Investigations7 min read

How to build a Google Vault search query for investigations

A good investigation in Google Vault does not start with keywords. It starts with structure. Strong investigations follow a clear sequence — scope, subject, participants, criteria, refinement, export — and this guide walks through each step.

Step 1 — Define the investigation objective

Before you open Google Vault, be clear on one thing: what question are you trying to answer?

  • What happened in this HR complaint?
  • Who approved these rates?
  • What was said about this employee?
  • Which emails relate to this billing dispute?
  • Did sensitive information leave the organisation?

The objective defines what relevant means, influences who you search, and determines how you refine results. If the objective is vague, the search will be vague.

Step 2 — Define the search scope

This is the most important step. Ask whose mailboxes are likely to contain the relevant discussions — not just who is involved in the issue. These are not the same.

Custodians might include managers, HR, finance, legal, operations, leadership, or external-facing roles. In many investigations, the key evidence sits in internal discussions, escalation threads, and decision-making emails rather than in the subject's own mailbox.

Example: For a billing dispute, custodians might include a finance lead, account manager, and operations lead. The supplier may be involved in the dispute, but the internal decision-making sits elsewhere.

Step 3 — Define the search subject

Now define who or what the investigation is about. This could be a person, a company, a domain, a project, a contract, or a case. This is separate from custodians.

Example: Custodians: finance and operations. Subject: supplier@example.com.

Step 4 — Define participants vs mentions

This is where many searches go wrong. You need to decide whether you are looking for direct involvement or indirect reference.

  • Participants: emails where someone is sender, recipient, cc, or bcc.
  • Mentions: emails where someone is discussed, referenced, or named.

Example: For an HR investigation, participants means emails the employee was part of. Mentions means emails discussing the employee. Both may be relevant, but they serve different purposes and require different search logic.

Step 5 — Decide on inclusion and exclusion logic

Ask: do you want emails involving the subject, or emails about the subject without them involved?

Include direct involvement:

from:person@example.com OR to:person@example.com OR cc:person@example.com

Include mentions:

"Person Name" OR person@example.com

Include mentions but exclude direct involvement:

("Person Name" OR person@example.com)
AND NOT (from:person@example.com OR to:person@example.com OR cc:person@example.com)

This exclusion pattern is especially useful in DSAR workflows, HR investigations, and internal reviews.

Step 6 — Define the date range

Date ranges shape the investigation. Do not just ask when the issue happened. Also ask what led up to it, what happened afterwards, when discussions started, and when decisions were made.

Start with a period before, during, and after the event in question. Refine once you understand the data.

Step 7 — Add keywords carefully

Now, and only now, add keywords. Keywords help narrow results, focus on specific themes, and identify risk or decision language. Examples:

billing OR invoice OR rate
approved OR approval OR sign-off
complaint OR concern OR issue

Keywords should refine the search, not define it. Starting too narrow risks missing evidence that uses different language for the same concept.

Step 8 — Run a broad first search

Do not try to get it perfect on the first attempt. Run a query that is logically correct and slightly broader than necessary. Then review the results, scan a sample of emails, identify patterns, and check whether the volume makes sense.

Step 9 — Refine the query

Now improve it based on what you see. Adjust custodians, participants, mentions, keywords, exclusions, and date ranges as needed. You may run multiple iterations before reaching the right dataset. That is normal — it is part of the process, not a sign that something is wrong.

Step 10 — Validate before export

Before exporting, confirm:

  • The right custodians are included
  • The result set matches the investigation scope
  • Mentions and participants are handled correctly
  • Exclusions are intentional and documented
  • Volume is reasonable
  • Important emails are visible in results

If something looks wrong, fix the query before exporting. An export is not easily undone.

Step 11 — Document the search logic

A good investigation is not just correct — it is explainable. Record custodians, search subject, participant logic, mention logic, exclusions, keywords, date range, and each iteration. This becomes part of your audit trail and is what you point to if the investigation is later challenged.

Example: putting it all together

Objective: Investigate a billing dispute with supplier@example.com.

Custodians: Finance lead, account manager, operations lead.

Criteria: Emails involving or mentioning supplier@example.com; keywords: billing, invoice, rate.

Simplified query:

(from:supplier@example.com OR to:supplier@example.com
  OR cc:supplier@example.com OR "supplier@example.com")
AND (billing OR invoice OR rate)
AND after:2023/01/01

Then review, refine, and repeat until the dataset accurately reflects the investigation scope.

The takeaway

Google Vault is powerful, but it does exactly what you ask it to do. If your query is wrong, your dataset is wrong, your investigation is slower, and your conclusions are weaker.

A structured query leads to faster review, clearer findings, and more defensible output. The quality of your investigation is determined not at export or at reporting, but at search.

Google Vault gives you access to the data. The quality of your investigation depends on how you search it.

Turn Google Vault exports into answers

ScoopVault connects to Google Vault directly, runs AI-assisted analysis on your exports, and produces structured findings with a full audit trail — so your investigations are defensible from the first search to the final report.

Learn more →