Legal Hold / Litigation Hold
Hold applied within 4 hours; zero data loss
A litigation hold has to reach every custodian within days of notice, and it has to actually stop the routine deletion of relevant records — Slack messages, Gmail, laptop files, ticketing systems, CRM records. Manual holds miss custodians, miss systems, and sit unattested for weeks. Spoliation sanctions are real and expensive, and the paper trail of "we sent the email" is worthless when the retention rule kept deleting anyway.
An hour-by-hour walkthrough.
Step by step.
- 01
Ingest the hold notice + expand scope
GC forwards the notice. Lex parses matter name, scope (topics, date range, systems), named custodians. Expands custodian list from the Context Graph — project members, correspondence graph, channel memberships.
Email · Context Graph · Directory - 02
GC approves the expanded scope
GC sees the named list + suggested additions with the signal that surfaced each. Approves as-is, removes names, adds names. Every decision is logged with reason.
Web UI · Slack · Audit log - 03
Notify custodians + require acknowledgement
Formal hold notice by email + Slack DM, with the acknowledgement form. Legally sufficient language reviewed by outside counsel. 24-hour SLA, escalating at 48 and 72 hours.
Email · Slack · Teams · Acknowledgement tracker - 04
Suspend retention across every system
For each custodian + each system with retention: apply hold at the platform level (Google Vault, Microsoft Purview, Slack Enterprise Grid retention, Box, GitHub archives, Jira project retention). Verify the suspension applied.
Google Vault · Microsoft Purview · Slack · Box · GitHub · Jira - 05
Re-scan weekly + release on notice
Weekly job re-scans for new custodians and adds them to the hold. On release notice from counsel, Lex reverses every suspension, notifies every custodian of release, and files the closure record with full timeline.
Scheduler · Audit log · Matter file
What you connect to make this run.
Google Vault · Microsoft Purview
read+writeApply retention holds at the identity level for Gmail / Google Drive / Google Chat and Exchange / OneDrive / Teams / SharePoint. Read hold status to verify. Native platform holds — not custom scripts — so they survive account changes.
Slack Enterprise · Box · GitHub · Jira
read+writeSuspend workspace / project retention rules for hold-relevant scopes. GitHub: repository archive-protection. Jira: project delete-lock. Each system has its own primitive; Lex wraps them uniformly.
Context Graph · HR system · Directory
readCustodian expansion. Project membership from HR + project management; correspondence graph from email + chat; org chart for escalation ladder. All read-only for the discovery step.
Matter file · Immutable audit log
writeEvery action written to an immutable log — hash-chained, timestamped, exportable for litigation. This is the artefact you produce to counsel to prove the hold was executed correctly.
Before and after, honestly.
Playbooks that pair with this one.
Answers about this playbook.
What if a custodian on hold leaves the company?
Hold survives departure. Their mailbox + files stay preserved (Google Vault / Microsoft Purview keep the retention lock) even after account deprovisioning. Lex flags the departure to legal so counsel can decide on interview or additional preservation.
How does this work with employees who use personal devices?
Corporate data on personal devices is out of scope for platform-level holds. Lex includes a device-attestation step in the acknowledgement: custodian confirms they've preserved local copies and stopped deleting relevant messages / files.
Can we scope holds by topic, not just custodian?
Yes for platforms that support content-based holds (Google Vault, Microsoft Purview). Lex applies topic + date-range filters where supported; falls back to custodian-wide hold where not.
What about third-party systems that don't have hold APIs?
Lex flags these systems in the hold record with the request to legal + admins to apply manual holds. Tracks the acknowledgement from each admin separately. Never claims coverage of a system it can't verify.
How is the release handled?
On release notice from counsel, Lex requires explicit GC approval before reversing. On approval: retention policies restored, custodians notified of release, closure record filed with full timeline. Nothing auto-deletes — that's a separate deletion policy, if applicable.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.