Mailboxes
Traces collects full email accounts (often called custodians) using the platform's native capabilities. What this means is there is no eDiscovery licensing required or software to install on your side. Instead, Traces talks directly to Microsoft or Google to collect every single email in full, with all attachments and threads intact.
What is collected?
As standard, we collect emails from the following folders:
Inbox
Sent Items
We can, at your request, also collect:
Deleted Items
Junk
Drafts
Recoverable Items*
Any specific folder from any custodian, e.g. "Accounts 2025", "Sales Pipeline"
All folders from any custodian
* A recoverable item (also called a partial) occurs when a deleted email has been fully deleted. Sometimes, the full delete process leaves artefacts and fragments of the email that was deleted. We cannot guarantee that there will be any recoverable items in a custodian's account.
What do you need from me?
We use a simple and secure approach called global consent - we send a link to a person (either yourself or a colleague, or your client) who has 'Global Administrator' permissions (every Microsoft and Google tenant has one). They will receive an email from Traces that details what they are approving and a button. When they click the button, they will be granting Traces access to every mailbox and the basic details of every user in the tenant. They have the ability to remove this permission at any time and we provide instruction on how to do so in the email. Once they click Authorise, a Traces analyst will be notified and can start the collection.
We appreciate that a lot of IT teams will run for the hills when asked to grant global consent. And this is entirely understandable; they are granting Traces a lot of read-only access to every mailbox. To help mitigate this risk, Traces only collects (and is only aware of) the custodians we manually enter for the scope of the collection. The chain of custody document details every mailbox that was accessed, what was accessed, and when.
If tenant-wide email access is too broad, we can provide a guide and instructions on manually setting up the access directly in the tenant. However, this is (in our experience) messier and more prone to errors than using the platform-provided access via global consent. We are here to help you and we understand security concerns, so we can explore your specific access requirements in more detail on the scoping call.

What do I get back?
Your evidence
For mailboxes you will receive a folder that contains EML files. An EML is the most universally-accepted format for an email, and can be opened in Apple Mail or similar programs. Each EML is a full email, so includes the original sender and recipients, timestamps, and attachments - it is like viewing the email as if you had received it yourself. The emails are arranged into the folders as they appear in the mailbox, e.g. Inbox, Sent Items. The attachments in their native format e.g. xlsx, docx are also in the folder if you wish to review outside a mail application.
Chain of custody
This is what shows how Traces collected the mailbox, the details of the instruction to us and authorisation details, and a summary of what was in scope of our collection with anything we couldn't get noted in the table. The chain of custody is what is needed to show that this collection is repeatable. Someone following the exact same steps, and at the exact same time, would have collected the exact same data. We do not include the forensic signature for each file in our chain of custody. Instead we rely on our hash list to contain these signatures, so the chain of custody can focus on recording the process we followed.
Hash list
A hash is a mathematical signature of a file. It is a way of looking at the contents of the file and the information about the file itself and deriving a long number. That long number is globally unique to that exact file in that exact state. It can be used to verify at any point if an email is used as evidence, that the email exhibited is exactly the same as the email that was collected by Traces. The file itself is a CSV, and can be viewed in Excel or similar spreadsheet software.
Item manifest
Another CSV file but this time much more usable. This contains details about each email and includes the following columns:
Custodian
Folder path
Provider item ID
Internet message ID
Subject preview
From address
Sent at
Received at
Size (bytes)
SHA256 (hash)
There are a few other columns, related to the forensic integrity of the email. You can download a sample email collection below. All collections are provided to you as a ZIP. It is password protected, and your analyst will provide your password to you in a different way (such as via text message or a secure messaging app). We do not publish the exact details on how we will provide you with the password upfront (for security reasons). You will be sent a link to download the ZIP folder. This link is one time use. Other links can be generated upon request.
Our own records of the engagement - who instructed us, what we were asked to do, what we did - is retained for six years. Traces will hold a copy of the ZIP for 90 days once we have confirmed you have downloaded and can access the bundle. You can at any time request the deletion of your collection from Traces.
