Every enterprise SharePoint environment needs clearly defined roles, documented responsibilities, and enforced support policies. Without them, ungoverned growth and unclear ownership cause governance failures. This guide defines the essential roles — from farm administrator to site owner — and the support policies EPC Group implements for Fortune 500, healthcare, and government organizations.
Key Facts
- SharePoint governance failures have two root causes: ungoverned growth and unclear ownership.
- Modern SharePoint in 2026 follows the hub-spoke pattern — 1 hub per business unit, 5–15 spoke sites per hub.
- Hub-spoke migrations see 60% faster content discovery and 40% fewer "where do I save this?" helpdesk tickets within 90 days.
- EPC Group has designed admin role frameworks for enterprises with 10,000+ users across regulated industries.
- EPC Group has 6,500+ SharePoint implementations and 29 years of Microsoft consulting experience.
SharePoint 2010 Or 2013 Roles Responsibilities Support Policies From A SharePoint Consulting Perspective
SharePoint Roles, Responsibilities & Support Policies
Every enterprise SharePoint environment needs clearly defined roles, documented responsibilities, and enforced support policies. Without them, ungoverned growth and unclear ownership cause governance failures. This guide defines the essential roles — from farm administrator to site owner — and the support policies EPC Group implements for Fortune 500, healthcare, and government organizations.
Key facts
- SharePoint governance failures have two root causes: ungoverned growth and unclear ownership.
- Modern SharePoint in 2026 follows the hub-spoke pattern — 1 hub per business unit, 5–15 spoke sites per hub.
- Hub-spoke migrations see 60% faster content discovery and 40% fewer "where do I save this?" helpdesk tickets within 90 days.
- EPC Group has designed admin role frameworks for enterprises with 10,000+ users across regulated industries.
- EPC Group has 6,500+ SharePoint implementations and 29 years of Microsoft consulting experience.
Why role definitions matter
Successful SharePoint deployments require clearly defined roles. This applies to SharePoint 2010, 2013, 2016, 2019, and SharePoint Online.
Without defined roles, two failure modes emerge:
- Ungoverned growth — site collections multiply without ownership. Content sprawls across hundreds of unmanaged sites.
- Unclear ownership — no one knows who is responsible for a site, its permissions, or its content lifecycle.
This guide defines the role hierarchy EPC Group implements on every enterprise SharePoint engagement.
SharePoint role hierarchy
Global Administrator
The Global Administrator has full access to all Microsoft 365 services — including SharePoint Online. This role should be held by a maximum of two to four people. It is used for break-glass scenarios and top-level tenant configuration. Day-to-day SharePoint administration does not require Global Admin.
SharePoint Administrator
The SharePoint Administrator manages the SharePoint Online admin center. Key responsibilities:
- Create and delete site collections.
- Configure external sharing settings at the tenant level.
- Manage hub site registration and associations.
- Set storage quotas per site collection.
- Configure search schema and managed properties.
- Review sharing reports and sensitivity label coverage.
Site Collection Administrator
The Site Collection Administrator owns a specific site collection. They handle permissions, site settings, and content lifecycle decisions within their scope. Responsibilities include:
- Grant and revoke access to the site collection.
- Configure site-level sharing settings within tenant policy.
- Manage site features, themes, and content types at the root.
- Review storage consumption and request quota increases.
- Manage retention and disposition of records in the site.
Site Owner
The Site Owner is a business user responsible for a specific team site or communication site. They manage day-to-day permissions and content organization. Key tasks:
- Add and remove members from the site's permission groups.
- Create subsites, lists, and document libraries (within governance limits).
- Apply metadata and content types to libraries.
- Review and clean up inactive content quarterly.
Site Member
Site Members can contribute content — create, edit, and delete items they own. They cannot change site settings or manage permissions. This is the standard role for knowledge workers who use SharePoint for collaboration.
Site Visitor
Site Visitors have read-only access. They can view and download content but cannot add or edit. Use this role for stakeholders who need access to published content without contributing to it.
Support policy framework
EPC Group implements three support tiers for enterprise SharePoint:
Tier 1 — Self-service
- Password resets and basic access requests via the IT portal.
- How-to guidance via the SharePoint intranet training library.
- Site creation requests via a governed Power Apps intake form.
Tier 2 — SharePoint Administrator
- Site collection provisioning and governance review.
- External sharing exceptions and audit log reviews.
- Managed metadata updates and content type publishing.
- Migration assistance for team-level content moves.
Tier 3 — EPC Group Managed Services
- 24/7 monitoring and incident response.
- SharePoint release wave management and change testing.
- Quarterly governance reviews and role recertification.
- Major migration and architecture projects.
Modern SharePoint information architecture (2026)
Modern SharePoint follows the hub-spoke pattern:
- 1 root hub site per business unit — owns navigation, branding, and search scope.
- 5–15 spoke sites per hub — team sites and communication sites connected to the hub.
- Mega-menu navigation tied to Viva Connections for the employee experience layer.
- Sensitivity labels at the hub level drive sharing controls across all spoke sites.
Organizations migrating from flat-IA legacy farms to this pattern see 60% faster content discovery and a 40% reduction in helpdesk tickets within 90 days.
Frequently asked questions
What is a SharePoint Site Collection Administrator?
A Site Collection Administrator has full control of a specific site collection in SharePoint — including all sites, lists, libraries, and permissions within it. This is different from the SharePoint Online Administrator, who manages the tenant level. Most enterprises assign 2–3 Site Collection Admins per hub site.
What is the difference between a Site Owner and a Site Collection Administrator?
A Site Collection Administrator has full control over an entire site collection — including subsites and their permissions. A Site Owner manages a single site within the collection. Site Owners cannot delete the site collection or modify tenant-level settings. Site Collection Admins can.
How many Global Administrators should a Microsoft 365 tenant have?
Microsoft recommends 2–4 Global Administrators maximum. More than 4 increases the attack surface for credential compromise. Global Admin accounts should have dedicated admin workstations, hardware MFA (FIDO2 keys), and should not be used for day-to-day work. Break-glass accounts require separate monitoring.
How do I govern SharePoint site creation?
Disable unrestricted self-service site creation in the SharePoint admin center. Replace it with a governed intake process — typically a Power Apps form connected to Power Automate that creates sites from an approved template with naming conventions, sensitivity labels, and an assigned Site Owner. EPC Group implements this as part of every governance engagement.
Schedule a consultation
EPC Group has designed SharePoint governance frameworks for enterprises with 10,000+ users. Call (888) 381-9725 or request a discovery call to discuss your SharePoint role and governance framework.
Why Organizations Choose EPC Group
EPC Group is a Houston-based Microsoft consulting firm with 29 years of enterprise implementation experience and over 10,000 successful deployments across Power BI, Microsoft Fabric, SharePoint, Azure, Microsoft 365, and Copilot. We serve organizations across all industries including Fortune 500, federal agencies, healthcare, financial services, government, manufacturing, energy, education, retail, technology, and global enterprises.
What sets EPC Group apart is our governance-first approach. Every engagement begins with a security and compliance assessment. Our team of senior architects brings hands-on delivery experience across HIPAA, SOC 2, FedRAMP, and CMMC environments. We own outcomes, not hours.
- Fixed-fee accelerators with predictable pricing and defined deliverables
- Senior architect engagement on every project, not rotating juniors
- Compliance-native delivery for regulated industries
- End-to-end coverage from strategy through 24/7 managed services
- 11,000+ enterprise engagements refined into repeatable, risk-controlled patterns
Call (888) 381-9725 or email contact@epcgroup.net for a free assessment.
SharePoint Architecture: 2026 Considerations for SharePoint 2010 Or 2013 Roles Responsibilities Support Policies From A SharePoin
Modern SharePoint information architecture in 2026 follows the hub-spoke pattern: 1 root hub per business unit, 5-15 spoke sites per hub, mega-menu navigation tied to Viva Connections, and sensitivity-label-driven sharing controls. Flat-IA legacy SharePoint farms migrating to this pattern typically see 60% faster content discovery, 40% reduction in 'where do I save this?' helpdesk tickets, and 100% sensitivity-label coverage within 90 days.
SharePoint Online tenant-to-tenant migration in 2026 is dominated by three approaches: native Microsoft 365 migration tools (free but limited to in-place tenant scenarios), ShareGate (best-in-class for permission preservation across hub-spoke architectures), and AvePoint Migrator (enterprise scale with regulated-industry compliance reporting). EPC Group selection criteria depend on user count, permission complexity, and audit-reporting requirements; typical enterprise migration runs 8-16 weeks at $150K-$450K all-in.
Decision factors EPC Group evaluates
- Hub-spoke information architecture redesign vs legacy flat-IA
- Migration tool selection (Microsoft native vs ShareGate vs AvePoint) by complexity tier
- Audit (Premium) configuration for 6-year retention
- Sensitivity label rollout with auto-classification rules
- Microsoft Purview content explorer for unauthorized PHI/PII discovery
EPC Group covers this topic across the relevant engagement portfolio. Reach the firm at contact@epcgroup.net for a 30-minute architect conversation.