Runbook automation: automate the steps, keep the judgement
The candidates worth automating are the frequent, boring and unambiguous ones. Automating a procedure nobody trusts just produces an automated mistake.
The obligation to preserve begins when litigation becomes reasonably anticipated — which is usually earlier than the day the complaint arrives, and always earlier than anyone wants it to be.
A legal hold — also called a litigation hold — is the suspension of an organisation’s ordinary deletion practices over information that may be relevant to a dispute. It is issued when litigation or an investigation is reasonably anticipated, and it stays in place until the matter ends.
The word "anticipated" carries the weight. The duty does not begin when proceedings are served; it begins when a reasonable organisation would expect them — a demand letter, a serious internal complaint, a regulator’s enquiry, sometimes an incident that plainly leads somewhere. Deciding that date late is the single most common failure, because everything deleted in the interval was deleted after the duty attached.
Email is understood and usually covered. What is missed is everything else: messaging platforms with short default retention, project tools that purge closed items, meeting recordings and transcripts, and personal accounts used for work. Those systems often delete by default rather than retaining by default, which reverses the risk — no one has to do anything wrong for evidence to disappear. Inventory them before the first hold rather than during one.
Suspending auto-deletion is an administrative action taken by whoever runs each system, and it is separate from telling people not to delete things. A hold notice that reaches custodians but never reaches the administrator who can turn off the retention policy has done half the job.
A hold covering everything for everyone is unsustainable and is usually abandoned quietly, which is worse than a narrower one that is followed. Scope by custodian, by date range and by subject matter, and revisit it as the matter develops — new custodians appear, the relevant period extends. Document the reasoning for the scope at the time, because the question later is not only what you preserved but why you thought that was enough.
Holds accumulate. Organisations that issue them diligently and never release them end up preserving everything indefinitely, which defeats their retention programme and costs storage and risk. When a matter concludes, issue a release notice, confirm which systems can resume normal disposal, and record the date. If another hold covers the same data, say so rather than releasing it twice.
What is examined if preservation is challenged is not only the data but the process: when the duty was identified, what was issued, to whom, what they acknowledged, and what was suspended. Ettex Records holds that per matter with the custodian list and acknowledgements, Ettex Sheets tracks the systems put on hold and their release status, and the notice sent to custodians is covered in litigation hold notice. The retention programme it interrupts is covered in data retention policy.
Being direct: this is a records approach, not an eDiscovery platform, and none of it is legal advice. When the duty attaches and what scope is defensible are legal judgements for counsel, and organisations with recurring litigation need purpose-built tooling.
When litigation or an investigation is reasonably anticipated — typically before proceedings are served, at the point a reasonable organisation would expect a dispute.
Automatic deletion in email and chat, retention schedules, device reimaging, offboarding purges, backup rotation, and individual deletion.
Scoped by custodian, date range and subject matter, with the reasoning documented. Overly broad holds are abandoned in practice, which is worse.
Yes. Unreleased holds accumulate and defeat the retention programme. Issue a release, confirm systems can resume disposal and record the date.
The candidates worth automating are the frequent, boring and unambiguous ones. Automating a procedure nobody trusts just produces an automated mistake.
The point of an SBOM is answering “are we affected?” in an hour instead of a fortnight. Produced by scanning a finished artefact, it usually cannot.
A flat parts list looks simpler and answers none of the questions a BOM exists for — what to buy, what it costs, and what a change breaks.