Skip to content

Wind-downs and transitions

HR channels and DMs: what to exclude from a closed company's archive

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

To exclude HR data from a closed company's archive, remove by default every HR channel, direct message, private non-work channel, performance and pay record, investigation, medical or leave detail, recruiting file and privileged legal thread. Find hidden ones through permissions, membership and keywords, confirm with human review, and log every exclusion before anything is licensed.

Key takeaways

  • Exclude by default and reinstate only by a documented decision, never the other way around.
  • Direct messages and group DMs are excluded as a class because privacy expectations are high and the work value is low.
  • Sensitive material often sits in channels not named HR, such as manager channels, incident channels and company-wide announcements.
  • Automated PII scanning helps find candidates for exclusion, but human review is still required.
  • Excluded material is segregated under retention rules, not automatically deleted.

What belongs on the exclusion list?#

The exclusion list for a closed company's archive covers anything about people as employees, private conversations, privileged legal material, security secrets and other parties' confidential information. These categories carry the highest privacy and legal risk and add little to what makes operational records useful, which is the record of how work was done.

Apply the list before scoping, not after. When exclusions are decided first, every later step works from a smaller, safer set, and the exclusion log becomes evidence that sensitive material was removed on purpose rather than missed by luck.

The exclusion list, system by system#

The exclusion list works best as a table naming each category, where it usually lives and how to find it. Channel and folder names differ between companies, so treat the locations as places to look rather than a complete map.

Two categories on the list are not about people at all. Security secrets, such as API keys and passwords pasted into channels, can still open live systems now run by successors or customers, and board and investor material often contains confidential terms owed to third parties.

The exclusion list, system by system
CategoryWhere it usually livesHow to find it
HR and people operationsHR channels, HR mailbox, HRIS, people-team wiki spaceChannel names, HR staff membership, restricted wiki spaces
Performance and disciplineReview tools, manager folders, one-on-one docsFile names, review tool exports, manager-only sharing
Compensation and payrollPayroll exports, finance spreadsheets, offer lettersFile types, finance folder permissions, keywords
Investigations and complaintsHR and legal email, restricted folders, private channelsMembership of HR plus counsel, restricted labels
Medical, leave and accommodationHR email, benefits channels, scattered messagesKeyword scan plus human review
Recruiting and candidatesATS, hiring channels, interview feedback docsSystem of origin, channel names
Direct messages and group DMsChat toolsMessage type in the export
Privileged legal communicationsCounsel email, legal channels, board foldersOutside counsel domains, legal staff membership
Security secretsDevOps channels, config files, wiki pagesSecret scanners plus manual review
Board, fundraising and investor materialBoard drives, leadership channelsFolder ownership, leadership membership

Why direct messages are excluded by default#

Direct messages are excluded by default because they carry the highest expectation of privacy and the lowest share of reusable work. People use DMs for quick work questions, but also for health news, complaints about managers, family matters and job searches, often in the same conversation.

DMs are also hard to prepare. Short, informal messages lean on context that de-identification tools miss, and a nickname or an inside reference can identify someone as clearly as a name. Employee notices may have described monitoring of company systems without contemplating reuse of private conversations, and privacy laws covering workers in some states may apply. Exceptions are rare, documented and approved by counsel.

How to find sensitive threads that aren't labeled HR#

Sensitive threads that aren't labeled HR are found by combining several weak signals, then confirming each candidate with a person. No single method finds them all.

Automated tools are a first pass only. The documentation for Presidio, an open-source PII detection tool, warns that automated detection carries no guarantee of finding all sensitive information and that additional systems and protections should be used. Human review of flagged and sampled messages closes that gap.

  • Private flag: start with every private channel and restricted space, and require a reason to keep any of them.
  • Membership: channels with an HR or legal member plus one or two employees are often about a person.
  • Names and descriptions: off-topic, social, leadership, managers and incident channels deserve a look.
  • Keywords: terms such as accommodation, termination, performance plan, salary, diagnosis and complaint flag messages for review.
  • File types: offer letters, signed separation agreements and scanned forms posted in shared channels.
  • Automated PII detection: tools that tag names, phone numbers and identifiers help triage large volumes.
  • Secret scanning: open-source scanners such as TruffleHog, which says it scans chats and wikis as well as Git, flag API keys and passwords. Its option to confirm whether a secret is live sends real login attempts, so agree with your security lead before using it.

Edge cases that need a decision#

Edge cases are work channels that contain a few sensitive messages, and each needs a recorded decision rather than a default. The usual choices are keeping the channel and redacting messages, dropping a thread, or dropping the channel.

Write each decision into the exclusion log with the reviewer's name and date, and apply it consistently. If one engineering channel keeps a redacted illness mention, every channel with the same situation should be handled the same way, which is far easier when decisions are written as rules rather than one-off calls.

Edge cases that need a decision
SituationUsual decision
Company announcement channel with layoff or departure noticesKeep work announcements; drop personnel notices
Engineering channel where someone mentions an illnessKeep the channel; redact the message
On-call channel listing personal phone numbersKeep the channel; redact numbers and names
Managers channel discussing staffing and performanceDrop the channel
Hiring coordination channelDrop it, along with interview feedback
Customer escalation channel naming a customer's employeesKeep after redaction, subject to contract review

Illustrative: a closed field service software company applies the list#

Illustrative: a fictional field service software company that had more than 50 full-time staff at its peak has closed. Its Slack workspace, Google Workspace mail, Confluence and BambooHR are preserved, and wind-down counsel is asked whether any of it could be licensed.

Counsel applies the exclusion list first. BambooHR, the people-ops Confluence space, every DM and group DM, all private channels without a documented work purpose, the leadership channel and the recruiting channels are set aside. A keyword scan and an automated PII pass flag messages in the remaining engineering and support channels, and a reviewer confirms each flag.

The reviewer finds an incident channel where an engineer explained an absence with a medical detail, and a support channel listing a technician's personal phone number. Both are redacted. What remains is engineering and support work, with an exclusion log naming each category, location and decision.

How SourceX handles workplace communications#

SourceX applies exclusions before scoping in the Preparation step of the SourceX five-step transaction and records each excluded category in the privacy record of the SourceX Evidence Packet. Direct messages are out of scope by default, and the supplier approves the final scope. Former employees' expectations weigh as heavily as legal minimums, which is why employee notices and handbooks are reviewed in the Rights step.

Exclusions also shape how the work is explained to former staff. A plain-language employee notice that lists what was left out, such as direct messages, HR records and private channels, answers the first question most people ask when they hear that a closed employer's records are being reviewed.

Frequently asked questions

Should excluded HR material be deleted?

Not automatically. Payroll, employment and some HR records carry retention obligations, and some may be under a litigation hold. Move excluded material into a restricted archive with named custodians, keep it as long as required, then delete it on schedule and record the deletion.

Are emails between HR and an employee excluded even if they are about work?

Yes, by default. Messages between HR and an individual employee usually concern that person's employment, even when the subject line mentions a project or schedule. The work content is rarely worth the privacy risk, and a simple rule is easier to verify.

Do contractors' messages need the same treatment?

Yes. Contractors' personal details, rates and performance discussions deserve the same care as employees', and their contracts may add confidentiality terms of their own. Apply the same exclusion categories to contractor channels and to email with staffing agencies.

What if former employees lived outside the US?

Records about people in other countries may bring other laws into play, such as the GDPR for people in the EU, with stricter rules on purpose and legal basis. Identify where former employees worked before scoping, and have counsel assess whether their records can be included at all.

Can former employees ask what was licensed?

Depending on where they live, privacy laws may give them rights to ask what information about them was used or disclosed. A clear exclusion log and a plain-language notice make those questions easier to answer, and a template employee notice can help explain the approach.

Sources

  • Presidio's documentation warns that because it uses automated detection mechanisms, there is no guarantee it will find all sensitive information, and additional systems and protections should be employed. Source
  • TruffleHog is an open-source secret scanner that scans sources including Git, chats, wikis, logs, object stores and filesystems, and for secrets it can classify it can log in to confirm whether the secret is live. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify