Start every workspace from a template
Every workspace starts as a request against a template your IT team owns. The template fixes the naming convention, visibility, owners, channels and apps, and names the approvers. Requesters fill it in from the Rencore Teams app, and IT only steps in when the approval asks for it. See Microsoft 365 provisioning for the template builder.
Keep a named owner on every workspace
Policies flag Teams without owners, with fewer than two owners, or whose owners have left and had their accounts disabled. Scheduled reviews then ask each owner in Microsoft Teams to confirm, remove or reassign access, and every decision is logged with a reason, so the auditor gets a record rather than a completion percentage.
Archive what nobody uses, and ask the owner first
The Inactive teams policy finds teams with no message posted and no SharePoint content changed in six months. An automation can archive them straight away, or first ask the owner in Teams whether the workspace is still needed. The Archive Microsoft Team automation also sets the SharePoint site to read-only, and deletion can wait for an approval whenever you want a person to sign off.
Remove guests once the project ends
Policies list the Teams that contain external users and the ones whose external members have not signed in for more than six months. Owner reviews show guests inline with the members, so the person who knows the project removes the guests who no longer need access. An automation can also mark every team with external users in its title.
Catch business-critical flows that stop
The lifecycle also covers the automations your business runs on. The Stopped Flows policy lists every Power Automate flow that has stopped, and notification rules email all owners, all admins or named recipients when a policy is violated or an automation fails.
Common questions about the Microsoft 365 workspace lifecycle
Which tools automate the Microsoft 365 workspace lifecycle?
Microsoft covers single stages natively, and a governance platform connects them. Rencore Governance runs the whole chain for Teams, SharePoint sites and Microsoft 365 Groups: requests from templates with approvals, owner reviews inside Microsoft Teams, policies that find ownerless or inactive workspaces, and automations that archive or delete them, with an approval step wherever you want a person to sign off.
What do Microsoft Entra, Purview and SharePoint Advanced Management already cover?
Each covers a real part of it. Microsoft Entra can expire and delete Microsoft 365 groups that are neither used nor renewed by their owners and, with Entra ID Governance licensing, reviews group membership and guest access. SharePoint Advanced Management runs site ownership, inactive site and site attestation policies: it counts activity in Teams, Exchange and Viva Engage as well as SharePoint, notifies owners, and can set inactive sites to read-only and archive them after a read-only period with Microsoft 365 Archive. Purview retains, deletes and labels the content itself. What stays open is the process from request to archive across Teams, groups and sites, an owner workflow inside Teams, and one policy set across workloads, which is the layer Rencore Governance adds on top.
How does Rencore Governance find workspaces nobody uses?
With policies that run on every scan. The Inactive teams policy lists teams with no message posted and no SharePoint content changed in six months, and a review template targets SharePoint sites last used more than 30 days ago. An automation then archives the team, or first asks the owner in Microsoft Teams whether to keep the workspace or let it be archived.
What happens when a workspace loses its owner?
Policies flag it. Teams without owners, with fewer than two owners, with a disabled owner account or with only disabled owner accounts each show up as violations, so a leaver does not leave an orphaned workspace behind. An owner review or an automation then puts a new owner in place, and every decision is logged with the reviewer's reason.
Can archiving or deletion wait for an approval?
Yes. The Archive Microsoft Team and Delete Microsoft Team automations each come in a variant that sends an approval request to a designated approver and acts only once it is granted; if the request is rejected, the team stays as it is. The Archive Microsoft Team automation also sets the team's SharePoint site to read-only, and the delete automation emails the team owner before anything is removed.
How are guests handled across the lifecycle?
Policies list the Teams that contain external users and those whose external members have not signed in for more than six months, and an automation can mark teams with external users in their title. Owner reviews show guests inline with the members, so the person who knows the project removes the guests who no longer need access.
How do I find out when a business-critical flow breaks?
Through policies and notifications. The Stopped Flows policy lists every Power Automate flow that has stopped, and notification rules for lost consent, automation errors and automation thresholds email all owners, all admins or named recipients, so the person responsible hears about it before the business does.