Rules for required documents
Together we describe which documents each type of client or case needs, and how often: monthly, yearly or once.
Document control checks that each client's or case's SharePoint folder holds its required monthly documents, reminds the person responsible about anything missing and files newly received documents into the right folders, all inside your Microsoft 365 tenant.
Missing documents · illustrative example
| Aug | Sep | Oct | |
|---|---|---|---|
| Client A | In | In | Missing |
| Client B | In | In | In |
| Case C | In | Missing | Missing |
| Case D | In | In | Missing |
Reminder to the person responsible
File received → text recognised → filed in its folder
01
The list of required documents usually exists already: contracts, orders, reports, permits. The hard part is making sure they land in the right folder every month. Folders are opened one by one, reminders are written by hand, and a gap shows up only when someone needs the document.
This is not a new document management system. Your documents stay where you keep them now; the check, the reminders and the filing work alongside.
02
Together we describe which documents each type of client or case needs, and how often: monthly, yearly or once.
File names, dates and locations are checked first. If a name does not fit, the app reads the PDF text, and reads scanned documents with text recognition inside your Azure subscription.
The app works out who is responsible from who has access to the client's or case's folder. Each person gets one email about their own clients only, with links to the folders and suggested standard names.
Files from a shared intake folder are moved to the right client, year and month folder and renamed to the standard. When the app is unsure, it leaves the file alone and asks.
One place showing which documents are missing, by client, month and person responsible.
03
The apps run in your Azure subscription, in an EU region. Each part gets only what it needs, and writing is kept apart from reading.
| Part | Permission | Why it is needed | Access |
|---|---|---|---|
| Check | Files.Read.All, Sites.Read.All and User.Read.All, or Sites.Selected (read on one site) and User.Read.All | Find missing documents and the person responsible | Read |
| Text recognition | Azure role “Cognitive Services User” on the Document Intelligence resource | Read the text of scanned PDFs without a key, with the same managed identity | Read |
| Filing | Sites.Selected with write on one documents site | Move and rename files on that site only | Write, one site |
| Reminders | Exchange “Application Mail.Send”, scoped to one shared mailbox | Send reminders from that mailbox only | Send, one mailbox |
Filing uses a separate identity from the check. The reminder app holds no Microsoft Graph permissions at all, only the Exchange right to send from one mailbox. In our test, an attempt to send as another person was refused (HTTP 403).
04
Measured on 2026-10-08 and 2026-10-09 in our own Microsoft 365 test environment with invented data; we planted the gaps and the untidy files on purpose. Checking by file name alone produced 2 false findings; after reading the text there were none. The results do not show how the check will work on your folders.
05
06
Something else on your mind?
Only when a file name does not match the expected document, and only inside your Azure subscription. The app reads the PDF text, or recognises the text of a scanned document, to work out the client, the document type and the month. We do not download your documents.
The check cannot: it has read rights only. Filing has write rights on one documents site only: it moves and renames files, but does not delete them or overwrite an existing file. In our test it skipped a file whose standard name was already taken.
Then the app reads its text, and recognises the text of a scanned document. In our test it recognised 0 of 3 such files by name alone, 2 of 3 after reading the PDF text, and 3 of 3 with text recognition.
From who has access to the client's or case's folder. In our test this identified the responsible person correctly for all 9 clients. If responsibility is recorded somewhere else in your company, such as a business system, we discuss it on the call.
Any document whose presence can be defined by a rule: monthly reports, contracts, orders, permits or certificates. Documents that are needed only in certain cases, such as after a new contract is signed, are harder to check: that needs data from your business system.
No. Your documents stay where they are in SharePoint, and people work as usual. The check, the reminders and the filing work alongside and help people keep to the rules you already have.
If your administrator grants read access across the organisation, the check sees personal OneDrives too. If read access covers one site only, personal OneDrives stay invisible and those clients are listed as not found. In our test, all 3 clients whose folders were in OneDrives were listed that way.