Can an organisation configure automatic deletion?¶
Yes. Administrators can often configure policies or workflows to remove files, messages, logs, backups or accounts when age, status, location or another condition is met.
The system may be the immediate actor¶
A deletion event may identify a policy engine, service account or administrator process rather than an interactive user. The ordinary interface may show only that the item disappeared.
Preserve the rule ID, scope, trigger, schedule, effective dates, creator and approver, change history, execution event and any exception or hold. These records distinguish normal policy operation from a manual deletion or unauthorised rule change.
One rule can affect many records¶
Automatic deletion may operate silently across many accounts. A cluster of removals at the same age or scheduled time can support policy execution. Errors, licence changes and configuration drift may cause partial or unexpected results.
Absence of data may therefore reflect ordinary governance rather than concealment. Equally, a deliberately altered policy can be relevant conduct; attribute the configuration change separately from later automated executions.
Use the historical rule¶
Current settings do not establish what applied during the relevant period. Compare policy history and execution logs with the governing retention policy and any holds or exceptions.
Administrator Priya approves Purview rule RET-22, set to delete documents in SharePoint folder /Temp after the configured age. At 02:00, policy job RUN-551 evaluates object OBJ-8120 and records outcome deleted; forty-two other objects of the same age are removed in the same run. That pattern and the rule history strongly support routine automated deletion. Whether a later change to RET-22 was authorised, and whether Dave deliberately moved the object into /Temp, remain separate propositions.
The next useful comparison is RUN-551 against the versioned RET-22 configuration, approval and change events, service identity, complete run results, exceptions and OBJ-8120 move history.
Current Microsoft automatic-deletion example - checked 3 September 2026
Microsoft Purview retention policies and labels can be configured to delete content automatically at the end of a period, or to begin a disposition review where supported. The historical configuration and execution evidence remain essential because current settings do not reconstruct an earlier run.
The point to remember
Automatic deletion is a system action governed by a historical rule. Establish who configured it, what triggered it and whether this event followed that design.