Purview blocks the send. Then someone writes an exception.
You turned it on, it blocked the wrong things, someone wrote an exception, and now it is a log nobody reads. DataGuard proposes what to remove, your team clears it, and every send is on the record.
Why Purview fails at small firms
Microsoft Purview is a genuinely capable tool. It was designed for large enterprise organizations with dedicated security teams who configure it, tune it, and manage it full time. That is the environment it was built for.
A law firm without a dedicated IT administrator is not that environment. When Purview is deployed without the resources to maintain it, one of two things happens: it is set too restrictively and generates so many false positives that staff routes around it, or it is loosened to stop the complaints and ends up doing nothing.
This is not a failure of your office manager or your IT vendor. It is a product that requires inputs your firm doesn't have.
Purview was built for IT departments at enterprises. DataGuard was built for firms without one.
Side by side
Five dimensions that matter without a full-time IT department.
| Dimension | Microsoft Purview | DataGuard |
|---|---|---|
| Setup time | Weeks, plus IT configuration | Connect the sources; no policy build |
| Who manages it daily | Requires trained IT admin | No admin to hire; your team reviews each flag |
| When something is flagged | Send is blocked; manual review queue | Sensitive content removed; share proceeds clean |
| Employee experience | Blocked send, no clear explanation | Document shared; clear summary of what was removed |
| What it takes to run | An admin to write the policies, tune them, and work the queue | No policy build; your team clears the flags it raises |
| Built for | Enterprise IT departments | Firms without an IT team |
| Legal-specific policies | Generic DLP policies, configured by hand | Ships with rules written against the confidentiality duties and privacy statutes firms work to; your firm edits them |
The difference that matters
Purview is a policy management platform. You configure the policies, manage the exceptions, review the flagged items, and adjust the rules over time. That requires someone doing it.
DataGuard is a document protection layer. It ships with the removal rules a firm is likely to need, so there is no policy engine to staff. Every outbound document is checked, and what it finds goes to your reviewer to clear. The detection is automatic. The decision is a person's.
Three steps. No new tool to learn.
DataGuard reads every outbound document where your team already works. The judgment stays with your reviewer. What goes away is the page-by-page read that used to come before it.
DataGuard lives inside the tools you already use
No new tools for your team to learn. DataGuard installs directly into Outlook, Gmail, OneDrive, Google Drive, SharePoint, and Clio, the tools your team already uses every day.
Every outbound document is read first
When a document is about to leave the firm (via email, a shared link, or a file attachment) DataGuard reads it against your firm's policies before it reaches anyone outside, and marks what should not go out.
You confirm. The clean version goes out.
SSNs, diagnosis codes, government IDs and other restricted content come back proposed for removal, each with the rule behind it. Your reviewer approves, edits, or overrides, and the audit log records the decision either way.
See it on the sends Purview got wrong.
20 minutes. Bring the sends it blocked and the ones it missed, and we will run the pre-flight check on the call.