24/7 Emergency Response: 1-800-868-8189
eDiscovery

Data Discovery and Source Mapping

Unknown Slack channels, regional cloud tenants, shared drives, and business databases create discovery risk long before review starts. GDF uncovers them before they become motion practice.

Legal team reviewing data source maps and custodian inventories on conference room screens

What This Solves

Most discovery disputes do not start in the courtroom. They start weeks earlier, when a key Salesforce org goes unidentified, a Slack workspace created during a merger never makes it onto the custodian list, or a Snowflake data warehouse turns out to hold years of transactional records that opposing counsel was expecting to see.

GDF's data discovery and source mapping work eliminates those surprises. Before any collection begins, GDF analysts conduct structured source interviews, deploy connector-based discovery tools against known cloud environments, and produce a documented data inventory that gives counsel a defensible picture of where relevant ESI lives, who controls it, and what has to be preserved. The result is better scoping, fewer late-breaking disclosures, and a stronger foundation for every downstream step in the matter.

What We Identify

Enterprise data does not stay in one place. A single custodian may have relevant ESI across a primary email account, a personal OneDrive, a shared Teams channel, a Slack workspace they joined through a partner tenant, a Salesforce account with embedded email logging, and a Box folder shared with outside counsel. GDF maps all of it.

Shadow IT is a particular challenge in complex matters. Employees frequently adopt SaaS tools that IT never formally approved: a department using a consumer version of Zoom for file sharing, a project team on an unregistered Notion workspace, or a sales group keeping deal notes in a personal Google Drive. GDF's source discovery process specifically looks for these repositories, not just the ones that appear on the initial interview list.

Platforms GDF routinely identifies and maps include:

  • Microsoft 365: Exchange Online, SharePoint, OneDrive, Teams, Viva Engage (Yammer)
  • Google Workspace: Gmail, Drive, Chat, Meet recordings, Shared Drives
  • Slack: standard channels, private channels, direct messages, Slack Connect workspaces
  • Salesforce: email logs, activity records, case notes, documents, chatter feeds
  • Snowflake and Databricks: analytical data warehouses, data lakehouse environments
  • AWS: S3 buckets, RDS databases, CloudTrail and CloudWatch logs
  • Azure: Blob storage, SQL databases, Active Directory audit logs
  • Oracle and SAP: ERP records, financial data, HR modules, transaction histories
  • SharePoint on-premises and hybrid deployments
  • Box: content repositories, comments, version histories, shared links
  • Zoom: meeting recordings, transcripts, chat histories, whiteboards
  • Backup systems, archive tapes, and decommissioned server images

Custodian-Source Alignment

Identifying sources is only half the work. GDF pairs each source with the custodians who have access, the data types each source holds, and the time periods for which data is available and recoverable. This custodian-source alignment document serves as the authoritative reference for scoping preservation and collection decisions throughout the matter.

For matters with large custodian populations, GDF uses structured intake questionnaires alongside automated account enumeration to cross-check self-reported information against actual system activity. An employee may not recall that they had access to a particular SharePoint site, but the access logs will show it. GDF reconciles both.

Our Process

Source Interviews

GDF conducts structured interviews with IT administrators, department heads, and key custodians to build an initial inventory of known data sources. Interview guides are tailored to the matter type, whether commercial litigation, regulatory inquiry, or internal investigation.

Connector-Based Discovery

Using API-level connectors and administrative access, GDF enumerates actual data locations across cloud tenants, SaaS platforms, and on-premises systems. This automated layer catches repositories that custodians did not mention and verifies the completeness of the interview-based inventory.

Live Data Mapping

GDF builds a living data map that documents each identified source: platform, data type, custodian access, date range of available data, retention policy, and collection feasibility. The map is updated as new sources surface during the engagement.

Custodian-Source Alignment

Each custodian is formally linked to the systems they use, including systems they may not have disclosed. GDF cross-references interview responses against system access logs, directory services, and license assignments to identify gaps or inconsistencies.

Scope Validation

GDF presents the completed data map to counsel for review, confirms which sources fall within scope, documents any sources counsel has determined are outside scope and the basis for that decision, and delivers the final inventory as a signed, dated deliverable for the matter record.

Defensibility and Documentation

Data discovery work is only as valuable as its documentation. Courts and opposing parties increasingly scrutinize not just what was collected, but how the producing party determined what existed in the first place. GDF delivers a written Source Identification Report that documents the methodology used, the sources identified, the custodians interviewed, the connector queries executed, and the scope decisions made by counsel.

This report gives counsel a factual record to cite in Rule 26(f) conferences, discovery responses, and any subsequent motion practice about the adequacy of the producing party's search. Every source enumeration query is logged with timestamps. Every interview is documented. The report can be supplemented as new information surfaces.

Deliverables

At the conclusion of source mapping, GDF delivers:

  • Source Identification Report: a written summary of all sources identified, the method of identification, and their relevance to the matter
  • Data Map: a structured inventory linking each source to data type, custodians, date range, and collection status
  • Custodian-Source Matrix: a reference document aligning each custodian to their data footprint across all identified systems
  • Shadow IT Log: documentation of any unauthorized or unapproved platforms identified during discovery
  • Scope Confirmation Memo: a record of counsel's in-scope and out-of-scope determinations, suitable for production or disclosure if required

Last reviewed and updated: April 2026

Cloud Tenant Enumeration

  • Microsoft 365, Google Workspace, Slack tenant scanning
  • Regional and subsidiary tenant identification
  • Shared workspace and Slack Connect discovery
  • Guest account and external collaboration mapping

SaaS Platform Discovery

  • Salesforce, Box, Zoom, and collaboration tool inventory
  • Shadow IT identification through network and license analysis
  • Data type classification per platform
  • Retention and deletion policy documentation

Database and Structured Data Sources

  • Snowflake, Databricks, Oracle, SAP mapping
  • AWS RDS, Azure SQL, and cloud database enumeration
  • ERP, CRM, and HRIS data location documentation
  • Schema and data type inventory for scoping decisions

Custodian Management

  • Structured custodian interviews with guided questionnaires
  • Cross-reference against directory services and access logs
  • Custodian-source alignment documentation
  • Supplemental custodian identification as new sources surface

Map Your Data Before Opposing Counsel Does

All matters are strictly confidential. Contact GDF to begin a source mapping engagement for your litigation or regulatory matter.

Start With the Full Picture

Better source mapping means fewer surprises, lower collection costs, and stronger defensibility throughout your matter. GDF can begin a source mapping engagement within days of engagement.