Skip to content
FRP-130 Fraud & Financial Crime

What should be preserved from cloud version history?

Cloud version history may show how a file changed over time, but viewing or restoring it can alter the account state.

Avoid this assumption: The current file contains everything needed. Earlier versions may show deleted text, previous filenames, different owners, edits, comments or earlier timestamps.

Before opening version history, preserve the current file, page, account, service, document ID, visible version and time.

Record any existing indication that version history is available without navigating into it unnecessarily.

If version history is opened, capture the full list, version dates, times, editors, labels, sizes and provider-generated identifiers.

Record whether times are shown in local time, account time or another zone.

Do not restore, rename, delete or download a version merely to inspect it.

Opening or downloading an earlier version may itself create audit records.

Do not assume a named editor personally made every change. Shared accounts, automation, imports and delegated access remain possible.

Where a version is central to the investigation, specialist or provider support may be needed to preserve the native history and audit context.

Capture any retention warning, missing period, unavailable version or indication that history is limited by account type.

Record whether the version list appears complete, limited, collapsed or filtered, and whether any version is marked current, named, restored or automatically generated.

Preserve any note explaining why a version was created or restored.

Operational takeaway

Preserve the complete version list and identifiers without restoring or altering anything, and treat named editors and timestamps as system records requiring contextual interpretation.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.