How to build a Google Vault search query for investigations
A good investigation in Google Vault does not start with keywords. It starts with structure. Strong investigations follow a clear sequence — scope, subject, participants, criteria, refinement, export — and this guide walks through each step.
Step 1 — Define the investigation objective
Before you open Google Vault, be clear on one thing: what question are you trying to answer?
- What happened in this HR complaint?
- Who approved these rates?
- What was said about this employee?
- Which emails relate to this billing dispute?
- Did sensitive information leave the organisation?
The objective defines what relevant means, influences who you search, and determines how you refine results. If the objective is vague, the search will be vague.
Step 2 — Define the search scope
This is the most important step. Ask whose mailboxes are likely to contain the relevant discussions — not just who is involved in the issue. These are not the same.
Custodians might include managers, HR, finance, legal, operations, leadership, or external-facing roles. In many investigations, the key evidence sits in internal discussions, escalation threads, and decision-making emails rather than in the subject's own mailbox.
Example: For a billing dispute, custodians might include a finance lead, account manager, and operations lead. The supplier may be involved in the dispute, but the internal decision-making sits elsewhere.
Step 3 — Define the search subject
Now define who or what the investigation is about. This could be a person, a company, a domain, a project, a contract, or a case. This is separate from custodians.
Example: Custodians: finance and operations. Subject: supplier@example.com.
Step 4 — Define participants vs mentions
This is where many searches go wrong. You need to decide whether you are looking for direct involvement or indirect reference.
- Participants: emails where someone is sender, recipient, cc, or bcc.
- Mentions: emails where someone is discussed, referenced, or named.
Example: For an HR investigation, participants means emails the employee was part of. Mentions means emails discussing the employee. Both may be relevant, but they serve different purposes and require different search logic.
Step 5 — Decide on inclusion and exclusion logic
Ask: do you want emails involving the subject, or emails about the subject without them involved?
Include direct involvement:
from:person@example.com OR to:person@example.com OR cc:person@example.com
Include mentions:
"Person Name" OR person@example.com
Include mentions but exclude direct involvement:
("Person Name" OR person@example.com)
AND NOT (from:person@example.com OR to:person@example.com OR cc:person@example.com)This exclusion pattern is especially useful in DSAR workflows, HR investigations, and internal reviews.
Step 6 — Define the date range
Date ranges shape the investigation. Do not just ask when the issue happened. Also ask what led up to it, what happened afterwards, when discussions started, and when decisions were made.
Start with a period before, during, and after the event in question. Refine once you understand the data.
Step 7 — Add keywords carefully
Now, and only now, add keywords. Keywords help narrow results, focus on specific themes, and identify risk or decision language. Examples:
billing OR invoice OR rate approved OR approval OR sign-off complaint OR concern OR issue
Keywords should refine the search, not define it. Starting too narrow risks missing evidence that uses different language for the same concept.
Step 8 — Run a broad first search
Do not try to get it perfect on the first attempt. Run a query that is logically correct and slightly broader than necessary. Then review the results, scan a sample of emails, identify patterns, and check whether the volume makes sense.
Step 9 — Refine the query
Now improve it based on what you see. Adjust custodians, participants, mentions, keywords, exclusions, and date ranges as needed. You may run multiple iterations before reaching the right dataset. That is normal — it is part of the process, not a sign that something is wrong.
Step 10 — Validate before export
Before exporting, confirm:
- The right custodians are included
- The result set matches the investigation scope
- Mentions and participants are handled correctly
- Exclusions are intentional and documented
- Volume is reasonable
- Important emails are visible in results
If something looks wrong, fix the query before exporting. An export is not easily undone.
Step 11 — Document the search logic
A good investigation is not just correct — it is explainable. Record custodians, search subject, participant logic, mention logic, exclusions, keywords, date range, and each iteration. This becomes part of your audit trail and is what you point to if the investigation is later challenged.
Example: putting it all together
Objective: Investigate a billing dispute with supplier@example.com.
Custodians: Finance lead, account manager, operations lead.
Criteria: Emails involving or mentioning supplier@example.com; keywords: billing, invoice, rate.
Simplified query:
(from:supplier@example.com OR to:supplier@example.com OR cc:supplier@example.com OR "supplier@example.com") AND (billing OR invoice OR rate) AND after:2023/01/01
Then review, refine, and repeat until the dataset accurately reflects the investigation scope.
The takeaway
Google Vault is powerful, but it does exactly what you ask it to do. If your query is wrong, your dataset is wrong, your investigation is slower, and your conclusions are weaker.
A structured query leads to faster review, clearer findings, and more defensible output. The quality of your investigation is determined not at export or at reporting, but at search.
Google Vault gives you access to the data. The quality of your investigation depends on how you search it.
Turn Google Vault exports into answers
ScoopVault connects to Google Vault directly, runs AI-assisted analysis on your exports, and produces structured findings with a full audit trail — so your investigations are defensible from the first search to the final report.
Learn more →