How to search Google Vault for emails about a person without missing key evidence
Searching a person's own mailbox is not the same as searching for emails about them. The distinction matters more than most teams realise — and conflating the two is one of the most common reasons investigations miss critical evidence.
Two different searches
When an investigation involves a specific individual, there are two fundamentally different things you might want to find:
- Emails they were part of: messages they sent, received, or were copied on — their direct participation in correspondence.
- Emails about them: messages where they are discussed, referenced, or named by others — internal conversations, management decisions, escalations.
These require different search logic and are often relevant for different reasons. HR investigations, DSARs, and internal reviews frequently need both, but for different parts of the evidence picture.
Define the objective first
Before writing any query, be clear about what you are trying to establish. Common objectives include:
- What did this person communicate, and with whom?
- What was said about this person internally?
- What decisions were made regarding this person?
- What personal data does the organisation hold about this individual?
The objective determines whether you need direct participation, indirect mentions, or both — and whether any exclusion logic applies.
Custodians vs subject
One of the most common mistakes is searching only the subject's own mailbox. In many investigations, the most significant evidence sits elsewhere: in the inbox of a manager who raised a concern, an HR thread discussing next steps, or a leadership email about a decision made before the subject was informed.
Think of it this way: custodians are whose mailboxes you search; the subject is who the investigation is about. They are often not the same person.
For a thorough search, custodians might include the subject themselves, their direct manager, HR contacts involved in the matter, peers who may have witnessed relevant events, and any leadership with decision-making involvement.
Searching by email address
Email address is the most precise identifier in Google Vault. For participation searches, use the from, to, cc, and bcc operators:
from:jane.smith@example.com OR to:jane.smith@example.com OR cc:jane.smith@example.com OR bcc:jane.smith@example.com
Be aware that email addresses may have changed over time — particularly following name changes, role changes, or domain migrations. If there is any possibility of an alternative address, include it.
Name variants and alternative identifiers
Email headers and message bodies often reference individuals by name rather than email address. A thorough mention search should account for common variants:
"Jane Smith" OR "J. Smith" OR "Jane S" OR jane.smith@example.com OR jsmith@example.com
Note that Google Vault searches for references across message content, which can include headers as well as the body — the exact matching behaviour may vary. Where precision matters, review a sample before relying on any single query variant.
For some investigations, employee IDs or account identifiers may also appear in correspondence — particularly in HR systems, payroll threads, or IT-related discussions. If these are relevant, include them as additional search terms.
Participants vs mentions: which do you need?
Once you have identified the person's email address and name variants, decide what type of reference you are looking for.
Participants means the person was directly in the email — as sender, recipient, or on copy. This captures their own communications.
Mentions means the person is referenced in the message — their name or address appears, but they were not necessarily a recipient. This captures what others said about them.
For HR investigations, you typically need both: the subject's own communications and the internal discussions about them. For DSARs, you need everything — direct participation and mentions both constitute personal data held by the organisation.
Exclusion logic: finding discussions without their involvement
Sometimes you specifically want emails discussing a person that they were not part of — internal management discussions, escalations, or decisions made before the subject was informed. Exclusion logic isolates these:
("Jane Smith" OR jane.smith@example.com)
AND NOT (from:jane.smith@example.com
OR to:jane.smith@example.com
OR cc:jane.smith@example.com)This pattern retrieves messages where the person is referenced but was not a participant. It is particularly useful in DSAR workflows — to surface data the subject may not know exists — and in HR investigations where management discussions are relevant to establishing what was known and when.
Multiple custodians
A person-focused search almost always benefits from running across multiple custodians. What appears in one inbox may not appear in another — escalation chains, manager notes, and peer discussions are often invisible if you only search the subject's own mail.
For each additional custodian, apply the same participant and mention logic. Document which custodians were included and why — that record is part of what makes the investigation defensible.
Date ranges
Use date ranges to frame the investigation correctly. For most matters, the relevant period extends before and after the central event: the weeks leading up to a complaint, the incident itself, and the period during which decisions were made and communicated.
A common mistake is to search only the period when the issue was active and visible. Context that established the pattern of behaviour — or that shows what was known before an action was taken — often sits outside that window.
Validate before export
Before exporting, review a sample of results to confirm the query is returning what you expected. Check that participant searches are capturing the right correspondence, that mention searches are finding references rather than just direct emails, and that the volume is consistent with the scope of the matter.
If the volume looks unexpectedly high or low, adjust the query before exporting. An export with the wrong dataset creates rework — and a record of an export that had to be re-run.
The takeaway
Searching for emails about a person is a different task from searching a person's mailbox. Combining participant searches, mention searches, and exclusion logic — across the right custodians and date range — gives you a defensible, complete dataset.
Document every decision: which custodians, which search logic, which exclusions, and why. That record is what holds up when the investigation is reviewed.
Google Vault gives you data. The investigation depends on how you search it.
Turn Google Vault exports into answers
ScoopVault connects to Google Vault directly, runs AI-assisted analysis on your exports, and produces structured findings with a full audit trail — so your investigations are defensible from the first search to the final report.
Learn more →