Shared storage follows a predictable arc. It starts organised, drifts for three years, and becomes a place where people search rather than browse. By then nobody will reorganise it, because the effort is large and the benefit is diffuse.

Automation helps, provided you decide the rules first.

Decide the rules before automating anything

Automation applies a policy. If you have no policy, automation will apply an accidental one.

Four questions:

What is current and what is finished? A completed job's files are reference material, not working material. Separating the two is the highest-value distinction available.

How long must each category be kept? Contracts, financial records, employment records, project files, certificates — each has a different answer, driven by legal requirement, contractual commitment or business need.

What happens at the end of that period? Delete, or move to deep archive? For most business records, archive is the honest answer.

Who decides exceptions? There will be some. Somebody needs authority to say a file is kept longer.

Structure that survives

Organise by the work rather than by the organisation chart. Departments are reorganised; jobs, clients and projects are not.

Keep it shallow. Three or four levels is usually enough, and every additional level is a decision somebody has to make correctly when filing.

Separate active from archived at the top level. This is what allows housekeeping to work, because it gives you somewhere to move things that is not deletion.

Name consistently, and put the date first in a sortable form. A folder of files beginning 2026-03-14 sorts itself; one beginning 14th March does not.

What to automate

Archiving completed work

When a job closes, its folder moves to the archive. Triggered from your job or CRM system where possible, so nobody has to remember.

The archive stays searchable and read-only. Read-only matters: it prevents somebody editing a completed record and it makes clear which copy is authoritative.

Flagging what looks abandoned

Rather than deleting old files, report them. A monthly list of folders untouched for two years, sent to the person responsible, prompts a decision without risking anything.

This is the safe version of housekeeping and it is where most businesses should start.

Finding duplicates and versions

Report files with near-identical names — the "final", "final v2", "final USE THIS" family. Report them rather than resolving them automatically, because only a person knows which is real.

Enforcing naming at creation

Where files are created by a system rather than by hand, name them correctly at source. A generated quote or certificate should never be named by a human.

Storage reporting

Which areas are growing, and how fast. This catches the folder where somebody is storing video, and it makes storage cost a visible thing rather than a surprise.

Report first, move second, delete last. Every step you skip is a step towards losing something that mattered.

Retention, done properly

A retention policy that is written and not applied is worse than none, because it documents an obligation you are demonstrably not meeting.

Practical implementation:

  • Categorise records and set a period for each, with the reasoning recorded.
  • Apply retention labels where your platform supports them, so the rule travels with the file.
  • Give a review window before anything is deleted — a report saying what will be removed in thirty days, to a person who can object.
  • Log what was deleted and when. You may need to demonstrate that you did.
  • Suspend deletion for anything under dispute or investigation, and have a way to apply that hold.

Under UK GDPR, keeping personal data indefinitely because deleting is effortful is not a defensible position. But neither is deleting something you were required to retain, which is why the review window matters.

Where it goes wrong

Deleting without a review period. The one mistake that cannot be undone.

Moving files people have linked to. Documents referenced from other systems, or bookmarked, break silently. Where possible, leave a redirect or notify.

Automating before agreeing the rules. The script becomes the policy, and nobody knows what it does.

Running it against everything at once. Start with one area, observe for a month, then extend.

Forgetting the backups. Archiving changes what your backups cover. Confirm the archive is backed up too, and that it can be restored — see backups that actually restore.

A sensible sequence

  1. Agree categories and retention periods, and write them down.
  2. Create the archive area and make it read-only.
  3. Report on what has not been touched in two years. Change nothing.
  4. Act on the report manually for a quarter.
  5. Then automate the archiving step.
  6. Add retention deletion last, with a review window.

Our maintenance team sets up file structure, archiving and retention for UK businesses. Start a conversation.