Services
Products
ExpireIQ Samyak Why Us About Insights Book a Demo
A Paras InfoGov Product

ExpireIQ

Govern your Microsoft 365 content from the day it lands
to the day you can prove you destroyed it.

Two modules, one lifecycle. Governance tells you who owns each site, who can reach it, and where retention does not apply. Disposition review handles what happens when that content expires.

You cannot defensibly dispose of a site nobody owns. That is why both live in one product.

Per site reviewers Your Azure tenant Unlimited sites & reviewers Deploys in one session
The Shape Of The Problem

What happens to content,
and where it goes wrong

Four stages. Most tools cover one.

1

Content lands

Sites and files accumulate continuously. Nobody is watching the shape of it.

2

Is it governed?

Who owns it. Who can reach it. Whether retention applies. Most estates cannot answer.

3

ExpireIQ answers

Scanned evidence, not assumption. Findings arrive in a queue you work through.

4

Content expires

The right people review it. Afterwards you can prove what was destroyed.

Governance is what makes disposition defensible.

A disposal decision is only as good as what you know about the site it came from.

Why This Matters Now

Copilot answers from
whatever it can reach

Two problems stall a rollout. Neither is about licensing.

It reaches what nobody meant to share

Copilot respects your permissions. That is the problem. The site opened to everyone three years ago, the anonymous link made for a supplier, the unlabelled site. All fair game.

Those permissions were survivable when you had to know content existed to find it. Copilot removes that step.

ExpireIQ finds those sites before your users do.

It quotes what should have been destroyed

Expired content is still indexed. Copilot will cite a superseded policy or a revoked decision with exactly the same confidence as current content.

Your disposition backlog is now an AI accuracy problem.

11

governance checks. Several map straight onto the conditions that make a Copilot rollout unsafe: oversharing, anonymous links, guest access, unlabelled sites.

ExpireIQ does not integrate with Copilot. It governs what Copilot reads, which is where the risk actually sits.

Two Modules, One Platform

Know what you hold.
Then dispose of it defensibly.

Content sitting open with no owner. Content that expired years ago and is still there. Most organisations have both.

Module One

Governance

A continuous read of your SharePoint estate: who owns what, who can reach what, and where your retention programme has gaps you did not know about.

  • Ownerless and single owner sites, resolved to real people
  • EEEU oversharing detected directly and inside permission groups
  • Anonymous and organisation wide links inventoried and matched to files
  • Retention coverage gaps, meaning sites with no labelled content at all
  • Guest access and inactive sites across every site collection
  • Configurable thresholds and severities for every check
Module Two

Disposition Review

Purview flags content when it reaches retention expiry. ExpireIQ runs the review that follows, routing it to the right people, enforcing sign off, and leaving evidence behind.

  • Per site reviewers so each department only sees its own content
  • Up to five sequential stages before anything is disposed of
  • Archive instead of delete to Azure Blob Storage in your tenant
  • Read only file preview without granting SharePoint access
  • Metadata retained permanently as proof of disposition
  • Upcoming expiry dates for every file in a reviewer's sites
The part no other tool can do.

Because ExpireIQ indexes retention labels at file level for disposition review, its governance findings can join the two together. Not "this site has no owner" and separately "this site has an anonymous link". It is this site holds 900 files labelled as records, has no accountable owner, and one of them is shared with anyone who has the link. That is a compliance conversation, not a hygiene report.

Module One

Find what has quietly gone wrong

Sites outlive the people who created them. Sharing links outlive the projects that needed them. ExpireIQ scans your estate continuously and reports what needs attention, with thresholds and severities you control.

Ownership

Ownerless sites, resolved to real people

ExpireIQ expands every group in a site's Owners list, including Microsoft 365 group owner and member claims and nested security groups, then excludes disabled accounts, guests and service principals. A site can list an owner and still have nobody accountable.

Ownership

Single owner sites

One owner is one resignation away from an ownerless site. ExpireIQ flags sites below your configured minimum, so single points of failure surface before they become orphans.

Ownership

It explains itself

When a site owner disputes a finding, the detail panel shows exactly why: which principals were examined, which resolved to nobody, and the reason, whether that is an empty group, a disabled account, an external user or a service principal.

Oversharing

Everyone Except External Users detection

The EEEU claim grants access to every internal user at once and is added far more often than anyone intends. ExpireIQ detects it whether granted directly on the site or buried inside a Members or Visitors permission group.

Oversharing

Anonymous sharing link inventory

Every "Anyone with the link" and organisation wide link across your estate, classified by type and permission, matched back to the file or folder it exposes, including shared folders, where everything inside inherits the exposure.

Oversharing

Broad access grants

Sites where a single permission grant reaches a large group of people. Set your own threshold for what counts as too broad for your organisation.

Exclusive

Retention coverage gaps

Which sites contain no content under a retention label at all. Because ExpireIQ already indexes labels for disposition review, it can answer a question permission focused tools cannot: where your retention programme simply has not reached.

Exclusive

Records at risk

The headline number: sites holding content under retention labels with no accountable owner, and anonymous links pointing at declared records. The intersection of exposure and obligation.

Hygiene

Guest access and external sharing posture

Which sites have external sharing enabled, at what level, and how many guest accounts can reach them, reported per site rather than as a tenant wide setting.

Hygiene

Inactive sites

Sites with no user initiated content change for longer than your configured threshold. Evaluated live against the current threshold, so changing the setting takes effect immediately without waiting for a rescan.

Hygiene

Missing sensitivity labels

Sites with no container sensitivity label applied, presented as programme coverage rather than as an alert count, giving you a ratio you can drive down over time.

Every finding is a decision with a record

Acknowledge a finding or suppress it until a date, with a reason. Every decision is added to a permanent history recording who decided, when and why. Nothing is overwritten, and reopening is itself a recorded decision.

What Gets Checked

Eleven checks, and what
each one actually tells you

Which checks run is up to you. These are the ones most organisations start with.

Ownerless site
Nobody is accountable for this content
Single owner
One departure leaves it unattended
No sensitivity label
Content is unclassified
No retention coverage
Nothing will ever expire here
Inactive site
Unused, still accumulating risk
External sharing enabled
The site can be shared outward
Guest access present
People outside the tenant are in
Everyone except external users
The whole organisation can reach it
Broad access
Permissions are wider than intended
Anonymous sharing links
Anyone with the URL can open it
Shared folders
Sharing is nested below the site
Module Two

Disposition review that reviewers will actually use

Records disposal fails for human reasons more often than technical ones. Reviewers cannot find what needs attention, cannot open the file to judge it, and nobody chases them. ExpireIQ addresses each of those.

Differentiator

Per site reviewer assignment

Assign specific reviewers to each SharePoint site. Finance sees finance content. HR sees HR content. Reviewers never see another site's content, so nothing is disposed of by someone with no business judging it.

Differentiator

Custom SharePoint columns in the disposal record

Capture up to five of your own columns, such as cost centre, matter number, business function or records class, against every file, with their proper display names, retained permanently in the disposal evidence. Auditors get the full business context, not just a file name and a date.

Differentiator

Proof of disposition that outlives the file

When a file is disposed of, the record stays: name, path, label, expiry date, every approval, every reviewer, every timestamp. Permanently searchable and exportable long after the content itself is gone.

Differentiator

Archive to cold storage instead of deleting

Reviewers can archive a file to Azure Blob Storage in your own tenant rather than disposing of it outright, keeping a recoverable copy at a fraction of SharePoint storage cost, when the disposal decision is not yet clear cut.

Differentiator

See what is due to expire

Each reviewer sees every file in the sites they look after, with its retention expiry date, so they know what is coming before it lands in their queue. No digging through a compliance portal.

New

Preview files without SharePoint access

Reviewers can open a read only preview of any file in the review queue without being granted SharePoint permissions and without a sharing link being created in your tenant. Every preview is written to the audit log.

Add site owners to a review stage in one click

Pull a site's existing SharePoint owners straight into a review stage rather than typing names. They become ordinary reviewers you can add to or remove from individually.

Sequential sign off, stage by stage

Configure up to five review stages per site. Sensitive disposals can require the department owner, then legal, then records management. Nothing is disposed of until every stage clears.

Business user friendly review experience

Reviewers see a plain list of what needs their decision, with the context to make it. No compliance portal navigation, no training required for someone who reviews a handful of files a month.

Administrators control the available actions

Decide which actions reviewers can take, whether that is approve, extend, relabel or archive. If your policy says reviewers may not extend retention, turn it off. Policy enforced by the tool, not by training.

Automatic reminders and escalation

Reviewers are emailed when files need attention. If nothing happens within a configurable window, the system escalates to a named contact automatically. Overdue work surfaces instead of quietly ageing.

Oversight dashboard and weekly digest

A live dashboard shows pending reviews, overdue files, escalations and completed disposals across every site, with a weekly email digest so compliance leads stay informed without logging in.

Where It Fits

ExpireIQ works alongside Purview, not instead of it

Purview stays your system of record for retention policy and labels. ExpireIQ takes over at the point where a label expires and a human has to decide something, and adds governance reporting your licence tier may not otherwise include.

What ExpireIQ adds to a Microsoft 365 environment
Capability Where it lives ExpireIQ
Retention policies and labels Microsoft Purview Reads them, configuration stays in Purview
Reviewers scoped per SharePoint site No native equivalent Included
Archive to cold storage as a review outcome No native equivalent Included
File preview without granting site access No native equivalent Included
Metadata retained after disposal as evidence No native equivalent Included
Upcoming expiry dates per file, across a reviewer's sites No native equivalent Included
Ownerless site and oversharing reporting SharePoint Advanced Management (per user add-on) Included, banded pricing
Governance findings joined with retention No native equivalent Included
Runs in your own Azure tenant No native equivalent Always
On the Roadmap

What is coming next

Design partners help shape the order. Everything below is in active development or scoped for the next releases.

Site ownership attestation

Scheduled campaigns asking site owners to confirm in writing that they still own and are accountable for their sites, with reminders, escalation, and a permanent record of who confirmed what and when.

Owner self service view

Site owners sign in and see governance findings for their own sites only, without an administrator having to chase them by email.

Item level permission scanning

Optional deep scanning that finds broken inheritance and unique permissions below site level, designed to be switched on deliberately and scoped to the sites that matter.

Guided remediation

Act on governance findings from within ExpireIQ, whether that is removing a sharing link or adding an owner, with the same dry run, approval and audit discipline as disposition.

Departed user exposure

Sites owned solely by disabled accounts, and orphaned content still carrying live retention labels with nobody left to approve its disposal.

Sensitivity label drift

Detect mismatches between a site's container label and the labels on the content inside it, meaning confidential sites holding public files, and the reverse.

Pricing

One price. Every feature. Both modules.

Starting at $499/month

Banded by your organisation's Microsoft 365 E3 or E5 licensed seat count. There are no per reviewer fees, no per site charges, and no feature gating between tiers. The smallest customer gets exactly the same product as the largest.

Azure infrastructure runs in your own subscription and is billed directly to you by Microsoft, separately from the ExpireIQ subscription. Typical infrastructure cost is $65 to $200 per month depending on organisation size.

Get a quote for your seat count

Included at every tier

  • Both modules, governance and disposition review
  • Unlimited SharePoint sites with no per site charge, ever
  • Unlimited reviewers and administrators
  • Unlimited files under management
  • Archive to Azure Blob Storage in your own tenant
  • Full audit trail including every configuration change
  • Automated deployment into your Azure subscription
  • Product updates as new capabilities ship
  • Direct support from the people who built it
Questions

Frequently asked questions

Straight answers about licensing, data residency, what happens to a file when it is disposed of, and how ExpireIQ relates to Microsoft Purview.

Can I assign different reviewers to different SharePoint sites?

Yes. ExpireIQ assigns reviewers per SharePoint site, and each reviewer sees only files from the sites they are assigned to. Reviewers only ever see their own sites, so a finance reviewer never sees HR content.

You can also add a site's existing SharePoint owners to a review stage in one click rather than typing names, and configure up to five sequential review stages per site, each with its own reviewers.

Is file metadata retained after a file is disposed of?

Yes, and this is central to the product. When a file is disposed of, ExpireIQ keeps the record permanently: file name, path, retention label, expiry date, who approved the disposal, when, at which stage, and the complete audit history.

That record remains searchable and exportable after the content itself is gone, which is what makes it usable as proof of disposition when an auditor asks you to demonstrate that a disposal decision was properly made.

Can custom SharePoint columns be captured in the disposal record?

Yes. Administrators can nominate up to five custom SharePoint columns such as department, cost centre, matter number, project code, records class, or any managed metadata field, and those values are captured against every file and retained in the proof of disposition record after disposal. Both the internal column name and its friendly display name are configured, so reviewers and auditors see readable labels rather than internal field names.

Can reviewers archive a file instead of deleting it?

Yes. Archive is one of the configurable disposition actions. Instead of disposing of the file outright, ExpireIQ copies it to Azure Blob Storage in your own tenant before removing it from SharePoint, so a recoverable copy exists at a fraction of SharePoint storage cost.

Administrators control which actions reviewers can take at all, whether that is approve, extend, relabel or archive, so if your policy does not permit reviewers to extend retention periods, that option can simply be switched off.

Can a reviewer preview a file they do not have SharePoint permission to open?

Yes, if the administrator enables it. ExpireIQ renders a read only preview of the file inside the review screen. No SharePoint permission is granted to the reviewer and no sharing link is created in your tenant, so nothing appears in your sharing reports as a result.

Every preview is recorded in the audit log with the reviewer's name, the file and a timestamp. That is a stronger position than permanently granting site access, because access is scoped to a single file in a single session and is evidenced.

What actually happens when a reviewer approves a disposal?

If more review stages remain, the file advances to the next stage and nothing is deleted. If it is the final stage, ExpireIQ queues the file for disposal.

At the next scheduled run, ExpireIQ removes the retention label, which is required because SharePoint blocks deletion of files that are labelled or declared as records, and then moves the file to the SharePoint recycle bin. It is not a permanent delete, so the file remains recoverable for as long as your tenant's recycle bin settings allow. The ExpireIQ metadata record is kept permanently regardless.

Can reviewers see what is due to expire in their sites?

Yes. ExpireIQ shows each reviewer every file across the sites they are responsible for, with its retention expiry date, so they can see what is coming up before it reaches their review queue. The dates are shown inside ExpireIQ, and nothing is written back to your SharePoint libraries.

How does ExpireIQ find ownerless SharePoint sites?

ExpireIQ reads each site's SharePoint Owners group and resolves every entry down to real people. Groups are expanded, including Microsoft 365 group owner and member claims and nested security groups, and disabled accounts, guest accounts and service principals are excluded.

This matters because a site can list an owner in SharePoint and still have zero accountable owners: the listed group may be empty, or its members may all have left the organisation. ExpireIQ reports both the raw count and the effective count, and explains precisely why a listed owner did not resolve to a real person.

What is EEEU oversharing in SharePoint?

EEEU stands for Everyone Except External Users. It is a special SharePoint claim that grants access to every internal user in the tenant at once. It is added far more often than anyone intends, usually by someone trying to make a document easy to find, and it is one of the most common causes of accidental organisation wide exposure.

ExpireIQ detects EEEU whether it has been granted directly on a site or is sitting inside a SharePoint permission group such as Members or Visitors, which is where it most often hides.

How do I find anonymous sharing links across SharePoint?

ExpireIQ inventories every sharing link on every scanned site and classifies each one as anonymous ("Anyone with the link"), organisation wide, or specific people, and as view or edit.

Each link is matched back to the file or folder it exposes. Where the file carries a retention label or is a declared record, ExpireIQ flags the combination, because an anonymous link on a declared record is a materially more serious finding than one on a draft. Shared folders are reported too, since everything inside them inherits the exposure, including files added later.

Can ExpireIQ show which sites have no retention coverage?

Yes, and this is unusual. Because ExpireIQ already indexes retention labels at file level for disposition review, it can report which sites contain no content under a retention label at all.

That answers a question permission focused governance tools structurally cannot: not "where are the access problems" but "where has my retention programme simply not reached yet". For a records manager, that is often the more urgent list.

Where is my data stored? Does Paras InfoGov host anything?

ExpireIQ deploys entirely into your organisation's own Microsoft Azure subscription. The database, storage account, application and background jobs all run in your tenant, in the Azure region you choose.

Paras InfoGov hosts nothing, stores none of your content or metadata, and has no standing access to your environment. For regulated industries and organisations with data residency obligations, this is usually the deciding factor.

Does ExpireIQ replace Microsoft Purview?

No, and it is not intended to. ExpireIQ works alongside Microsoft Purview. Purview remains your system of record for retention policies and labels, and all policy configuration stays there.

ExpireIQ takes over at the point where labelled content reaches its retention expiry and a human being has to decide what happens to it, and adds SharePoint governance reporting on top of the same scanned data.

Does ExpireIQ handle SharePoint site or Teams provisioning?

No. ExpireIQ governs workspaces that already exist, covering retention expiry, disposition review, ownership and oversharing.

Provisioning new workspaces correctly is a different problem, and we solve it with a separate product: Samyak, for templated Microsoft 365 site and team provisioning. The two are complementary. Provision it right, then govern it over its life. They are sold and deployed independently.

How is ExpireIQ different from SharePoint Advanced Management?

Three differences matter most. First, licensing: SharePoint Advanced Management is a per user add-on that must be licensed for every user in the tenant, whereas ExpireIQ is priced in bands regardless of how many people use it.

Second, ExpireIQ covers disposition review, which SharePoint Advanced Management does not.

Third, ExpireIQ's governance findings are joined with retention and disposition data, so a finding can state that a site is ownerless and holds content labelled as records, rather than reporting those two facts in separate reports that nobody joins up.

Is every action audited?

Yes. Every disposal decision, extension, relabel, archive action, file preview and configuration change is written to an immutable audit trail with the acting user, a timestamp, and the before and after values where relevant.

Governance decisions follow the same principle: acknowledging or suppressing a finding is recorded as permanent decision history rather than overwriting the previous state, and reopening a suppressed finding is itself a recorded decision. Nothing in the trail can be edited away.

How long does deployment take?

Deployment into your Azure tenant is automated and typically completes within a single working session. Your IT administrator runs a short onboarding script, a Global Administrator grants consent to the application permissions, and the platform provisions and configures itself.

No agents are installed anywhere, nothing is deployed to end user devices, and no content leaves your tenant at any point.

What does ExpireIQ cost?

Pricing starts at $499 per month, banded by your organisation's Microsoft 365 E3 or E5 licensed seat count. Every feature is included at every tier, with unlimited sites, unlimited reviewer and administrator accounts, and unlimited files under management.

Azure infrastructure runs in your own subscription and is billed separately by Microsoft, typically between $65 and $200 per month depending on size.

See it against your own tenant

Book a 30 minute demo. No preparation needed. Bring your hardest questions about retention, disposal evidence or oversharing, and we will show you what ExpireIQ does with them.

Or email us directly at contact@parasinfogov.com