Legal playbook · AI Employee: Lex

Legal Hold / Litigation Hold

Hold applied within 4 hours; zero data loss

The problem

A litigation hold has to reach every custodian within days of notice, and it has to actually stop the routine deletion of relevant records — Slack messages, Gmail, laptop files, ticketing systems, CRM records. Manual holds miss custodians, miss systems, and sit unattested for weeks. Spoliation sanctions are real and expensive, and the paper trail of "we sent the email" is worthless when the retention rule kept deleting anyway.

At a glance
Trigger
Form
Approvals
Attorney sign-off
What it does
Writes to your systems
Systems
Google Vault · M365 Purview · HRIS
How it feels in production

An hour-by-hour walkthrough.

Outside counsel sends a litigation hold notice to the GC: preserve everything related to Project Titan, effective immediately, all custodians listed. The GC forwards to Lex with the scope and custodians. Lex expands custodian scope: the 12 named custodians plus 34 additional people identified from the Context Graph (project members, cc'd on hold-relevant emails, mentioned in Slack channels about Titan). Presents the expanded list back to the GC — accept, reject, or edit. On GC approval: 1. Sends the formal hold notice to every custodian (email + Slack DM) with the acknowledgement form. 2. Suspends retention policies in Gmail, Google Vault, Slack, Zoom, Microsoft 365, Box, Google Drive, GitHub, and Jira for those custodians and matching topics. 3. Flags relevant CRM records + support tickets as "legal hold" so no auto-purge fires. 4. Starts the acknowledgement tracker: 24-hour SLA, escalation to manager at 48 hours, escalation to VP at 72. 5. Files the whole record — scope, custodians, systems, timestamps, acknowledgements — into the matter file with immutable audit log. Every week, Lex re-scans for new custodians (someone joining the project, someone newly mentioned in relevant channels) and adds them to the hold. When outside counsel releases the hold, Lex reverses every suspension, notifies every custodian, and files the release record.
How it works

Step by step.

  1. 01

    Ingest the hold notice + expand scope

    GC forwards the notice. Lex parses matter name, scope (topics, date range, systems), named custodians. Expands custodian list from the Context Graph — project members, correspondence graph, channel memberships.

    Email · Context Graph · Directory
  2. 02

    GC approves the expanded scope

    GC sees the named list + suggested additions with the signal that surfaced each. Approves as-is, removes names, adds names. Every decision is logged with reason.

    Web UI · Slack · Audit log
  3. 03

    Notify custodians + require acknowledgement

    Formal hold notice by email + Slack DM, with the acknowledgement form. Legally sufficient language reviewed by outside counsel. 24-hour SLA, escalating at 48 and 72 hours.

    Email · Slack · Teams · Acknowledgement tracker
  4. 04

    Suspend retention across every system

    For each custodian + each system with retention: apply hold at the platform level (Google Vault, Microsoft Purview, Slack Enterprise Grid retention, Box, GitHub archives, Jira project retention). Verify the suspension applied.

    Google Vault · Microsoft Purview · Slack · Box · GitHub · Jira
  5. 05

    Re-scan weekly + release on notice

    Weekly job re-scans for new custodians and adds them to the hold. On release notice from counsel, Lex reverses every suspension, notifies every custodian of release, and files the closure record with full timeline.

    Scheduler · Audit log · Matter file
Systems and wiring

What you connect to make this run.

Google Vault · Microsoft Purview

read+write

Apply retention holds at the identity level for Gmail / Google Drive / Google Chat and Exchange / OneDrive / Teams / SharePoint. Read hold status to verify. Native platform holds — not custom scripts — so they survive account changes.

Slack Enterprise · Box · GitHub · Jira

read+write

Suspend workspace / project retention rules for hold-relevant scopes. GitHub: repository archive-protection. Jira: project delete-lock. Each system has its own primitive; Lex wraps them uniformly.

Context Graph · HR system · Directory

read

Custodian expansion. Project membership from HR + project management; correspondence graph from email + chat; org chart for escalation ladder. All read-only for the discovery step.

Matter file · Immutable audit log

write

Every action written to an immutable log — hash-chained, timestamped, exportable for litigation. This is the artefact you produce to counsel to prove the hold was executed correctly.

What changes

Before and after, honestly.

Time from notice to hold effective on every system
Before
3-14 days
After
Under 4 hours
Custodian acknowledgement rate within 72 hours
Before
40-70%
After
95%+ (escalation ladder forces the conversation)
% of relevant systems actually held (audit finding)
Before
50-80%
After
99%+ (uniform coverage across every retention system)
Legal hours per hold execution
Before
8-24 hours
After
Under 60 minutes (scope approval + exceptions)
Related

Playbooks that pair with this one.

Frequently asked

Answers about this playbook.

What if a custodian on hold leaves the company?

Hold survives departure. Their mailbox + files stay preserved (Google Vault / Microsoft Purview keep the retention lock) even after account deprovisioning. Lex flags the departure to legal so counsel can decide on interview or additional preservation.

How does this work with employees who use personal devices?

Corporate data on personal devices is out of scope for platform-level holds. Lex includes a device-attestation step in the acknowledgement: custodian confirms they've preserved local copies and stopped deleting relevant messages / files.

Can we scope holds by topic, not just custodian?

Yes for platforms that support content-based holds (Google Vault, Microsoft Purview). Lex applies topic + date-range filters where supported; falls back to custodian-wide hold where not.

What about third-party systems that don't have hold APIs?

Lex flags these systems in the hold record with the request to legal + admins to apply manual holds. Tracks the acknowledgement from each admin separately. Never claims coverage of a system it can't verify.

How is the release handled?

On release notice from counsel, Lex requires explicit GC approval before reversing. On approval: retention policies restored, custodians notified of release, closure record filed with full timeline. Nothing auto-deletes — that's a separate deletion policy, if applicable.

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.