Auditing an existing documentation space
Before I touched the structure, I needed to know what was actually in the space. Redesigning it without doing that first just moves the same mess into better-looking folders. I've done that the wrong way round before, on a smaller project, and had to go back and redo it.
Where I started
83 pages, going back six years, no single owner across the whole space. A few things stood out fast.
Three separate pages walked through "how to add a new site," each written by a different engineer at a different point, and each one slightly wrong about something the others got right. The topology diagrams hadn't been touched since a data-centre migration two years earlier, and they were still linked from the space's homepage as if they were current. Nineteen pages had no owner listed at all – either the field was left blank, or the person who wrote them had since moved teams. And the procedure people actually followed for a couple of common tasks wasn't written down anywhere; it lived in a Slack channel and in two engineers' heads.
None of that's unusual for a space that's grown for six years without anyone responsible for its upkeep.
How I went through it
I went page by page and sorted each one into Keep, Update, Merge, or Archive:
- Keep – the content was accurate and someone was already using it.
- Update – the topic still mattered but the detail was wrong or missing.
- Merge – two or three pages said the same thing, sometimes contradicting each other, and needed to become one page.
- Archive – the underlying system or process didn't exist anymore.
My first instinct was to delete the Archive pile outright – it was outdated, why keep it. That's not a call to make alone, though: from a compliance angle, some of that content needed to stay findable for audit purposes even once it stopped being current. So I moved it into a separate Archive space instead of deleting it: out of the way, but not gone. That's the version that made it into the final structure.
Two flags mattered more than the Keep/Update/Merge/Archive call itself: whether a page had a named owner, and whether it had ever been reviewed. A page can be Keep-worthy today and still be one departure away from going stale, if nobody's accountable for checking it.
Tracking it
| Page | Owner | Last Updated | Status | Action |
|---|---|---|---|---|
| Adding a New Site (v1) | – (left the team) | Mar 2022 | Superseded by two other versions | Merge |
| Adding a New Site (v2) | – | Nov 2023 | Most current of the three | Merge (becomes the base page) |
| Site Topology Diagrams | – | Aug 2023 | Predates the DC migration | Update |
| Change Management Process | Owned, actively maintained | Jun 2026 | Accurate | Keep |
| VPN Setup (Legacy) | – | Jan 2021 | Decommissioned provider | Archive |
| Incident Response – Core Switch Failure | – | Feb 2024 | Correct steps, split across two pages | Merge |
| Naming Conventions | – | Unknown | No review date on record | Update |
What came out of it
Two things fed directly into the next stage: a ranked list of what needed merging or updating before it went anywhere near the new structure, and a list of ownerless pages that became the starting point for assigning ownership.
See Redesigning the Space Structure for what I built once the audit was done.
Documentation audit framework
When auditing a documentation space, I use a systematic framework to identify what needs work and prioritize remediation by risk.
Audit methodology
Inventory → Assess → Risk-Rate → Prioritize → Remediate → Approve → Monitor
- Inventory – Catalog every document with its metadata (owner, last update, audience, criticality)
- Assess – Evaluate each document against quality criteria
- Risk-Rate – Score each document by risk impact
- Prioritize – Focus on highest-risk items first
- Remediate – Fix accuracy, structure, ownership, review cycles
- Approve – Get sign-off from owner before publishing
- Monitor – Track changes and refresh cycles ongoing
Documentation risk assessment
For each document in the audit, I assess seven dimensions of risk:
| Dimension | Assessment Question | Low Risk | Medium Risk | High Risk |
|---|---|---|---|---|
| Accuracy | Is the information still correct? | Reviewed within last 6 months | Reviewed 6–12 months ago | Not reviewed in 12+ months; contradicts other docs |
| Completeness | Are required steps or controls missing? | All critical steps present | Some guidance missing | Gaps in procedure; missing controls |
| Consistency | Does it contradict other documentation? | Consistent terminology & logic | Minor variations with other docs | Directly contradicts; creates ambiguity |
| Ownership | Is there a responsible owner? | Named owner with backup | Named owner; no backup | Ownerless; nobody accountable |
| Currency | Has it been reviewed recently? | Review completed fewer than 6 months ago | Last reviewed 6–12 months ago | No review date; appears obsolete |
| Usability | Can the intended audience actually follow it? | Tested with users; clear structure | Mostly usable; minor clarity issues | Confusing; jargon-heavy; untested |
| Control | Is the document versioned and approved? | Approved version tracked; change history | Version exists; approval unclear | No version; no approval record |
Risk scoring: For each dimension, score 1–3 (low, medium, high). Average the seven scores to get overall document risk.
Example audit matrix
| Document | Owner | Last Updated | Accuracy | Completeness | Consistency | Ownership | Currency | Usability | Control | Risk Level | Action |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Adding a New Site (v1) | – | Mar 2022 | High | Medium | High | High | High | Medium | High | HIGH | Merge with v2 |
| Adding a New Site (v2) | Named (FM Ops) | Nov 2023 | Low | Low | Low | Low | Low | Low | Low | LOW | Keep |
| Site Topology Diagrams | – | Aug 2023 | High | High | Low | High | Medium | Medium | High | HIGH | Update + assign owner |
| Change Management Process | Named (Compliance) | Jun 2026 | Low | Low | Low | Low | Low | Low | Low | LOW | Keep |
| VPN Setup (Legacy) | – | Jan 2021 | High | High | Medium | High | High | High | High | CRITICAL | Archive (retain for compliance) |
| Incident Response | – | Feb 2024 | Low | High | High | High | Medium | Low | High | HIGH | Merge pages + assign owner |
What this reveals
Documents scoring "HIGH RISK" or "CRITICAL" across multiple dimensions indicate:
- Ownership gaps – Nobody is accountable for staying current
- Accuracy risk – Information may be outdated or wrong
- Operational risk – Users may be following incorrect procedures
- Compliance risk – Audit trail may be broken
- Organizational debt – These documents worsen without intervention
The risk matrix allows a Facilities Manager or documentation owner to see at a glance which documents need urgent attention and which can be left stable.
Using the audit for prioritization
Once you've scored all documents, prioritize remediation by:
Risk × Operational Importance × Frequency of Use × Regulatory Impact
For example:
- An ownerless SOP used by field teams daily that affects safety = Fix first
- A design document with one named owner, reviewed 9 months ago = Review and update
- An archived procedure from 2021 = Retain for compliance; monitor only