Verify classification is working with Purview reporting
You specified that every Woodgrove Bank transaction record at Relecloud must carry an item-scoped sensitivity label, and a Purview specialist implemented that requirement. The label policy is published, the priority conflicts are resolved, and on paper the scheme looks complete. But you can't open every file in the tenant to check, and even if you could, a snapshot today doesn't tell you whether someone quietly downgrades or strips a label tomorrow. Confirming that an implementation matches what you specified is a different job from building it, and Microsoft Purview gives you two separate reporting surfaces to do exactly that.
Guiding question: Purview offers two classification reporting surfaces. One answers "what's labeled right now?" The other answers "how has labeling changed over time?" Before you read further, predict which surface—Content explorer or Activity explorer—answers each question, then check your answer against the reveal below.
Content explorer shows what's classified right now
Content explorer displays a current snapshot of every item in your tenant that carries a sensitivity label, carries a retention label, or matches a sensitive information type. It's the surface you open when the question is "what is classified right now?"—for Relecloud's transaction records, Content explorer is where you confirm that the items you specified as item-scoped actually show the label you expect, without touching a single file yourself.
That inventory spans Exchange, SharePoint, OneDrive, and Teams, since Teams content is stored in the underlying SharePoint sites. One limitation worth knowing before you rely on it: encrypted sensitivity labels don't surface in Content explorer for SharePoint and OneDrive locations. If Woodgrove's transaction records carry an encrypted label and live in a SharePoint document library, Content explorer's count for that location won't reflect them—so a clean-looking snapshot there doesn't necessarily mean nothing is labeled.
Learn more about setup and scope in Get started with Content Explorer.
Activity explorer shows how classification changes over time
Content explorer tells you what's true right now, but it can't tell you whether a label was just added, just removed, or has sat unchanged for months. That's the gap Activity explorer fills. It provides a historical view of what's happening to your labeled content, pulling up to 30 days of activity from the Microsoft 365 unified audit logs. Where Content explorer answers "what is classified right now?", Activity explorer answers "how is classification changing—and is anyone quietly downgrading or stripping labels?"
The activities it surfaces include a label being applied, a label being changed (upgraded, downgraded, or removed entirely), and DLP policy match events. Suppose the finance team's justification-on-downgrade setting from the policy conflict you resolved earlier is working as designed. Activity explorer is where that shows up as evidence: a label-changed event with a justification attached, rather than a silent removal. If someone strips a label from a Woodgrove transaction record without justification, that event appears here too, giving you a trail to investigate instead of a guess.
| Reporting surface | Question it answers | Key limitation |
|---|---|---|
| Content explorer | What's classified right now? (current snapshot) | Encrypted labels don't surface for SharePoint and OneDrive locations |
| Activity explorer | How has classification changed over time? (label applied, changed, or removed; DLP matches) | Up to 30 days of history from the unified audit logs |
Learn more about the activity types it tracks in Get started with activity explorer.
Viewing the tab and viewing the content are two different permissions
Before you go looking for either surface, know that access to them is two-tiered, and the two tiers are easy to conflate. One set of permissions gets you into the Content explorer tab at all—the Compliance Administrator, Security Administrator, or Compliance Data Administrator Microsoft Entra ID roles, or the Information Protection Admin, Analyst, Investigator, or Reader Purview roles. Having one of those roles means you can open the tab and see that it exists.
It doesn't mean you can see what's inside it. Viewing the actual list of classified items and their contents requires a separate, more restrictive permission on top of tab access. An administrator holding only the tab-level role sees an empty or inaccessible list, not because nothing is classified, but because the content-level permission hasn't been granted. That distinction matters directly for the verification role you're in: confirming Woodgrove's transaction records are labeled as specified can require different, tighter permissions than the ones the Purview specialist used to design the labels and policies in the first place. If your view looks empty, check which tier of permission you're missing before you conclude the labeling failed.
You can now confirm, without inspecting a single file by hand, that classification is applied the way you specified it, and that changes to that classification leave a visible trail. That closes the loop on people and content inside Relecloud's own tenant. The open question left is whether Microsoft 365 Copilot honors that same labeling scheme when it grounds its responses in Woodgrove's data, or whether its recognition of those labels has blind spots you haven't tested yet.