Governance

End Teams sprawl. Govern every workspace from creation to retirement.

Governed workspace creation with approval workflows, templates, and lifecycle management.

From $7,500one-time deployment
compass://provisioning-engine
Provisioning Request #PRV-2847In Progress
Request Submitted
Marketing Team Site
Project
Manager Approval
Approved by J. Smith
Approved
3
IT Review
Checking naming policy
Reviewing
4
Provisioning
Template: Project Site v2
Queued
5
Handoff & Monitor
Notify owner + lifecycle
Pending
Active Requests
12
Provisioned (30d)
47
Archived
156

Overview

Microsoft provides a binary choice for workspace creation: fully open self-service that leads to sprawl, or fully restricted creation that creates bottlenecks and shadow IT. There is no native middle ground. Teams templates cannot include private or shared channels, cannot apply sensitivity labels, and changes never propagate to existing teams. Site scripts are limited to 300 actions and cannot provision pages or web parts.

Compass Provisioning Engine fills this gap with guided self-service workspace creation that includes approval workflows, metadata capture, content-rich templates, naming convention enforcement, and full lifecycle management from creation through archival and deletion. Built on the open-source PnP Provisioning Engine (MIT licensed, 10+ years of development), it leverages Power Apps for the request interface, SharePoint for tracking, Power Automate for approvals, and Azure Functions for provisioning execution.

Use Cases

  • Governed Teams and SharePoint creation
  • Project-based workspace lifecycle management
  • Mergers and acquisitions workspace setup
  • Department onboarding automation

Key Features

Power App request form for guided workspace creation
Multi-level approval workflows via Power Automate
Content-rich templates: pre-populated folders, files, channels, Planner tasks, pages, and web parts
Naming convention enforcement and metadata capture at creation time
Sensitivity label application during provisioning
Lifecycle management: inactivity detection, owner notifications, attestation workflows, automated archival
Built on PnP Provisioning Engine (MIT licensed, battle-tested across 10+ years)
SharePoint-based audit trail for all provisioning and lifecycle events
Uses Power Automate Process license ($150/flow/month). Avoids per-user premium licensing

Technical Architecture

Deployed in your tenant
Your Microsoft 365 Tenant
Power AppsRequest form
Power AutomateApproval workflows
PnP EngineAzure Functions
SharePointSite + Teams creation
Lifecycle MgmtMonitor + archive
trigger
compute
storage
output
action
All components run in your Azure subscription

71% of IT leaders report Copilot introduces additional security risks by surfacing overshared content from abandoned workspaces. Provisioning governance ensures every workspace is created with proper permissions and retired when no longer needed.

Ready to deploy Provisioning Engine?

Book a consultation and we will walk through your tenant to show exactly how this product maps to your requirements.