All storiesSecurity

Legal hold for documents: preserve scope, versions, and custodians

Connect counsel's scope, technical preservation, custodians, verification, and controlled release of a document hold.

Legal hold for documents: preserve scope, versions, and custodians: Counsel scope, Custodian mapping, Preservation controls, Verification.
Security / Office SDK

Implement a legal hold from a documented instruction by the responsible legal authority. Map its records, custodians, versions, and related material to verified preservation controls and procedures. Test cleanup and employee departure. Release only with authorization and after checking overlapping holds and retention obligations.

Obtain a precise instruction

Ask counsel or the designated authority to identify the matter, custodians, date range, information types, and preservation start point. Record who may change or release the instruction. Avoid making legal scope decisions through a storage administrator's interpretation of a folder name. Relevant material can include versions, attachments, comments, exports, and related records in other systems depending on the instruction. Preserve source identifiers and ownership relationships to support later collection. Legal requirements vary, so the procedure should follow the applicable professional advice rather than treating a product setting as a universal legal solution.

Instruction scope, system mapping, preservation tests, and exception ownership.
Figure 1. The platform implements the instruction; it does not define its legal scope.

Record the instruction and its implementation separately

The hold register should distinguish what must be preserved from how the system preserves it. This prevents a technical setting from silently narrowing counsel's instruction. Link the two records through a hold identifier and retain the authority for scope changes.

Instruction recordImplementation record
Matter and authorized issuerControl owner and affected systems
Custodians and information scopeMapped documents, versions, attachments, and exceptions
Start and release authorityActivation time, verification, and authorized release event

The fields are a procedural example, not legal advice or a claim that a platform offers each field. Counsel and records owners should define the applicable scope and evidence. Operators should then identify the actual supported controls and any manual preservation required.

Test a rule change while the hold is active. For example, a version cleanup schedule may be revised or a storage lifecycle policy applied to a new collection. Verify that held material remains excluded according to the approved procedure. Keep an exception queue for material the platform cannot preserve as required. A visible lock on the current document is insufficient evidence if the instruction also covers comments, earlier revisions, or related objects.

Map scope to actual controls

Verify the selected platform's preservation capabilities and the behavior of storage lifecycle rules, version cleanup, account deletion, and ordinary user actions. A visible document lock may prevent editing without preserving every earlier version or external copy. If the platform lacks a required control, design an approved preservation procedure with counsel and records owners, documenting its limitations. Coordinate with backup and storage administrators so routine expiration does not defeat the instruction. Keep operational access restricted and distinguish preservation from granting broader viewing rights. A hold should not inadvertently make confidential matter content available to new users.

Exercise an employee departure

A departing employee owns project documents covered by a hold. Use a test custodian and harmless records to simulate account deactivation, ownership transfer, attempted deletion, version cleanup, and export. Verify that preserved material remains identifiable and retrievable through the approved procedure. Record the relationship between the original custodian and the recovered collection rather than simply assigning every file to an administrator. Test any supporting storage control according to its documented behavior. This example exposes interactions between identity lifecycle and preservation that are easily missed when a hold is tested only on an unchanged active account.

Deactivation, ownership transfer, cleanup, and export tests for held records.
Figure 2. Preservation must survive normal identity and maintenance transitions.

Verify and release deliberately

Maintain a hold register with scope, instruction date, control implementation, verification result, and responsible owners. Review changes such as folder moves, new versions, and custodian departures against that scope. When release is authorized, check whether another hold or retention obligation still applies before restoring routine disposal. Record the authority, time, and affected collection. Do not automatically delete preserved material just because one hold ends. Provide an accountable collection process for legal requests with controlled exports and integrity evidence appropriate to the case, keeping preservation and external disclosure as separate decisions.

Preservation checks

  • Retain counsel's scope and the authority to modify or release it.
  • Map covered records and custodians to verified technical controls.
  • Test deletion, cleanup, account departure, and version retrieval.
  • Review changes and preserve identifiers connecting records to their origin.
  • Release only after checking overlapping holds and retention obligations.

Further reading

Back to all stories

Keep reading.

All stories