Technical field guide
The sections below preserve the service-specific depth behind eDiscovery Data Discovery & Source Mapping, edited for the current national practice and its documented engagement model. Methods are selected for the source, authorization, system state and assigned specialty. No single tool or artifact establishes a conclusion, and legal, regulatory or certification decisions remain with the responsible authority.
What This Solves
Most discovery disputes do not start in the courtroom. They start weeks earlier, when a key Salesforce org goes unidentified, a Slack workspace created during a merger never makes it onto the custodian list, or a Snowflake data warehouse turns out to hold years of transactional records that opposing counsel was expecting to see.
Source mapping is designed to surface those systems before collection begins. Before any collection begins, GDF analysts conduct structured source interviews, deploy connector-based discovery tools against known cloud environments, and produce a documented data inventory that gives counsel a defensible picture of where relevant ESI lives, who controls it, and what has to be preserved. The result is better scoping, fewer late-breaking disclosures, and a stronger foundation for every downstream step in the matter.
What We Identify
Enterprise data does not stay in one place. A single custodian may have relevant ESI across a primary email account, a personal OneDrive, a shared Teams channel, a Slack workspace they joined through a partner tenant, a Salesforce account with embedded email logging, and a Box folder shared with outside counsel. GDF maps all of it.
Shadow IT is a particular challenge in complex matters. Employees frequently adopt SaaS tools that IT never formally approved: a department using a consumer version of Zoom for file sharing, a project team on an unregistered Notion workspace, or a sales group keeping deal notes in a personal Google Drive. GDF's source discovery process specifically looks for these repositories, not just the ones that appear on the initial interview list.
Platforms GDF routinely identifies and maps include:
- Microsoft 365: Exchange Online, SharePoint, OneDrive, Teams, Viva Engage (Yammer)
- Google Workspace: Gmail, Drive, Chat, Meet recordings, Shared Drives
- Slack: standard channels, private channels, direct messages, Slack Connect workspaces
- Salesforce: email logs, activity records, case notes, documents, chatter feeds
- Snowflake and Databricks: analytical data warehouses, data lakehouse environments
- AWS: S3 buckets, RDS databases, CloudTrail and CloudWatch logs
- Azure: Blob storage, SQL databases, Active Directory audit logs
- Oracle and SAP: ERP records, financial data, HR modules, transaction histories
- SharePoint on-premises and hybrid deployments
- Box: content repositories, comments, version histories, shared links
- Zoom: meeting recordings, transcripts, chat histories, whiteboards
- Backup systems, archive tapes, and decommissioned server images
Custodian-Source Alignment
Identifying sources is only half the work. GDF pairs each source with the custodians who have access, the data types each source holds, and the time periods for which data is available and recoverable. This custodian-source alignment document serves as the authoritative reference for scoping preservation and collection decisions throughout the matter.
For matters with large custodian populations, GDF uses structured intake questionnaires alongside automated account enumeration to cross-check self-reported information against actual system activity. An employee may not recall that they had access to a particular SharePoint site, but the access logs will show it. GDF reconciles both.
Defensibility and Documentation
Data discovery work is only as valuable as its documentation. Courts and opposing parties increasingly scrutinize not just what was collected, but how the producing party determined what existed in the first place. GDF delivers a written Source Identification Report that documents the methodology used, the sources identified, the custodians interviewed, the connector queries executed, and the scope decisions made by counsel.
This report gives counsel a factual record to cite in Rule 26(f) conferences, discovery responses, and any subsequent motion practice about the adequacy of the producing party's search. Source-enumeration queries should be logged with timestamps. Relevant source interviews should be documented. The report can be supplemented as new information surfaces.
Deliverables
At the conclusion of source mapping, GDF delivers:
- Source Identification Report: a written summary of all sources identified, the method of identification, and their relevance to the matter
- Data Map: a structured inventory linking each source to data type, custodians, date range, and collection status
- Custodian-Source Matrix: a reference document aligning each custodian to their data footprint across all identified systems
- Shadow IT Log: documentation of any unauthorized or unapproved platforms identified during discovery
- Scope Confirmation Memo: a record of counsel's in-scope and out-of-scope determinations, suitable for production or disclosure if required