All articles

How to build a document management system

The problem is rarely storage — it is finding the right version of the right document and proving who did what. Build for retrieval and control, not for filing.

Most companies do not have a storage problem. They have a retrieval problem. Documents are everywhere — a shared drive, three cloud folders, email attachments, someone's laptop, a filing cabinet — and the pain is never that there is nowhere to put a file. The pain is finding the current, correct version of a contract two years later, knowing it is the version that was actually signed, and proving who changed it and when. A document management system that only solves storage solves the problem nobody had.

Define the real need before the tool

Document management is a broad term hiding very different needs, and the wrong assumption at the start makes everything downstream wrong. For some companies the core need is search — a lawyer or engineer who has to find the right clause across thousands of files. For others it is control — proving, for an auditor or regulator, exactly who accessed a record and what changed. For others it is process — a contract that has to move through drafting, review, approval, and signature without living in an email thread.

These pull the design in different directions. A search-first system invests in metadata and indexing. A control-first system invests in permissions and an immutable audit trail. A process-first system invests in workflow. Trying to be all three equally from day one produces something expensive and diffuse. The first job is to name which pain is actually costing you money, and build for that first.

The trap is treating this as an IT decision. The person who feels the pain — the lawyer who cannot find the clause, the compliance officer who dreads the audit, the operations lead whose approvals stall — is the one who can name the need precisely. Start the project in their office, not in a feature comparison, and the rest of the design has a spine to grow around.

Metadata and search are the whole game

A document nobody can find might as well not exist, and folder hierarchies are where findability goes to die. Everyone files differently, the same document belongs in three folders at once, and six months later nobody remembers the scheme. The system that works stores documents flat and finds them by their properties — client, project, type, date, status, author — plus full-text search across the contents.

The discipline is capturing that metadata without turning every upload into a form-filling chore. The best systems infer what they can — pulling a client and date from the document itself, defaulting the type from where it came from — and ask the human only for what cannot be inferred. Get this wrong and people route around the system to save two minutes, and a document management system that people route around is just an expensive folder.

Search quality is also a promise you have to keep over time. A system that finds everything on launch degrades quietly as people upload without tagging, scan documents that hold no searchable text, or invent categories nobody agreed on. Deciding what is mandatory, what is inferred, and what the system does with a document it cannot classify is not a detail — it is the difference between a search that stays trustworthy and one that slowly fills with noise.

Versioning, access, and the audit trail

Three capabilities separate a real DMS from a shared drive with ambitions. Versioning means the system holds the history of a document, so contract_final_v3_REALLY_final stops being a filename and becomes a property you can trust — you can see every version, who made it, and roll back. Access control means the right people see a document and the wrong ones do not, expressed in terms your business understands rather than a tangle of folder permissions no one dares touch.

The audit trail is the one companies underestimate until they need it. A record of who viewed, edited, downloaded, and shared each document — tamper-evident and complete — is what turns we think it was fine into here is exactly what happened. When a dispute, an audit, or a regulator arrives, this is the difference between an afternoon and a crisis. If your industry has any compliance weight at all, treat the audit trail as a core requirement, not a nice-to-have.

These three are also what make collaboration safe rather than chaotic. When several people work on the same document, versioning stops them overwriting each other, access control keeps a draft from leaking before it is ready, and the audit trail means a mistake can be traced and understood rather than argued about. Together they turn a shared pile of files into something a business can actually rely on under pressure.

Retention, e-signatures, and workflows

Documents have a lifecycle, and a mature system manages the whole of it. Retention means knowing what must be kept, for how long, and what must be deleted when its time is up — because keeping everything forever is itself a liability, not caution. Under GDPR and sector rules, holding personal data past its purpose is a risk you are choosing to run.

Electronic signatures turn the system from a place documents rest into a place work completes, closing the loop that otherwise leaks into email and print-sign-scan. And workflows — routing a document for review and approval, with a record of each step — are what stop approvals from living in inboxes. Not every DMS needs these on day one, but knowing whether you will need them changes the architecture, so decide deliberately rather than discovering it later.

These capabilities also tend to arrive in an order. Storage, search, and control come first because nothing else works without them; retention and signatures follow once the basics are trusted; workflows come last, because automating how documents move only makes sense after they are reliably stored and found. Trying to deliver the whole lifecycle at once is how a document project loses two years. Sequencing it is how it ships something useful in months.

Compliance and data protection are the frame

For a document system, compliance is not a feature bolted on the side — it is the frame the whole thing sits in. Documents are exactly where regulated and personal data accumulates, and the questions come fast: where is this data physically stored, who can reach it, how long do we keep it, can we produce a subject access request, can we prove a record was not altered? These answers have to be designed in, because retrofitting data protection into a system that already holds thousands of sensitive documents is painful and sometimes impossible.

This is also where the honest constraints live. Data residency, encryption, retention, and access governance are not the exciting part of the project, but they are the part that keeps you out of trouble, and they should be settled before the first document is loaded rather than negotiated after.

It helps to treat these requirements as fixed constraints handed to the design, not preferences to balance later. Where the data may live, who may see it, and how long it survives are decisions with legal weight, and they are far cheaper to honour in the schema than to bolt on afterwards. A system built inside those lines from the start is calmer to run and far easier to defend when someone asks how it works.

Migrating the mess you already have

A new system does not empty the old drives. Somewhere there are years of documents in folders nobody maintains, attachments buried in email, and scans with no metadata at all, and the migration of that backlog is often larger than building the system itself. Pretending it will sort itself out is how a shiny new system ends up as an empty shell beside the same old shared drive everyone still uses.

The honest approach is to decide what actually has to move. Not everything is worth migrating — much of the backlog is duplicates, drafts, and documents past any retention need, and dragging all of it across just imports the mess into a cleaner container. Move what has current value and clear legal need, archive the rest in a searchable but separate store, and be deliberate about the metadata you attach on the way in. The migration is the one chance to impose order on the pile, and skipping that chance wastes much of the project.

Off-the-shelf, SharePoint, or custom

Here is the contrarian part: most companies asking us to build a document management system should not build one. Mature products exist — dedicated DMS platforms, and SharePoint, which most organisations already own and underuse. For standard document storage, search, versioning, and permissions, a well-configured off-the-shelf system is faster, cheaper, and maintained by someone else. We will say so plainly when it fits.

SharePoint deserves a special mention because so many companies already pay for it and use it as little more than a shared drive. Configured properly — with real metadata, content types, versioning, and permissions — it covers a great deal of what people ask a custom DMS to do. Before commissioning anything, it is worth asking honestly whether the tool you already own, used well, would close most of the gap.

Custom earns its place at the edges: when documents are the core of a product you sell, when a workflow is specific enough that configuring a generic tool becomes a fight, when integration with your line-of-business systems has to be seamless rather than bolted on, or when your compliance regime is unusual enough that generic products cannot satisfy it. Even then, start narrow. A system that does one document type extremely well beats a platform that does everything adequately, and it earns the right to grow. Begin with a short assessment — the real pain, the compliance frame, an honest off-the-shelf-versus-custom recommendation, and a costed first slice — and you avoid the most common outcome: an expensive system that becomes yet another place documents get lost.

Drowning in documents across drives and inboxes?

We run a fixed-fee document assessment: the real pain, the compliance frame, and an honest off-the-shelf-versus-custom recommendation with a costed first slice.

Book a document assessment