Turn the matter into a collection specification
Begin with the questions the review must support, the relevant period and the people or business functions likely to hold material. Identify mailboxes, collaboration spaces, shared drives, devices and external systems. Record account aliases, ownership changes and departed employees. A list of personal mailboxes alone may miss a transaction negotiated in a shared channel or approved through a workflow application.
Agree the authority, privacy constraints, access permissions and handling requirements with the responsible legal and organisational stakeholders. Separate the technical collection specification from legal decisions about relevance, privilege and disclosure. Set a change process: new custodians, sources or time periods should be approved and recorded, so the final delivery can be reconciled with the instructions.
Distinguish preservation from collection
Preservation aims to protect relevant information against loss or alteration; collection creates material for examination. They require separate checks. In a hosted platform, verify which locations a hold covers, whether it is active and what exclusions remain. A search export does not demonstrate that the original source will remain available next month, and a preservation setting does not establish that every required item has been collected.
Record the platform, account identifiers, collection method, query, time zone, operator and execution period. Capture warnings, failed locations and available process reports. For dynamic sources, explain how edits, deleted items, versions and linked attachments are represented. Platform capabilities, permissions and licensing can affect the result, so validate the actual tenant rather than assuming documentation describes its configuration.
Test whether the search finds what matters
Use known relevant items to challenge the search design. Include aliases, language variants, date boundaries and representative attachment types. Ask what the query cannot evaluate: encrypted files, unsupported formats, unindexed items, images without usable text or content outside the selected sources. A zero-result search is meaningful only within those limits.
Separate discovery searches used to understand the data from the approved collection query. Retain query versions and the reason for revisions. Sample both included and excluded material where authorised, with selection rules that can be explained. If machine-assisted review prioritises documents, preserve the review method and human decisions; a model score should not silently determine legal relevance or privilege.

Preserve relationships and processing history
Keep sufficient context to reconnect a message with its attachments, a document with its versions and an exported item with its source. Deduplication may reduce review effort, but it must not erase the record that the same document occurred in different custodians’ collections. Document the deduplication unit, the metadata retained and the method for recovering those relationships.
Store originals separately from normalised text, rendered documents and working copies. Record processing tools, versions, settings and errors. Cryptographic hashes can support verification that particular delivered bytes match an earlier copy; they do not establish authorship, truthfulness or completeness of the collection. Preserve a clear path from a reviewed document back to the acquired item and its collection record.
Reconcile the delivery before handing it over
Agree a reconciliation model that follows the platform’s counting rules. Search hits, exported messages, attachments, document versions and processed review records may be different units. Explain expected expansions and reductions rather than demanding that every stage has the same count. Investigate unexplained differences and separate empty, failed, excluded and successfully processed items.
Validate a sample of the actual delivered package. Confirm that native files open, text extraction is usable, attachments remain linked, metadata maps correctly and redactions behave as intended in every included representation. A redacted PDF may be undermined by an unredacted native file or text sidecar. Record the recipient, transfer channel, integrity check and acceptance outcome.
Specify useful deliverables and closure
Request the approved scope, source inventory, collection log, processing report, exception register, metadata specification and delivery manifest alongside the evidence. Define how questions and additional collections will be handled. At closure, agree retention, return or disposal with the authorised owner, accounting for any continuing preservation requirement; do not treat delivery as automatic permission to delete.
TRUST-IT can support technical scoping, collection validation, processing and evidence presentation in coordination with your advisers. For an initial discussion, describe the matter, sources, approximate volume and deadlines without sending sensitive evidence through the public contact form. A secure exchange method can be agreed once the handling requirements are understood.
Further reading
- EDRM — Current Electronic Discovery Reference Model
- Microsoft Learn — eDiscovery workflow
- Microsoft Learn — Export items from a review set
Put the guidance to work
Electronic evidence preservation, targeted collection, document processing, technical analysis and support for legal review.
eDiscovery & dispute support