Ghani Governance
Start from written policy. Then implement. A UK practice — live workstreams grouped by job.

Ghani Governance implements Microsoft Purview for UK organisations. The groundwater is written policy: we read it, or we draft it, then we design the Purview posture. The pages below are the live offer after that — protect, govern, investigate. A discovery workshop decides which workstreams are actually in scope.
From policy
Map data, classification, privacy, AUP, ROPA, AI, incident and cloud policies onto Microsoft Purview controls. Delivered as a design report before anyone builds in the tenant.
Learn more →A lot of organisations have no usable written policy. We draft the set that the Purview design actually needs — not a 40-document pack for its own sake.
Learn more →
Protect
Policy design, endpoint DLP where it is justified, testing, tuning and operational handover.
Learn more →
Taxonomy, publishing, protection settings and adoption — aligned with DLP rather than running as a side project.
Learn more →
Proportionate monitoring and investigation governance, with HR and DPO overlay.
Learn more →
Policy-based review of communications, with a named purpose, reviewers, and HR/DPO overlay — not a licence to watch everyone.
Learn more →
Newer Purview capability for sensitive-data risk around AI use. We implement what your tenant can actually do.
Learn more →
Govern
Scans, sources, glossary, ownership and operating routines — one implementation, not three brochure pages.
Learn more →
Retention and records in Purview, designed around actual legal and operational need.
Learn more →
Assessments and improvement actions you can run, including UK GDPR in general terms. Not a certificate.
Learn more →
Investigate
Purview eDiscovery implementation: holds, collections and review so legal and compliance can run a matter.
Learn more →A scoping conversation about what you need to protect, what is already configured, and what must not break.