Back to blog

A Document Management System Requirements Checklist You Can Test in a Demo

A document management system requirements checklist with a demo test and pass or fail signal for each item, plus SharePoint migration gotchas and scripts.

Luka Abramovic21 min read

Isometric checklist connected to document search, access permissions and archiving requirements.

A document management system requirements checklist only separates products when every requirement comes with a test you run in the vendor's demo, on your own files, with the pass or fail signal written down before the demo starts. Every vendor answers yes to "does it have version control?". The useful test is asking the system to show, within a minute, which revision of a procedure was in force on a date you pick and who approved it. In SharePoint, a library set to automatic version limits deliberately deletes some older versions, so the revision an auditor asks about may simply be gone.

Each of the nine areas below ends in a table: the requirement, how to test it in a 30-minute demo, and what passing and failing look like. SharePoint and OneDrive are the worked example, because many businesses already pay for them. Microsoft behavior is as of September 2026. The last section turns the tables into a demo script.

1. Scope: build a test pack before any demo

A demo on the vendor's sample files proves that the vendor's sample files work. Yours are messier, and the difference is where products fail. So the first requirement is a test pack, assembled once and handed to every vendor unchanged:

  1. Your 20 worst scans: faxes, phone photos of paper, stamped pages, rotated pages, tables, handwriting in the margin. For each, ask a colleague to write down three things they can read at a glance, such as a part number, a name and a date. That gives you 60 phrases a person can find, which the system should find too.
  2. One real folder, copied untidied, with your deepest nesting, longest file names and oddest characters. The script in section 8 finds it.
  3. Five real questions, collected as described in section 2.
  4. One restricted document and a test account that should not see it. Pick something with distinctive words, such as a salary review.
  5. One document with a known history: at least three revisions, where you know which was in force when and who approved it.
  6. Your awkward formats: the largest file you have, a CAD drawing or other specialist format, and an Outlook .msg email with attachments.

When you list where documents live today, include personal OneDrive folders and mailboxes. If approvals happen by email, the approval evidence is in someone's inbox, which changes both the migration and the permissions design.

Scope requirement and how to test it
RequirementHow to test it in the demoPass or fail signal
Handles your real formats and sizesUpload the largest file and the awkward formats. Open each in the browser preview, then search for a word that appears only inside it.Pass: each previews and is found, or the vendor names up front what it cannot index. Fail: "we would convert those first."

2. The questions people actually ask

Ask five to ten future users about the last three times they went looking for a document: the question in their own words, and how long it took. "Which revision of the pump specification applied to the Harper order?" is a question. "Specifications" is a topic, and useless for testing. Today's times are your baseline for judging the new system later.

Choose five for the demo and make them deliberately different:

  • Two that need one document found: "where is the signed lease for the Dayton warehouse?"
  • Two that need an answer from inside documents: "what torque does the current maintenance procedure give for the M12 bolts?"
  • One your documents cannot answer. For any product with an AI assistant, this is the most revealing question you will ask.

Also include two documents that genuinely disagree, such as last year's and this year's price list, and ask something that touches both. A system that silently picks one will do the same in daily use. We wrote about the same failure with numbers, where answers that looked right but changed from run to run led users to stop trusting the system entirely.

Question requirements and how to test them
RequirementHow to test it in the demoPass or fail signal
Finds the right document from a real questionYou type each question exactly as it was asked. The vendor may not rephrase it.Pass: the right document in the top three results, with the matching passage highlighted. Fail: it only works after the vendor turns your question into keywords or filters.
Says when the answer is not thereAsk the question your documents cannot answer.Pass: a plain "not found in these documents." Fail: a confident answer, or a loosely related document presented as the answer.
Shows conflicts instead of resolving them silentlyAsk the question that touches both disagreeing documents.Pass: both sources shown, with their dates or revisions. Fail: one answer, and no mention of the other document.

3. Identity and permissions

The permission test that matters is indirect. Nobody leaks a salary file by opening it. It leaks when someone without access types "pay rise" into search and the results page shows a title, a snippet, a result count or an autocomplete suggestion drawn from a file they could never open. If the product has an AI assistant, ask it an indirect question too, such as "what raises are planned for next year?". Anything derived from the restricted file, even a vague summary, is a leak.

Then test removal. Search systems usually keep their own copy of who may see what and update it after a change, so there is a delay between revoking access and results disappearing. The vendor should know how long it is.

In SharePoint, watch how exceptions pile up. When someone shares a single file with a person who has no access to its library, SharePoint breaks permission inheritance on that file and gives the person "Limited Access" to the site so they can reach it (Microsoft: permission levels). Nobody grants Limited Access on purpose, so nobody reviews it. Microsoft supports up to 50,000 items with unique permissions in one library but recommends staying under 5,000, and once a folder or library holds more than 100,000 items you can no longer break or restore inheritance on it at all (Microsoft: sharing and inheritance limits). Design access by group and by library before migration, not file by file afterwards.

Permission requirements and how to test them
RequirementHow to test it in the demoPass or fail signal
Search never reveals what the user cannot openSign in as the test account. Search for distinctive words from the restricted document's title and body, then ask any assistant an indirect question about it.Pass: no title, snippet, count, suggestion or answer derived from it. Fail: any trace, including a "request access" card that shows the title.
Removing access takes effect quicklyGrant access, search, revoke, then search again every few minutes.Pass: gone within a delay the vendor states in advance. Fail: still visible at the end of the demo, and nobody can say why.
Leavers lose access through your identity providerDisable the test account in Microsoft Entra ID, Google Workspace or Okta during the demo.Pass: sign-in, sync and sharing links stop working, and the vendor can say what happens to copies already synced to a laptop. Fail: a separate user list to maintain.
Exceptions can be listedAsk for every item whose permissions differ from its folder or library.Pass: a report in minutes. Fail: checking item by item.

4. Capture, naming and metadata

A mandatory field that busy people must type by hand gets filled with whatever passes validation, such as the first option in the list. Prefer metadata the system can derive: from the folder or project it was filed in, the template it came from, the email it arrived with, or the text on the page. Keep the fields people must choose themselves to two or three.

Two SharePoint settings change what capture means in practice:

  • Require check out. In a library with this setting, a file you upload is checked out to you, and nobody else can see it until you fill in any required properties and check it in (Microsoft: require check out). It also prevents co-authoring. After a bulk upload, files nobody checked in stay invisible to everyone but the uploader. A site owner finds them under Library settings, "Manage files which have no checked in version". Check that page after every migration batch.
  • The list view threshold. A library can hold up to 30 million items, but a view or filter that has to process more than 5,000 items can fail, and SharePoint Online won't let you raise that limit. Large libraries keep working when views filter first on an indexed column (Microsoft: list view threshold). So index the columns people filter by before a library passes 5,000 items.
Capture requirements and how to test them
RequirementHow to test it in the demoPass or fail signal
Required metadata gets filled in properlyAdd five files the ways staff actually will: drag in, save from Word, email in.Pass: required fields are derived or prompted, and a file cannot become visible to others without them. Fail: fields left blank or silently defaulted.
Email and scanner captureForward an email with two attachments to the capture address. Scan one page on your own scanner.Pass: both arrive filed, with sender and date as metadata and attachments linked to their email. Fail: someone downloads and re-uploads.
Duplicates are caughtUpload the same file twice under different names.Pass: a warning or a link to the existing copy. Fail: two independent copies.
Filtering still works at volumeAsk to filter a library of more than 5,000 items by one of your metadata columns.Pass: it works in the normal view. Fail: a threshold error, or "use search instead."

5. Versions and approval

The question that matters is which revision was in force on a given date, and who approved it. It gets asked after something goes wrong, exactly when the answer has to be provable. ISO 9001:2015 requires documented information to be reviewed and approved for suitability and adequacy (clause 7.5.2) and its changes controlled, for example by version control (clause 7.5.3). The 2008 edition also said to prevent the unintended use of obsolete documents. That line is gone from ISO 9001 but still appears in ISO 13485 for medical devices and AS9100 for aerospace. ISO 9001:2026 was published on 16 September 2026, so check clause numbers against the edition your auditor uses.

Version history is a different thing from approval. SharePoint saves a version on every save, which records who changed what, not which version was approved. It also has limits (Microsoft: version history limits):

  • New libraries follow the organization default: 500 major versions with no time limit, unless your admin has changed it.
  • The automatic setting thins out older versions, keeping more recent ones and fewer from further back. That is wrong for controlled documents, because the algorithm decides which versions are least likely to be needed without knowing which one was approved.
  • The manual setting keeps a set number of major versions, optionally deleting versions older than a set number of days. The admin screens won't go below 100 versions or 30 days.
  • Changing the organization default only affects libraries created afterwards (Microsoft: organization version limits), so check each existing library that will hold controlled documents.

Your Microsoft 365 admin can check a library in a minute with the SharePoint Online Management Shell for PowerShell. The first line connects to your SharePoint admin center. The second only reads the setting.

Connect-SPOService -Url https://yourcompany-admin.sharepoint.com
Get-SPOListVersionPolicy -Site https://yourcompany.sharepoint.com/sites/Quality -List "Controlled Documents"

If that library is on automatic, this command moves it to a fixed count with no time limit. It applies to versions created from now on and cannot bring back versions already deleted.

Set-SPOListVersionPolicy -Site https://yourcompany.sharepoint.com/sites/Quality -List "Controlled Documents" -EnableAutoExpirationVersionTrim $false -MajorVersionLimit 500 -MajorWithMinorVersionsLimit 20 -ExpireVersionsAfterDays 0
Version and approval requirements and how to test them
RequirementHow to test it in the demoPass or fail signal
Shows what was in force on a dateLoad your document with the known history. Ask which revision was current on a date you name, who approved it, and when.Pass: answered in under a minute, with approver and date recorded by the system. Fail: scrolling through version history and guessing from "modified" dates.
Superseded revisions are markedOpen an old revision from a search result or a saved link.Pass: clearly marked as superseded, with a link to the current one. Fail: it looks identical to the current revision.
Approval is recorded against the exact revisionRun one approval live, then edit the approved document.Pass: approver, date and version captured, and the edit starts a new draft while the approved revision stays unchanged. Fail: approval is an email, or a status column anyone can change.
Version limits cannot delete evidenceAsk to see the version setting on the library that will hold controlled documents.Pass: a count, or a retention rule, that you chose. Fail: automatic thinning, or nobody knows.

6. Retrieval and verification

OCR accuracy figures are measured on the vendor's documents. Measure on yours, against what a person reads. Load your 20 worst scans, search for each of the 60 phrases exactly as your colleague wrote them down, and count how many find the right page. Our default bar: nothing missed on a clean typed page, and on the bad scans, no misses on the numbers people actually search for, such as part, drawing and invoice numbers. A missed name on a faded fax is forgivable. A missed invoice number means that document is effectively lost.

Then ask where the recognized text is stored. It can live in the product's search index or in the file itself, as a text layer inside the PDF. Only the second leaves with you: if you change systems later, index-only text stays behind and your scans go back to being pictures.

For any AI-generated answer, click the citation. It should open the document at the page and passage used, not just name the file. If it can't, checking an answer means re-reading the whole document, and people stop checking.

Retrieval requirements and how to test them
RequirementHow to test it in the demoPass or fail signal
Finds text in your worst scansSearch for the 60 phrases, exactly as written.Pass: meets the bar above. Fail: the vendor says your scans are "too poor", which describes your archive rather than an exception.
Answers link to the exact passageClick the citation on three AI answers.Pass: opens at the page with the passage highlighted. Fail: it cites the whole file, or nothing.
Recognized text leaves with youExport one scanned file and search inside it on your own PC.Pass: the text is selectable and searchable. Fail: an image-only PDF.

7. Retention and disposal

A retention requirement has three parts: how long each type of document must be kept, what stops it being changed or deleted in that time, and what evidence remains once it is destroyed. The periods come from your legal and tax advisers. The system's job is to apply them without relying on people to remember.

In Microsoft 365 this is Microsoft Purview, and its two kinds of label are easy to confuse:

  • Sensitivity labels classify how confidential something is and can enforce protection such as encryption and watermarks (Microsoft: sensitivity labels). They say nothing about how long to keep it.
  • Retention labels keep or delete content after a set period (Microsoft: retention). An item carries one retention label at a time and can have one sensitivity label as well.
  • A retention label can also declare an item a record, which locks it against deletion and, while locked, against editing (Microsoft: declare records). A regulatory record is stricter: once applied, nobody can remove the label, not even a global administrator. Test it on copies, never on live documents, and decide in advance who may apply it.
  • Retention has a storage cost. When someone deletes a retained file in SharePoint, or edits one covered by a retention policy, a copy goes to the site's Preservation Hold library, and that library counts against the site's storage (Microsoft: retention for SharePoint).

For records, the international reference is ISO 15489-1:2016, which expects records to be authentic, reliable, complete and unaltered, and usable. In demo terms: can the system show that a record has not changed since it was declared, and who did what to it before then?

Retention requirements and how to test them
RequirementHow to test it in the demoPass or fail signal
Retention periods apply by document typeSet a period for a test document type, then upload a document of that type.Pass: the label is applied automatically from the type, location or content. Fail: users must remember to pick it.
Records cannot be quietly altered or deletedDeclare a test document a record. Try to edit and delete it as an ordinary user, then as an admin.Pass: blocked, and the attempts appear in the audit log. Fail: an admin can delete it without trace.
A legal hold overrides disposalAsk the vendor to set up a test folder whose retention period has already ended. Put a hold on it, then run disposal.Pass: nothing in the folder is destroyed and the hold is visible to admins. Fail: holds are tracked in a spreadsheet.
Disposal leaves evidenceAsk to see the record of an item destroyed under a retention rule.Pass: what was destroyed, when, under which rule and who approved it. Fail: it simply disappears.

8. Integration and migration

For integration, two requirements carry most of the weight: links from your ERP, CRM and project tools must survive a rename or a move, and other systems must be able to file documents with metadata and no person involved. Designing those connections is covered in our guide to connecting business systems without replacing everything.

Migration is where fine print costs the most. The gotchas for a move into SharePoint or OneDrive, as of September 2026:

  1. Path length. The whole decoded path, including the file name, can't exceed 400 characters (Microsoft: restrictions and limitations). Once people sync a library to their PCs, a second limit applies: past 260 characters, a file won't open in Office desktop apps, and the local sync folder adds its own prefix, such as C:\Users\name\Company Name\Site - Documents\ (Microsoft: path length limits). A file that migrated cleanly can still refuse to open in desktop Excel.
  2. Characters and names. Not allowed: the characters " * : < > ? / \ |, leading or trailing spaces, the names .lock, CON, PRN, AUX, NUL, COM0 to COM9, LPT0 to LPT9, _vti_ and desktop.ini, and any name starting with ~$. Windows refuses the same characters, so they mostly turn up in files that came from Macs or other cloud drives.
  3. Dates and authors. Uploading through the browser or dragging files into a library creates new files as far as SharePoint knows, so it stamps its own values: Created and Modified become the upload time, and Created By becomes the uploader. Migration tools such as Microsoft's SharePoint Migration Tool use a migration interface that is allowed to carry the original dates across. A Windows file share records an owner rather than an author, so check what your tool puts in Created By.
  4. Permissions. Microsoft's tool maps file-share permissions item by item: Read to Read, Write to Contribute, Full Control to Full Control. A share with years of per-folder exceptions arrives as thousands of unique permissions, straight into the limits in section 3. Simplify the share's permissions before moving it.
  5. Invisible files. If the target library requires check-out, files loaded by hand can stay checked out and visible only to the uploader (section 4).
  6. Leaving again. Microsoft notes that downloading files from a SharePoint library does not bring their document properties, permissions, links between files, workflow information or version history (Microsoft: manual migration). Every product has an equivalent. Ask what an export contains before you sign.

Before any migration, run this against the folder you plan to move. It only reads, and anyone comfortable opening PowerShell on a PC that can see the share can run it. Edit the three lines at the top, set the target to where the files will land (the 400-character limit counts that part too), then open the CSV in Excel and filter the Flags column.

# Pre-migration check. Read-only: lists problems, changes nothing.
$source = "\\fileserver\Projects\Migration test"
$target = "sites/Projects/Shared Documents/Migration test"
$out    = "$env:USERPROFILE\Desktop\premigration-check.csv"

$blocked = '^(\.lock|CON|PRN|AUX|NUL|COM[0-9]|LPT[0-9]|desktop\.ini)$'
Get-ChildItem -LiteralPath $source -Recurse -Force -ErrorAction SilentlyContinue -ErrorVariable unreadable |
ForEach-Object {
  $rel   = $_.FullName.Substring($source.Length).TrimStart('\')
  $dest  = "$target/" + ($rel -replace '\\', '/')
  $flags = @()
  if ($dest.Length -gt 400)              { $flags += 'path over 400' }
  if ($_.Name -match '["*:<>?/\\|]')     { $flags += 'invalid character' }
  if ($_.Name -match '^\s|\s$')          { $flags += 'leading or trailing space' }
  if ($_.Name -match $blocked -or $_.Name -like '~$*' -or $_.Name -like '*_vti_*') { $flags += 'blocked name' }
  [pscustomobject]@{
    Path         = $rel
    Kind         = $(if ($_.PSIsContainer) { 'Folder' } else { 'File' })
    Modified     = $_.LastWriteTime
    TargetLength = $dest.Length
    Flags        = ($flags -join '; ')
  }
} | Export-Csv -LiteralPath $out -NoTypeInformation -Encoding UTF8
"$($unreadable.Count) items could not be read"

If the last line reports anything other than zero, run the script again in PowerShell 7. Older Windows PowerShell can fail to read paths longer than 260 characters, which are exactly the files you are looking for.

The count is the other half. This lists the number of files in each top-level folder. Run it before the move and again against the synced library afterwards.

Get-ChildItem -LiteralPath "\\fileserver\Projects\Migration test" -Directory | ForEach-Object {
  [pscustomobject]@{
    Folder = $_.Name
    Files  = @(Get-ChildItem -LiteralPath $_.FullName -Recurse -File -Force -ErrorAction SilentlyContinue).Count
  }
}

Treat a migration tool's success total as a claim and its list of skipped files as the real report. Then open ten files at random, including two from the longest paths, and check that the names and dates came across.

Integration and migration requirements and how to test them
RequirementHow to test it in the demoPass or fail signal
Links survive renames and movesPaste a document link into a record in your ERP or CRM. Rename the document, move it to another folder, then click the link.Pass: it still opens. Fail: not found.
Migration reports what it skippedHave the vendor migrate your test folder before the demo, with their standard tool.Pass: file counts match per folder, dates match on ten spot checks, and every skipped file is listed with a reason. Fail: a success total only.
You can leave with everythingExport one folder during the demo.Pass: the files, a metadata file and all versions. Fail: files only, or "our services team handles exports."

9. Failure behavior

People decide whether to trust a system by what it does when something goes wrong. Over-sharing is the hardest failure to see, because an over-permissive setting produces no complaints, so it needs a report.

Failure behavior requirements and how to test them
RequirementHow to test it in the demoPass or fail signal
Rejected files are reported, not droppedUpload a file with a blocked name, and one whose path is over the limit.Pass: an error that names the file and the rule it broke, and the item appears in a failure report. Fail: silently skipped, or a generic error.
Work continues during an outageAsk what staff can open if the service or your internet connection is down, and how edits made offline are reconciled.Pass: a specific answer, such as synced copies of named libraries and a stated rule for conflicting edits. Fail: "it doesn't go down."
Over-sharing is found without a complaintAsk how an admin would find a folder shared with the whole company, or with anyone who has the link.Pass: a scheduled report with a named owner who reviews it. Fail: waiting for someone to notice.

The 30-minute demo script

Send each vendor the test pack and this note a week ahead. Asking in advance is fair to them, and it rules out a scripted demo.

Please load the attached files into a trial environment exactly as provided, without renaming or cleaning them, and migrate the folder "Migration test" with your standard tool. Bring that tool's report of skipped files. In the demo we will ask you to do these live: answer five questions we type; search for phrases from our scans; sign in as a test user with no access to one file and search for it; show which revision of a document was in force on a date we give; declare a record and try to delete it; and export one folder with its metadata and versions. We will score each step on the day.

  1. Minutes 0 to 5, migration: compare file counts per folder, open the longest path, read the skipped-file report.
  2. 5 to 10, questions: you type all five, including the unanswerable one.
  3. 10 to 14, OCR: ten of the 60 phrases, chosen at random.
  4. 14 to 19, permissions: search and the indirect question as the test account, then grant, revoke and start the clock.
  5. 19 to 24, versions: the date-in-force question, one live approval, then an edit to the approved revision.
  6. 24 to 27, retention: declare a record and try to delete it as an admin.
  7. 27 to 30, exit: export one folder and take the files with you.

Score each table row pass or fail on the day. Anything the vendor will "follow up on" is a fail until it arrives in writing. For vendors still in the running, run all 60 phrases and the access-removal timing afterwards in a trial.

If an existing product passes, buy it and spend the budget on configuration and migration, which is usually cheaper to run than anything built. If every candidate fails the same rows, typically permissions, integration or answers you can check, you have found the part worth integrating or building, and our comparison of integrating, replacing or building helps you decide which.

If you have run these tests and want a second opinion, send us the scored tables, the vendor's skipped-file report and your five questions. We would look first at the permission and version rows, because those failures stay invisible until an audit or a leak finds them. Our internal AI systems work starts from that evidence and tells you whether configuration will close the gaps or something needs to be built.

Build with Adamant Code

Is your business outgrowing its tools?

Bring one workflow or software problem. We’ll discuss where your current setup falls short and the next step worth exploring.

Talk through your workflow
A Document Management System Requirements Checklist You Can Test in a Demo | Adamant Code