Summary
- In short
- SharePoint provides versioning, content approval, check-out and, with Microsoft Purview, records retention, under a shared-
responsibility model in which the customer qualifies its own GxP use. Seal provides document control as a configured GxP workflow, with approval and effectiveness separate and each revision connected to training and the work. - When it fits
- Most of your documents are collaboration content in Microsoft 365, you want Purview retention across SharePoint, OneDrive and Exchange, and you have the capacity to configure and qualify a library for GxP procedures.
- When Seal fits
- Your controlled procedures must reach the point of use: one effective version, training assigned from the change, forms that keep their version, and Neil preparing revisions for your team to approve.
- Using both
- Keep SharePoint as the library and start one procedure family in Seal. Seal’s SharePoint connection shares selected versioned files, read-only, for reference with @.
1SharePoint and Seal, side by side.
SharePoint and Seal can both hold versioned procedures with approvals and an audit history. They are different kinds of product. SharePoint is Microsoft’s general content platform: teams configure document libraries with versioning, content approval and check-out, and Microsoft Purview adds retention and records management across Microsoft 365.¹² Seal is the GxP operating system for biopharma: document control is a governed workflow connected to the training, forms and work each procedure governs.
| SharePoint | Seal | |
|---|---|---|
| What it is | General content platform | GxP operating system for biopharma |
| GxP basis | Shared responsibility, no GxP cert | Supplier evidence; you own the use |
| Versions | Major and minor, with check-out | One effective version per document |
| Approval | Content approval publishes | Approval and effectiveness separate |
| Records | Purview retention labels | Form records keep their version |
| Point of use | Library views and permissions | A check in the workflow |
| AI | Agents in SharePoint | Neil drafts the configured change |
| Connection | Shared to Seal, read-only | @ references to captured versions |
| Getting started | Configure and qualify a library | One procedure family first |
2What SharePoint is built for.
SharePoint is made for organisations that want documents, sites and collaboration inside Microsoft 365, configured for many purposes, of which GxP document control is one. Its document control features are general settings that each library owner configures for the library’s purpose.¹
In a SharePoint document library, an owner can require content approval for submitted items, keep major versions only or major and minor versions, limit how many versions and drafts are kept, set who can see drafts, and require documents to be checked out before editing. Earlier versions can be viewed and restored from the version history.¹ Microsoft’s planning guidance describes how these work together: a draft awaiting content approval is Pending, users with approver permissions control its publication, and once approved it becomes a new major version visible to readers. A library owner can optionally associate a workflow to run the approval process, and check-in comments create a running history of changes.³
Microsoft Purview records management extends this across Microsoft 365. Retention labels apply retention periods and actions, and can declare items as records or regulatory records. A regulatory record’s label cannot be removed once applied, even by a global administrator, and its retention period can only be extended; the option must first be enabled with PowerShell. Records deleted at the end of their retention period leave proof of disposition.² For AI, agents in SharePoint help users find information on sites, pages and document libraries, and respond based on each user’s access permissions; they are available with a Copilot licence or pay-as-you-go billing.⁴
3What GxP document control asks of a general platform.
Microsoft is direct about where the responsibility sits. Its GxP compliance page says there is no GxP certification for cloud service providers, and that computerised systems used in GxP processes require validation of adherence to GxP requirements.⁵
Office 365 undergoes independent audits for quality and information security management, including ISO 9001 and ISO/IEC 27001. Microsoft retained Montrium, an independent GxP compliance organisation, to conduct a GxP qualification review, and the resulting qualification guidelines for Office 365 identify the responsibility shared between Microsoft and its customers. They recommend activities and controls that customers can establish to keep control of GxP computerised systems hosted on those services. Microsoft Purview Compliance Manager offers a premium template for a GxP assessment.⁵
So a SharePoint library used for GxP procedures is a computerised system the regulated company configures, qualifies and keeps under its own control, using Microsoft’s platform evidence as one input. Seal divides responsibility the same way: Seal provides the platform controls and its own verification and release evidence for the version in scope, and your team owns the intended use, the process requirements, risk acceptance and production approval. The difference is what is already configured. In Seal, document types, review disciplines, signature meanings, effective dates, training impact and controlled copies are part of a governed document control workflow, described in the document control blueprint, and each change to that configuration runs its selected acceptance tests before publication.
4Approval, effectiveness and the work.
In SharePoint’s content approval, approving a version is what publishes it to readers.³ In Seal, approval and effectiveness are separate decisions, and the effective version is connected to the work.
Each version in Seal moves from draft through review and approval to effective, and is later superseded or retired. Approval alone does not make a version effective. The effective date is when the new version becomes the instruction in force, coordinated with training, configuration, form deployment, controlled-copy exchange and translations; if implementation is delayed, the approved version waits with its reason recorded. Signature records show who approved each version, when and with what meaning.
Training follows the change. In the example in Seal’s document control blueprint, when Procedure-042 moves from version 2 to version 3, a configured automation identifies the people trained on version 2, marks that training as superseded for the new version and assigns the required retraining. Where the workflow has a training prerequisite, a person without the current qualification cannot complete the step that depends on it. The change record decides whether a revision needs no training, awareness, read-
Forms work the same way. Form FRM-001 version 2.0 is a controlled template; completed for batch B-047, it becomes a record that keeps the form version, the person, the time and the data, and is protected from change once approved. For any date and activity, the connected records show the instruction in force, its training status, the distributed copies and who was qualified to do the work.
5Where SharePoint is the better fit.
SharePoint is the better fit when the main need is collaboration and records retention across Microsoft 365, and your team is prepared to configure and qualify it.
- Your organisation already runs on Microsoft 365, and most of your documents are collaboration content rather than GxP-controlled procedures.
- You want retention and records management, including immutable regulatory records, applied consistently across SharePoint, OneDrive and Exchange.²
- You have the quality and IT capacity to qualify a SharePoint configuration using Microsoft’s qualification guidelines and shared-
responsibility model.⁵ - You need AI that finds information across sites and libraries with each user’s own permissions, under your Copilot licensing.⁴
6Where Seal is the better fit.
Seal is the better fit when controlled procedures must reach the work, and you would rather configure a governed workflow than assemble document control from general features.
- You want one effective version per document, with approval and effectiveness as separate gates and the outgoing version in force until the replacement is ready.
- You want a revision to identify the affected roles, assign the training it requires and, where configured, govern whether a person may perform the step that depends on it.
- You want forms to become records that keep the form version they were completed on, and procedure changes that can add a check to the workflow itself.
- You want Neil to prepare revisions. Neil drafts the revised instruction from the source procedure, finds the forms, training and records it affects, and prepares the configured change with its verification for your team to review and approve. In line with the EU’s draft GMP Annex 22 on AI, Neil is not used in GMP execution. It helps set up configuration, which your team verifies and releases under change control.
7Running Seal alongside SharePoint.
SharePoint can stay where your documents live while one procedure family runs in Seal. Seal’s SharePoint connection shares selected versioned files from a SharePoint site with chosen Seal groups, to reference with @ in documents, comments and Neil. Optional text copying supports readable files, and opening the original uses each reader’s SharePoint permissions.
Setup is in Seal: open Settings, then Integrations, set up SharePoint and enter the site URL; sign in with Microsoft, choose a document library and select files with version history enabled; then choose the Seal groups, review text copying and enable the library. Microsoft administrator consent may be required. Sharing starts after review and a successful sync. The library reads only and makes no changes in SharePoint. Disabling sharing blocks new reads, turning text copying off removes stored text, and disconnecting deletes the copies. A captured version stays linked to its original.
8Moving from SharePoint to Seal.
Start with one procedure family and its forms, and leave the rest of the library where it is.
- Choose a procedure family where revisions keep missing the point of use, such as one whose forms or training drift after each change.
- Connect the SharePoint library for the documents it references, read-only.
- Bring an existing revision and map it to the roles it affects. Neil drafts the configured workflow, and your team checks it against how the work runs. The 48-hour evaluation turns one procedure into a working workflow with a validation pack to inspect. Production timing then depends on scope, interfaces, migration and your release requirements.
- Follow the revision through approval, training and effectiveness before extending the workflow.
- When you migrate, import documents with their version history where it exists, establish controlled baselines and document types before go-live, and reconcile imported records. A file upload is not an approved baseline, and missing history is not invented.
The document management blueprint describes how procedures, forms and training connect in Seal.
References
- 1Enable and configure versioning for a list or library, Microsoft Support. https:/
/ support. microsoft. com/ en- us/ office/ enable- and- configure- versioning- for- a- list- or- library- 1555d642- 23ee- 446a- 990a- bcab618c7a37 (read 8 October 2026) - 2Records management for documents and emails in Microsoft 365, Microsoft Learn. https:/
/ learn. microsoft. com/ en- us/ purview/ records- management (read 8 October 2026) - 3Plan document versioning, content approval, and check-out controls in SharePoint Server, Microsoft Learn. https:/
/ learn. microsoft. com/ en- us/ sharepoint/ governance/ versioning- content- approval- and- check- out- planning (read 8 October 2026) - 4Get started with agents in SharePoint, Microsoft Learn. https:/
/ learn. microsoft. com/ en- us/ sharepoint/ get- started- sharepoint- agents (read 8 October 2026) - 5Good Clinical, Laboratory, and Manufacturing Practices (GxP), Microsoft Compliance, Microsoft Learn. https:/
/ learn. microsoft. com/ en- us/ compliance/ regulatory/ offering- gxp (read 8 October 2026)
AQuestions and answers
Can SharePoint be used for GxP document control?
Microsoft says there is no GxP certification for cloud service providers and that computerised systems used in GxP processes require validation. Its qualification guidelines for Office 365 set out the responsibility shared with customers and the controls customers can establish. A regulated company that uses SharePoint for GxP procedures configures, qualifies and controls that use itself.
Is Seal an alternative to SharePoint for SOPs?
For controlled procedures, yes. Seal keeps one effective version per document, separates approval from effectiveness, and connects each revision to training, forms and the work it governs. SharePoint remains a good home for general collaboration content, and Seal can reference files in it.
Can Seal read documents in SharePoint?
Yes. Seal’s SharePoint connection shares selected versioned files from a SharePoint site with chosen Seal groups, for reference with @ in documents, comments and Neil. It reads only, and opening the original uses each reader’s SharePoint permissions.
What does approval mean in each?
With SharePoint content approval, an approved draft becomes a new major version visible to readers. In Seal, approval records agreement to a version, and a separate effective date makes it the instruction in force once training, configuration and controlled copies are ready.
How long does it take to start with Seal?
The 48-hour evaluation turns one procedure into a working workflow with a validation pack to inspect. Start with one procedure family and its forms. Production timing then depends on scope, interfaces, migration and your release requirements.
