What should I ask a cloud provider to preserve?¶
Ask the provider to preserve identified, relevant record categories for the correct account, tenant, service and time range. A request to preserve “the account” may not cover logs, deleted objects or linked products held in separate systems.
Translate the question into record categories¶
If the issue is unauthorised access, relevant categories may include authentication, sessions, tokens, trusted devices, recovery changes, application consent, administrator actions and security alerts. For disputed file activity, consider object metadata, versions, sharing, access, downloads, edits, deletion and recycle-bin records.
Include stable account, user-object, tenant and resource identifiers; known aliases; the justified date range and time zone; and any event, session or correlation IDs. Identify linked services separately where the provider operates distinct products or retention systems.
Preservation is a holding action¶
Preservation seeks to prevent relevant records being lost through ordinary expiry or deletion while the appropriate acquisition process continues. It does not itself obtain the data, guarantee that every category exists or replace the required legal and organisational procedure.
Act with enough specificity for the provider to locate the material, especially where short retention periods may apply. At the same time, keep the scope relevant and proportionate. If time or identity is uncertain, explain the basis for a reasonable window or set of possible accounts rather than using an unexplained blanket request.
Provider acquisition requests address what should later be supplied, which is a separate question from what must first be retained.
The point to remember
Preservation should identify the records at risk, their account and tenant context, and a justified period; it holds evidence while the proper route for obtaining it proceeds.