Skip to content

Leadership and readiness

Auto-delete settings that quietly erase your company history

By SourceX Editorial · Updated

Short answer

Auto-delete settings quietly erase company history when retention rules, plan limits or account cleanup jobs remove records on a schedule nobody reviews. Audit every system holding tickets, chat, email, recordings, CRM activity and engineering work. The rule: before changing anything, find the oldest record you can still open and export whatever is next in line for deletion.

Key takeaways

  • Deletion rules keep running long after the administrator who configured them has left the company.
  • Departed-user cleanup, plan downgrades and storage caps delete history without anyone choosing a retention period.
  • The oldest record you can still open is a better test of retention than the setting shown on an admin page.
  • Some deletion is required by contracts or privacy commitments, so pause or extend a rule only with legal sign-off.
  • Export what is next in line for deletion before debating long-term retention policy.

How do auto-delete settings erase history without anyone noticing?#

Auto-delete settings erase history unnoticed because they run on a schedule, in the background, with no alert when records disappear. A retention rule configured during a security project, a storage cleanup or a plan change keeps deleting tickets, messages and recordings every day afterward.

The person who set the rule has often moved on, and the reason was rarely written down. New administrators inherit the setting without knowing it exists. Teams find out only when someone searches for an old customer thread, an incident discussion or a warranty call and nothing older than a certain point comes back.

Deleted SaaS data is often unrecoverable once the vendor's own recovery window passes. Read each vendor's documentation on deletion and recovery for your plan rather than assuming a restore will be possible.

Vendor documentation makes the stakes concrete. Zendesk admins can create ticket deletion schedules that delete archived tickets after a set period; deleted tickets cannot be restored, and the schedules keep deleting any ticket that matches. Slack retains all messages and files for the lifetime of the workspace by default, but admins can set custom deletion periods, and that deletion is permanent. Zoom lets owners, admins and licensed users turn on deletion of cloud recordings after a set number of days. Each is a sensible control when chosen on purpose and a silent loss when nobody remembers it was switched on.

Audit checklist by system type#

The audit checklist by system type shows where deletion rules usually hide and what to export before anything else. Setting names differ by product and plan, so treat the middle column as a pointer to the right area of the admin console, not a menu path.

Start with the systems where decisions are written down, not just transactions. Help desks, chat, CRM activity and engineering reviews hold the reasoning behind outcomes, and that reasoning is the hardest part of company history to rebuild.

Audit checklist by system type
System typeWhere to lookWhat to export first
Help desk (Zendesk, Freshdesk, Intercom, Help Scout)Deletion schedules for closed tickets or conversations, attachment and redaction rules, archive settingsClosed tickets with internal notes, tags, linked issues and satisfaction ratings
Chat and collaboration (Slack, Microsoft Teams)Workspace and channel retention, file retention, retention policies in the admin centerIncident, escalation and customer channels where decisions are discussed
Email (Microsoft 365, Google Workspace)Retention policies, handling of departed users' mailboxes, archive and hold settingsMailboxes of departing leaders, shared inboxes and sales or support aliases
Phone, meetings and call recordingRecording and transcript retention, storage limits, purge of older recordingsRecordings with transcripts and call outcome fields, linked to customer or job IDs
CRM (Salesforce, HubSpot)Field and activity history retention, inactive record cleanup, email sync and attachment limitsActivity timelines, opportunity history and notes on won and lost deals
Engineering (GitHub, GitLab, Jira)Log and artifact retention, branch and project deletion, archived project cleanupPull request reviews, issue histories and links between issues and releases
Field service and ERP (ServiceTitan, Housecall Pro, NetSuite, Epicor)Purge jobs, archive settings, attachment storage limits, sandbox refreshesJob notes, photos, estimates, warranty claims and nonconformance records
File storage (SharePoint, Google Drive, Box)Retention labels, trash purge, deletion of departed users' drivesDeparted users' drives and project folders with no current owner

The deletions nobody configured on purpose#

The deletions nobody configured on purpose often do more damage than retention rules, because they never appear in a retention policy. They come from account lifecycle, billing and storage decisions made for unrelated reasons.

Ask finance and IT together about these, since the trigger is often a cost-saving step. Reclaiming a license or trimming a storage add-on looks like housekeeping on an invoice and like a deletion in the archive.

  • Departed-user cleanup: removing a license can trigger deletion of that person's mailbox, drive and chat history after a grace period.
  • Plan downgrades: lower tiers may hide older history or cap how far back search and export reach.
  • Storage caps: recording and attachment limits can trigger automatic purges of the oldest files.
  • Integrations: a sync between two systems can mirror a deletion from one into the other.
  • Secondary instances: a sandbox, a regional instance or an acquired company's tenant can lapse and be removed by the vendor.
  • Contract end: after a subscription ends, vendors typically delete customer data after their stated period, whether or not anyone exported it.

How to run the audit, step by step#

Running the audit step by step keeps it short and leaves a written record. Most of the work is looking, not changing, and the record is what lets legal and leadership make the retention decision with facts in hand.

  • List every system that holds business records, using single sign-on, accounts payable and expense reports to catch tools IT does not manage.
  • For each system, capture the retention and deletion settings as dated screenshots or exports.
  • Check the admin audit log for who changed retention and when.
  • Open the oldest record you can find in each record type and note its date.
  • Flag any system where deletion is actively running and valuable records sit near the cutoff.
  • Export the next-in-line records in a structured format that keeps IDs, timestamps and attachments.
  • Record each finding and decision in a retention register owned by IT and reviewed by legal.

Whether to pause, extend or let a deletion rule run is a legal and business decision, not an IT preference. Some deletion is required by customer contracts, privacy commitments or data minimization principles, and extending it can create a new problem.

Put each decision in writing. A retention register naming the system, the rule, the reason and the approver is what auditors, acquirers and any future data licensee will ask to see.

Pause, extend or let it run: deciding with legal
What you findDefault actionWho signs off
A rule with no documented reasonPause or extend while the reason is investigatedIT lead with legal
Deletion required by a contract or privacy noticeLet it run and document the obligationGeneral counsel or privacy lead
Records under a legal holdSuspend deletion for the held scope; in Slack, a legal hold saves messages and files regardless of retention settingsCounsel managing the hold
Business records with no restriction and ongoing valueExtend retention and export a structured copyBusiness owner with legal
Personal data kept beyond its stated purposeLet it run, or de-identify before keepingPrivacy lead

Illustrative: a roofing contractor finds its call history thinning#

Illustrative: a fictional roofing and restoration contractor runs jobs in a field service platform, answers calls through a cloud phone system and uses Microsoft 365 for email. A new IT lead is asked to pull old calls for a warranty dispute and finds that recordings stop at a fixed point in the past.

The audit turns up three silent deletions. A former office manager had set the phone system to purge older recordings to save storage. Departed estimators' mailboxes were deleted when their licenses were reassigned. And a photo sync between the field service app and a shared drive had mirrored deletions made during a cleanup.

With counsel, the company first reviews its call recording consent practice before deciding how long recordings should exist at all, then exports current recordings with job numbers ahead of the next purge. It switches departed-user handling to archive mailboxes instead of deleting them, fixes the sync, and starts a retention register reviewed after any admin or plan change.

How SourceX looks at retained history#

SourceX looks at retained history as one of the first facts in a fit check, because accessible years by system matter more than years in business. In the Supply step of the SourceX five-step transaction, a company describes its systems, record families and date coverage as metadata, and nothing is shared during the initial assessment.

In the SourceX Enterprise Data Value Framework, recency, scale and data cleanliness increase value, while privacy burden reduces net value. SourceX does not ask any company to keep records it is obliged to delete; the aim is that deletion happens by decision, not by a setting nobody remembers.

Frequently asked questions

How often should retention settings be checked?

Check them after any administrator change, plan change, migration, acquisition or new integration, and on a regular schedule leadership sets. Retention drift usually follows those events, so tying the review to them catches most surprises without adding a heavy process.

Can deleted SaaS data be recovered?

Sometimes, within a vendor's recovery window and on certain plans, but it is not something to rely on. Many vendors purge deleted data permanently after their stated period. Read the deletion and recovery section of each vendor's documentation and test a restore on non-critical data before you need one.

Does a third-party backup tool solve the problem?

A backup tool captures what exists when it runs, so it helps only if it started before the deletion. Some backups also follow the source system's retention or their own rotation. Check what a restore returns: a usable export with IDs and thread links, or a snapshot only the backup tool can read.

Should we simply turn off auto-delete everywhere?

No. Some deletion rules exist for good reasons, including privacy commitments, customer contracts and limits on keeping personal data. Switching everything off can breach those obligations and widen the impact of any security incident. Decide system by system with legal, and document why each rule is set the way it is.

Who should own retention settings?

IT usually owns the settings, legal owns the obligations and business leaders own the value of the records. Name one owner per system in the retention register and route any change to deletion rules through a short review with legal, the same way access changes are reviewed.

Sources

  • Zendesk admins can create ticket deletion schedules that delete archived tickets after a set period; deleted tickets cannot be restored, and the schedules keep deleting matching tickets. Source
  • By default Slack retains all messages and files for the lifetime of the workspace; admins can set custom deletion periods, and message and file deletion is permanent. Source
  • When a Slack legal hold is in place, messages and files in a conversation are saved regardless of retention settings, even if members edit or delete content. Source
  • Zoom lets account owners, admins and licensed users enable deletion of cloud recordings after a specified number of days. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify