What should be preserved before an account is deleted?¶
Before deletion, preserve the account's identity, current access state, relevant content relationships and the provider's explanation of what the deletion process will change.
Capture the state that deletion may remove¶
Record the service, internal account ID, username, contact details, tenant, profile URL and status. Preserve relevant sessions, linked devices, authentication and recovery settings, administrator roles, connected applications and security alerts. Identify messages, files, folders, transactions, group memberships and sharing relationships that answer the investigative question.
Capture provider warnings about data removal, grace periods, recovery and retained records. Do not start or confirm deletion merely to discover its effects. Consider proportionate native export, provider preservation, organisational records or specialist acquisition first.
Treat deletion as an evidential event¶
If safeguarding, security, employment or policy needs require deletion, assess whether a narrower action can address the risk. Where delay is unsafe, record why and preserve what is practicable. Document the authority, operator, exact time, confirmation and the account state immediately before and after action.
Deletion may not close linked services, invalidate every session or remove copies held elsewhere. It also does not establish who controlled the account. Preserve those questions separately from the administrative decision.
Key takeaway
Record the account's identifiers, relationships, sessions and deletion terms before action, then document deletion as a change whose actual effects must be verified rather than assumed.