Investigations6 min read

Google Vault gives you data. It doesn\'t give you the investigation.

Google Vault is a powerful legal hold and export tool. But compliance teams often discover a gap — sometimes a painful one — between what Vault produces and what an investigation actually requires.

What Vault was built to do

Google Vault is an archiving, legal hold, and eDiscovery tool for Google Workspace. It lets administrators place legal holds on custodians, search across Gmail and Drive, and export data in formats that can be handed to legal counsel or regulators.

That is a genuinely useful capability. Vault solves the data preservation problem. It ensures that relevant messages and files aren\'t deleted or modified while an investigation is live. For organisations with regulatory obligations, that alone justifies its use.

But preservation and export is where Vault\'s role ends.

The gap Vault leaves open

When you run a Vault export, you receive a compressed archive. Inside are MBOX files for email, JSON metadata, and — if Drive was included — copies of documents. There is no summary. There is no timeline. There is no indication of which messages matter or why.

What you have is raw data. Tens of thousands of rows, if the matter is anything but trivial. The investigation — the structured analysis that leads to a defensible finding — hasn\'t happened yet. It hasn\'t even started.

This is the gap that organisations routinely underestimate. They plan for the export. They don\'t plan for what comes after it.

What an investigation actually requires

A defensible workplace investigation needs more than a data dump. It needs:

  • Scoped collection. Evidence gathered from the right custodians, covering the right time period, using clearly documented search criteria — so that scope decisions can be justified later.
  • Structured analysis. The ability to identify relevant communications, surface patterns, and understand the sequence of events — not just retrieve documents that match a keyword.
  • An audit trail. A record of every search run, every decision made, and every finding reached. If the investigation is later challenged, the audit trail is what establishes that the process was sound.
  • Reproducible outputs. Findings that can be exported, reviewed by counsel, and shared with regulators if required — in a format that holds up under scrutiny.

Vault handles the first step of scoped collection. The rest falls to whatever process the compliance team has in place.

Why the manual gap is a risk

Many teams bridge the gap with spreadsheets, manual review, and shared documents. For small matters this is manageable. For anything significant — a harassment investigation, a fraud allegation, a regulatory inquiry — it introduces risk that is hard to see until it becomes a problem.

Inconsistent reviewers reach different conclusions from the same data. Manual processes leave gaps in the audit trail. Key emails get missed because the keyword search wasn\'t broad enough, or because the reviewer was working quickly. Findings produced this way are difficult to defend if challenged.

The problem isn\'t that Vault is inadequate. The problem is expecting Vault to be something it was never designed to be.

Designing the process around Vault\'s role

The teams that handle Vault-based investigations most effectively treat Vault as the data source and build a structured process on top of it. They define their search criteria before running the export, not after. They work from the Vault data systematically rather than manually scanning MBOX files. They produce a written record of what was searched and what was found.

The investigation lives in the process. Vault is just where the evidence comes from.

Turn Google Vault exports into answers

ScoopVault connects to Google Vault directly, runs AI-assisted analysis on your exports, and produces structured findings with a full audit trail — so your investigations are defensible from the first search to the final report.

Learn more →