Bringing public sector policy management out of the filing cabinet

LHC, a leading provider of free-to-use public sector framework agreements, replaced a manual, department-by-department policy process with a single secure intranet — where every policy is classified, version-controlled and visible only to the people entitled to see it.

Bringing public sector policy management out of the filing cabinet

The Client

LHC is a leading provider of free-to-use framework agreements for the UK public sector. Working with local authorities, housing associations, schools, NHS bodies and other public organisations, LHC establishes pre-procured frameworks that allow those bodies to appoint contractors and suppliers for construction, refurbishment and maintenance work without running a full tender exercise each time. This saves public organisations considerable time and cost while keeping procurement compliant with public contract regulations. LHC operates as a not-for-profit organisation, returning surpluses to the communities served by the projects it helps deliver, and works across England, Scotland and Wales through regional arrangements tailored to local needs. Because its role sits at the heart of how public money is spent, LHC operates under close scrutiny: transparency, auditability and the correct handling of documentation are fundamental to its credibility with the public bodies that rely on it.


Impressive Numbers

  • Policy documents from multiple departments consolidated into one classified repository
  • Full version history retained on every policy document, replacing manual copies
  • Accessible on desktop, tablet and mobile from any location

The Challenge

For an organisation whose business is helping the public sector do procurement properly, LHC's own internal policy management had become an uncomfortable irony. Policies covering different classifications and departments were being managed manually — produced locally, circulated by email, stored wherever the originating team happened to store things.

The practical consequences were felt daily. Locating the current policy on a given subject meant knowing which department owned it and asking someone there. Staff could not be confident that the copy they were reading was the latest version, because there was no single authoritative source and no version history to check against. In an organisation where getting the process right is the entire point, that uncertainty was more than an inconvenience.

Keeping the repository current was equally difficult. Gathering updated policy documents from different departments, confirming they were the approved versions and filing them consistently was a recurring manual task that consumed a great deal of time and was never quite finished. Something was always out of date somewhere.

Access control compounded the problem. Some policy material and employee records should be seen only by particular roles, but with documents spread across locations, permissions were maintained by hand and impossible to verify. For a public sector body, that is a governance exposure as much as an administrative headache.

LHC came to us wanting one secure, well-organised home for their policies — properly classified, reliably current, with controlled access and a clear audit trail.


The Solution

We built LHC an intranet on SharePoint Online designed specifically around classified policy management and the document governance that goes with it.

The first phase was structural rather than technical. Working with LHC, we established how their policies should be classified — by category, by department, by who needs access — and used that scheme as the foundation for everything else. Getting this right at the start meant the platform could enforce the rules rather than merely store the documents.

The policy repository itself is organised by classification instead of by the department that happened to produce a document. Staff looking for guidance on a topic go to that topic, rather than needing to know its origin. Each document carries metadata drawn from the classification scheme, so search returns results based on what a document is about rather than what somebody named the file. For an organisation where the right answer matters and the nearly-right answer can be costly, that reliability was central.

Version control was built in from the outset. Every policy has one authoritative current version with a full history behind it. Anyone can see when a policy last changed and what it replaced. Local copies became unnecessary, and with them went the risk of someone working from superseded guidance — the single biggest failure mode of the previous arrangement.

The process of keeping policies current was restructured. Rather than a periodic manual gathering exercise across departments, documents are submitted into the repository through SharePoint workflows that route them for review and approval before publication. The document reaches the right reviewer, the status is visible, and the outcome is recorded. Departments update their own material within a consistent process instead of sending files to a central coordinator to file.

Access permissions were rebuilt around roles. Rather than folder-level permissions maintained by hand, access is determined by a user's role and the document's classification. Sensitive policy material and employee records are restricted to those entitled to see them; general guidance is available to all staff. Because the model is rule-based, it remains accurate as people join, change role and leave — solving the drift problem that made the previous approach unmanageable.

We also applied retention and disposal handling by classification, so documents are kept for the period their category requires and dealt with afterwards according to the rule. For a public body, being able to state a retention position with confidence is a genuine benefit.

Search and retrieval received particular attention. Because the repository is metadata-driven, staff can filter by classification, department, date or document type and narrow a large policy estate to the handful of documents that matter. Finding a policy takes seconds rather than an exchange of emails.

The whole platform is cloud-based and works properly on tablets and phones, so staff working from home, visiting member organisations or attending meetings reach the current policy set wherever they are. Security was treated as a first-order requirement throughout: the environment sits within LHC's own Microsoft 365 tenant, access is auditable, and confidential material is protected by design rather than by convention.

Client's Quote / Review

DRAFT FOR CLIENT APPROVAL — please confirm wording and attribution before publication.

"We help public bodies get procurement right, so our own governance needs to stand up to the same scrutiny. Having every policy classified, version-controlled and properly access-managed in one place has removed a great deal of manual work and, more to the point, removed the doubt about whether people are working from the current version."— [Name], [Job title], LHC


The Results

The change LHC's staff notice first is certainty. When someone opens a policy now, it is the current one — there is no parallel copy on a shared drive and no need to check with the department that produced it. For an organisation built on procedural correctness, removing that doubt is worth more than the time saved finding the document, considerable though that is.

The manual burden of keeping the policy estate current has largely gone. Departments submit and update their own material through a defined review and approval route, so the repository stays current as a by-product of normal work rather than through a periodic gathering exercise. The recurring task of chasing departments for their latest documents simply stopped being necessary.

Retrieval is dramatically faster. Because documents are classified and tagged rather than filed in folders, staff search by subject and filter down to what they need in seconds. Queries that previously travelled by email to whoever was thought to know are now answered directly by the person who has the question.

Governance improved in ways that matter to a public sector body. Every policy carries a visible version history, every approval leaves a record, and access is determined by role rather than maintained by hand. When LHC needs to demonstrate how its documentation is controlled — to auditors, to member organisations or internally — the evidence exists already rather than needing to be assembled.

The access model itself has reduced administrative effort and risk together. Confidential policy material and employee records are visible only to the roles entitled to see them, and because permissions follow role rather than folder, they remain correct as the organisation changes. The uncertainty about who could see what, which was one of LHC's stated concerns at the outset, no longer applies.

Retention is handled by classification, so documents are kept for the required period and dealt with appropriately afterwards. LHC can state its retention position rather than estimate it — a meaningful improvement for an organisation operating in the public eye.

Because the platform is cloud-based and works properly on any device, staff working remotely or visiting member organisations reach the same current policies they would see at their desk. For a body that spends a good deal of time with the public organisations it serves, that portability removed a persistent practical constraint.

Most usefully, LHC now has a system that maintains itself. The classification scheme, workflows and permission model were designed to keep working as the organisation and its policy estate grow, so the platform will not need the periodic rescue that the previous arrangement required.

THE DETAILS

Company: LHC (LHC Procurement Group)

Location: United Kingdom

Industry: Construction & Real Estate

Duration : 4 months (estimated)

WHAT WE DID

Requirements analysis

Information architecture

SharePoint build

Document management

Version control

Permission configuration

Search optimisation

TECHNOLOGY WE USED

Sharepoint

Microsoft Dataverse

What can we
do for you?

Is Your Business AI-Ready?

sidebar