A completed export does not establish that a collaboration record is complete. The visible conversation may span messages, linked files, edits and participants in separate systems. Before sending a large enterprise collection to review, reconcile what the scope called for with what each export actually contains.
Build a source map around conversations and participants
Counsel defines preservation scope. Technical owners identify the tenants, workspaces, accounts, channels, shared mailboxes and connected file stores involved. Record relevant retention settings and account lifecycle changes before a departure, license removal or migration changes availability.
Microsoft documents that Teams message and file evidence can require different locations, including Exchange, SharePoint and OneDrive. Private and shared channels introduce further distinctions. Slack export availability depends on the plan, permissions and export type. Confirm current provider support for the actual environment rather than assuming that one administrator's download covers every conversation.
Retain relationships the reviewer will need
Preserve available message and channel identifiers, thread relationships, participant context and file references. Check whether linked attachments are included, merely referenced or unavailable. An exported conversation with a broken attachment link can omit the document that gave the exchange meaning.
- Compare expected participants and channels with the export inventory.
- Retain native packages and provider manifests before conversion.
- Record date filters, time conventions and processing options.
- Test representative threads and attachments in the intended review format.
- Document unsupported content, failed items and collection gaps.
Keep content preservation separate from activity evidence
A content hold does not automatically preserve every identity or audit source. Capture time-sensitive administrative and access records through the appropriate method. If containment or account changes occur during collection, record them so a later chronology can distinguish response activity from the conduct being examined.
The handoff should include collection receipts, source counts, validation results and an exception register. Counts can change during conversion or deduplication; explain the transformation instead of presenting unlike totals as matching. Preserve the original material so a disputed output can be reproduced.
See cloud collections, review-platform support and the enterprise cloud source map.
Provider documentation
Microsoft Teams eDiscovery and Slack import and export options.