published: 3 July 2026  |  Category: Compliance and Governance

Six weeks before an ISO recertification audit, the IT Manager at a 180-person precision manufacturing firm discovered that their SharePoint environment had a version history problem, a stale permissions problem, and a storage problem. Here is how they resolved all three in four working days.

Problem What was found Tool used Outcome
Version history bloat on quality document libraries 280 GB of a 340 GB site footprint was version history accumulated over 6 years Space Master Version Trimmer 260 GB reclaimed; version count per file trimmed to 30
Stale edit access from former staff 3 former quality managers still held Contribute permissions on controlled document libraries Report Master All 3 accounts identified via permissions export and removed in SharePoint; clean export provided to auditor
Mixed live and archived project content 6 project libraries contained completed-project files mixed with active quality records Space Master Bulk Delete + Recycle Master Completed-project folders moved to archive site; recycle bins cleared

Meet Callum, IT Manager at Hartwell Precision

Hartwell Precision manufactures engineered components for the aerospace and automotive sectors. Their 180 employees work across two facilities, and the company holds an ISO 9001 quality management certification that undergoes external audit every three years.

Callum joined Hartwell as IT Manager two years ago, inheriting a Microsoft 365 tenant that had been running without a dedicated IT resource for most of its life. SharePoint had been in use for six years: quality procedures, work instructions, inspection records, and supplier documentation all lived there. Versioning had been enabled from day one and had never been reviewed. Permissions had been granted during onboarding for dozens of former staff and never revoked.

When the quality team flagged the upcoming ISO recertification to Callum six weeks before the audit date, the question on the table was not whether SharePoint was ready. It clearly was not. The question was how much of the backlog he could clear in the time available.

What the audit requirement actually asked for

ISO 9001 auditors checking a document management system look for three things at minimum: evidence that controlled documents have an auditable version history, confirmation that only authorised personnel can modify quality-controlled content, and a demonstrable process for separating live controlled documents from superseded or archived versions.

Hartwell's SharePoint environment was theoretically capable of meeting all three requirements. The practical problem was that years of unchecked configuration meant the evidence trail was buried in noise: 400-version histories where the auditor would need to find the 12 meaningful revisions, permissions lists that still included former staff, and active document libraries mixed with completed project content from engagements that had ended two and three years ago.

When should you clean up SharePoint before a compliance audit?

The answer depends on your situation. Clean up before the audit when:

  • Version histories have grown beyond 50 versions per file on average, making them hard to navigate for reviewers.
  • Any former employee or contractor still has edit access to controlled document libraries.
  • Active, controlled content is mixed in the same libraries as completed, superseded, or project-specific files.
  • Your storage utilisation report shows that version history is consuming the majority of quota on the quality management site.
  • You cannot produce a current permissions report showing exactly who has what access within a few minutes of being asked.

If any of those conditions apply, cleaning up before the audit is not optional. A clean environment gives the auditor a clear evidence trail; a messy one requires you to explain every discrepancy.

Note: Cleaning up SharePoint before an audit is not the same as deleting audit evidence. The goal is to remove noise (stale permissions, excessive old versions, orphaned project content) while preserving the meaningful record (significant version milestones, current authorised access, live controlled documents). Always ensure the current version of every controlled document is intact before trimming historical versions.

What the data revealed

The version history picture

Callum ran a storage utilisation report using Report Master and exported the results to Excel. The quality management site showed 340 GB total storage consumed. Breaking it down by library:

  • The Quality Procedures library (820 documents): 38 GB current files, 160 GB version history.
  • The Inspection Records library (2,100 documents): 14 GB current files, 82 GB version history.
  • The Supplier Documentation library (640 documents): 8 GB current files, 36 GB version history.
  • Three project libraries (combined): 2 GB current files, 0.4 GB version history.

The three primary quality libraries accounted for 280 GB of version history for 60 GB of current content. The version limit on each library was set to 500 - the SharePoint default, never changed. Files in the Quality Procedures library averaged 194 versions each.

The permissions picture

The Report Master permissions export showed every user with access to each quality library. Scanning against the current Entra ID user list, Callum identified three accounts belonging to former quality managers who had left Hartwell 8 to 18 months ago. All three held Contribute access on the Quality Procedures library, meaning they could still edit controlled document content if their accounts had not been disabled. Two of the three accounts were still active in Entra ID because the offboarding process had not included a SharePoint permissions step.

The cleanup: four days of work

With a clear picture of what needed fixing, Callum planned four targeted actions.

Day 1: Version trim on the Quality Procedures library. Using Space Master's Version Trimmer, he set a keep policy of 30 versions per file and deleted all versions older than two years beyond those 30. The policy ran overnight and reclaimed 142 GB from the Quality Procedures library alone. The remaining 18 versions per file on average were the meaningful milestones: annual policy review revisions, change-controlled amendments, and recently active edits.

Day 2: Version trim on Inspection Records and Supplier Documentation. The same keep policy ran across both libraries and reclaimed a further 98 GB. The Inspection Records library presented a specific pattern: inspection records from completed jobs had accumulated versions because templates were being edited in-place rather than copied. Callum flagged this to the quality manager as a process change for the future.

Day 3: Permissions cleanup and stale account removal. Using the Report Master permissions export to confirm exactly which accounts held stale access, Callum removed the three former quality managers from all library permission groups directly through the SharePoint admin center. He re-ran the Report Master permissions export after the removal to produce a clean, current view of who holds access to each library. That export became the permissions evidence document for the auditor.

Day 4: Project content separation. The six project libraries contained completed-project content mixed alongside active quality records because project teams had used the quality site as a convenient place to store working files. Callum used Space Master's Bulk Delete to remove files from completed projects that had no ongoing relevance, and moved others to a dedicated archive site using ShareMaster's Copy To feature. Callum cleared the quality site's recycle bin with Recycle Master once all moves were confirmed. For more on the approach to SharePoint permissions evidence, see the guide to exporting SharePoint permissions to Excel.

What Callum presented to the auditor

At the audit, Callum had three documents ready:

  • A Report Master permissions export showing every current user with access to each quality library, their permission level, and whether that access was directly assigned or inherited. The auditor asked who had edit access to the Quality Procedures library. Callum showed the filtered Excel row in under 30 seconds.
  • A version history sample for three selected controlled documents, showing the version dates, version numbers, and a brief description of the change reason from the file's version comment field. The histories were clean enough to read: 18 to 22 meaningful entries rather than the 190+ they had carried the previous month.
  • A site structure diagram showing the separation between the live quality management site and the archive site, demonstrating that superseded and completed-project content had been moved out of the controlled document environment.

The audit passed. The auditor noted the clear permissions structure and the version history evidence as positive indicators of document control maturity.

Total storage reclaimed: 260 GB. Stale permissions removed: 3. Time to complete: 4 working days.

Learn more about Space Master's Version Trimmer

Try ShareMaster free for 14 days