Mattia Musazzi

Tracked Regulatory Document Distribution on SharePoint

How we made read-receipt tracking of regulatory documents automatic for ~5,000 employees with SharePoint, SPFx and Power BI, eliminating non-compliance risk.

Selective distribution of regulatory documents on SharePoint with tracked read receipts and compliance monitoring in Power BI

A tracked read receipt is the documentary evidence that a person required to know a procedure has received, opened and confirmed it with an explicit action, recorded with a date and identity. For a regional railway transport company with around 5,000 employees we made it automatic on SharePoint, SPFx and Power BI: the risk of non-compliance through missing traceability is now eliminated.

Proving that everyone required to know an operating procedure, a ministerial decree or a safety rule has received and confirmed it is a regulatory obligation. The company handled it with manual processes, no automatic traceability and no real-time visibility on compliance status. Unlike business procedures management on SharePoint — which governs the creation and approval of documents — here the problem was downstream: selective distribution and proof of acknowledgement.

The problem: regulatory traceability across 5,000 people

Not every document concerns every employee. A technical regulation for train drivers should not reach administrative staff; a station safety procedure does not concern onboard crew. Distribution must be selective, based on the functional org chart, not sent to the whole company population.

The requirement was precise: distribute documents to the right people and record the acknowledgement so that the record holds value as documentary evidence. Without it, every external check became a risky manual operation. The lack of traceability was not just an operational problem: it exposed the company to concrete risk in a regulatory audit. The starting point was to zero out that risk.

The solution: SharePoint, SPFx and Power BI, tailored

We built an application on SharePoint Online in three layers, each with a distinct responsibility.

Three-layer architecture: document repository on SharePoint, an SPFx web part for read receipts and a Power BI report for compliance monitoring

Document repository on SharePoint Online

Regulatory documents are uploaded with a structure by thematic area — safety, operational, administrative, technical. The metadata on each document determines who it must be distributed to, based on functional classification rather than the general organisational structure, with the same governance rigour behind increasing compliance with SharePoint.

SPFx web part for distribution and read receipts

The core of the application is a custom web part built with the SharePoint Framework. When a document is published, the system crosses its thematic area with the functional matrix of the org chart and automatically identifies the recipients. Each user finds the pending documents in their personal section. The read receipt requires an explicit action — opening the document is not enough, it must be confirmed — and is recorded with a timestamp and the user’s identity.

Power BI report for compliance monitoring

For compliance officers, legal and HR, a Power BI report shows the read-receipt status of every published document in real time: how many people have completed, how many are pending, who is missing. It is navigable by document, by functional area and by individual user. In an external review, the evidence is immediately available.

The results

The application is used by around 5,000 employees. The distribution and read-receipt tracking process is fully digitised: the risk of non-compliance through missing traceability is eliminated. Compliance officers have real-time visibility on the status of every distributed regulatory document; in an audit the evidence is structured, exportable and accompanied by certain time metadata, with nothing to reconstruct after the fact.

The most critical phase of the project was not the technical development but the preliminary analysis. The company’s functional org chart is an articulated structure, with partially overlapping areas and cross-cutting roles. Defining precisely who should receive what, by which criteria and with which exceptions, required in-depth working sessions with internal stakeholders before writing a single line of code. A technically correct application that distributes documents to the wrong people does not solve the problem: it moves it.

Who this approach is for

The model suits any organisation with regulatory obligations that require documentary evidence of acknowledgement: public transport, utilities, pharmaceutical, banking, regulated manufacturing. The combination of org-chart-based selective distribution, tracked acknowledgement and a monitoring report meets compliance-audit requirements, and is close to the approach used to manage regulations with SharePoint and Syntex.

If your organisation distributes regulatory documents without structured traceability, we can help you build a tool that guarantees it. Contact us for an assessment →

Mattia Musazzi

Written by

Mattia Musazzi

Modern Work · Dev4Side