To choose a document management system, start with the work your team needs to complete: finding the right contract, approving an invoice, controlling access to employee records, or retrieving an older version. Turn those tasks into acceptance tests, compare the shortlisted systems against the same tests, and choose the one your users can operate reliably.

A long feature list is useful only when the features solve your problems. This guide explains how to move from requirements to a tested decision. For a smaller-business buying brief, see our SME buyer’s guide; for a feature checklist, use the 15 online DMS requirements.

1. Define the problem before choosing the software

A document management system combines a document repository with controls such as metadata, permissions, version history and workflows. Decide which of those controls you need beyond your current shared folders or cloud storage.

Interview the people who create, approve, retrieve and administer documents. Write down where work stops: missing information, unclear ownership, duplicate copies, manual chasing, or access that is difficult to remove. Select three representative processes for your evaluation.

Give each requirement an owner, a priority and a pass condition. “Good search” is vague. “A colleague can find a scanned invoice using its supplier and invoice number” is testable.

2. Decide how the system must be deployed and accessed

Compare cloud and on-premises options against your IT capacity, connectivity, data-location requirements and recovery arrangements. Ask who operates backups, installs updates, handles incidents and restores data. Separate availability commitments from backup and recovery commitments.

Test access from the devices your staff actually use, including mobile devices where relevant. Check identity integration, onboarding and removal of users, external collaboration, and any restrictions on access from untrusted networks. Confirm the exact deployment and plan with the vendor before signing.

3. Use the same demonstration script for every vendor

AreaWhat to testEvidence to request
Search and metadataFind a document by a custom field and by text inside a supported scan.Results from your sample files; supported formats and OCR languages.
PermissionsGive a reviewer access to one folder, restrict changes, then remove access.The resulting permissions and a test from the reviewer’s account.
Version controlUpload a revision, identify the current version and retrieve an earlier one.Version history and the downloaded files.
WorkflowsRun approval and rejection paths, including an absent approver.Task status, history and the handling of overdue work.
Records lifecycleApply a test retention rule and an exception.The start-date rule, planned action and exception behaviour.
Migration and exitImport a sample with metadata and export a usable copy.A reconciliation report and clear export limitations.

Use anonymised or non-sensitive sample documents. Include awkward cases: similar file names, incomplete metadata, a poor-quality scan, a large folder and a user who should have no access. Ask ordinary team members to repeat the tasks after the demonstration.

4. Check how Folderit supports those tests

Folderit provides custom metadata fields and folder templates, file version history, and approval, acknowledgement and signing workflows. Templates can give incoming resources a consistent set of fields; required fields help users identify missing information.

Live Search and Deep Search serve different tasks. Deep Search can search supported document content using OCR and indexing, as well as metadata and other indexed information. Test your formats and languages: XLSX content is not included in Folderit’s OCR content search.

Permission levels include Previewer, Viewer, Editor, Upload-only and, on the applicable plan, Custom permissions. A Previewer can review supported documents without downloading; a Viewer can download. Check the scope of a permission as well as its name.

Documented integrations include Microsoft Office 365, Outlook, DocuSign, Microsoft Entra ID, Okta and Google SAML. Folderit also provides a public API for custom connections. Confirm licensing, configuration and any integration-specific limits against your intended workflow.

5. Evaluate security and regulatory fit with evidence

Ask for the vendor’s current security documentation, relevant certification scope, contractual commitments, data-processing terms and recovery arrangements. Test access control, user removal and audit-log retrieval. Folderit’s Security Policy settings include enforced two-factor authentication and IP restrictions; its global audit log supports filtering and export.

A DMS supports your controls; it does not decide which laws apply to your organisation. Have the responsible owner confirm retention periods, lawful access, data location and any sector-specific requirements. For personal data, the European Commission explains that GDPR requires purpose-based retention and appropriate security.

6. Compare the complete operating cost

Include the subscription or licence, storage, user and collaborator allowances, implementation, migration, training, integrations and support. Ask about charges for expansion and exporting data. A cheaper plan can cost more overall if it leaves staff manually correcting metadata or chasing approvals.

Use a simple scoring method: mandatory requirements are pass/fail; useful features receive a weighted score. Record what was demonstrated, what requires configuration and what remains unproven. Do not let optional features compensate for a failed mandatory requirement.

7. Make the decision after a pilot

Run one complete process with a small group. Measure retrieval time, missing metadata, failed permissions tests and approval completion. Confirm an implementation owner, training plan and migration and cutover plan before rollout.

The right system is the one that meets your required controls, fits your budget and remains usable in daily work. Start a Folderit trial and test it with the same acceptance criteria you use for every shortlisted system.