Policy-based review, with HR and DPO overlay
Configure it so it has a purpose, a reviewer, and a fairness path — not a licence to watch everyone.

Microsoft Purview Communication Compliance can detect communications that may breach a written policy — for example harassment, threats, or sharing of regulated information. It is not “we spy on staff”. Enabling every template for the whole tenant is how these programmes lose trust and, in a UK organisation, how they become hard to defend.
Ghani Governance configures the product and the overlay around it: which scenarios justify a policy, who may see a match, how HR is involved, and how the DPO can explain the purpose. Product reference: Microsoft’s Communication Compliance documentation.
Each policy has a purpose a non-specialist can repeat. No “monitor everything in case”.
Scope, conditions and reviewers aimed at usable cases, not volume.
A small named set. Matches are not a spectator sport for IT.
Fairness, retention of investigative material, and a path that can be explained if challenged. The DPO is in the design, not a slide at the end.
False positives reviewed before the population grows.
All Purview services · Insider Risk Management · UK and Greater Manchester service area
Behaviours that justify a policy, agreed with HR and the DPO.
Licensing, permissions, related DLP or Insider Risk controls.
One scenario or a limited population first.
Matches, false positives, and whether reviewers can actually act.
Ownership, access reviews, change control.
It must not be. Communication Compliance is for defined policy scenarios — for example harassment, threat, or unauthorised sharing of sensitive information — with named reviewers, a purpose, and HR/DPO overlay. Broad “read everyone’s mail” configurations are how these programmes lose legitimacy.
DLP looks at sensitive content leaving a channel. Insider Risk looks at patterns of user activity. Communication Compliance reviews the content of communications against policy. They can share signals; they are not substitutes, and they should not all be pointed at the same population without a reason.
A small, named set — typically a combination of HR, employee relations, legal or compliance, not the whole security team. We design that access with the DPO in the conversation.
A scoping conversation about what you need to protect, what is already configured, and what must not break.