Wind-downs and transitions
HR channels and DMs: what to exclude from a closed company's archive
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
To exclude HR data from a closed company's archive, remove by default every HR channel, direct message, private non-work channel, performance and pay record, investigation, medical or leave detail, recruiting file and privileged legal thread. Find hidden ones through permissions, membership and keywords, confirm with human review, and log every exclusion before anything is licensed.
Key takeaways
- Exclude by default and reinstate only by a documented decision, never the other way around.
- Direct messages and group DMs are excluded as a class because privacy expectations are high and the work value is low.
- Sensitive material often sits in channels not named HR, such as manager channels, incident channels and company-wide announcements.
- Automated PII scanning helps find candidates for exclusion, but human review is still required.
- Excluded material is segregated under retention rules, not automatically deleted.
What belongs on the exclusion list?#
The exclusion list for a closed company's archive covers anything about people as employees, private conversations, privileged legal material, security secrets and other parties' confidential information. These categories carry the highest privacy and legal risk and add little to what makes operational records useful, which is the record of how work was done.
Apply the list before scoping, not after. When exclusions are decided first, every later step works from a smaller, safer set, and the exclusion log becomes evidence that sensitive material was removed on purpose rather than missed by luck.
The exclusion list, system by system#
The exclusion list works best as a table naming each category, where it usually lives and how to find it. Channel and folder names differ between companies, so treat the locations as places to look rather than a complete map.
Two categories on the list are not about people at all. Security secrets, such as API keys and passwords pasted into channels, can still open live systems now run by successors or customers, and board and investor material often contains confidential terms owed to third parties.
| Category | Where it usually lives | How to find it |
|---|---|---|
| HR and people operations | HR channels, HR mailbox, HRIS, people-team wiki space | Channel names, HR staff membership, restricted wiki spaces |
| Performance and discipline | Review tools, manager folders, one-on-one docs | File names, review tool exports, manager-only sharing |
| Compensation and payroll | Payroll exports, finance spreadsheets, offer letters | File types, finance folder permissions, keywords |
| Investigations and complaints | HR and legal email, restricted folders, private channels | Membership of HR plus counsel, restricted labels |
| Medical, leave and accommodation | HR email, benefits channels, scattered messages | Keyword scan plus human review |
| Recruiting and candidates | ATS, hiring channels, interview feedback docs | System of origin, channel names |
| Direct messages and group DMs | Chat tools | Message type in the export |
| Privileged legal communications | Counsel email, legal channels, board folders | Outside counsel domains, legal staff membership |
| Security secrets | DevOps channels, config files, wiki pages | Secret scanners plus manual review |
| Board, fundraising and investor material | Board drives, leadership channels | Folder ownership, leadership membership |
Why direct messages are excluded by default#
Direct messages are excluded by default because they carry the highest expectation of privacy and the lowest share of reusable work. People use DMs for quick work questions, but also for health news, complaints about managers, family matters and job searches, often in the same conversation.
DMs are also hard to prepare. Short, informal messages lean on context that de-identification tools miss, and a nickname or an inside reference can identify someone as clearly as a name. Employee notices may have described monitoring of company systems without contemplating reuse of private conversations, and privacy laws covering workers in some states may apply. Exceptions are rare, documented and approved by counsel.
How to find sensitive threads that aren't labeled HR#
Sensitive threads that aren't labeled HR are found by combining several weak signals, then confirming each candidate with a person. No single method finds them all.
Automated tools are a first pass only. The documentation for Presidio, an open-source PII detection tool, warns that automated detection carries no guarantee of finding all sensitive information and that additional systems and protections should be used. Human review of flagged and sampled messages closes that gap.
- Private flag: start with every private channel and restricted space, and require a reason to keep any of them.
- Membership: channels with an HR or legal member plus one or two employees are often about a person.
- Names and descriptions: off-topic, social, leadership, managers and incident channels deserve a look.
- Keywords: terms such as accommodation, termination, performance plan, salary, diagnosis and complaint flag messages for review.
- File types: offer letters, signed separation agreements and scanned forms posted in shared channels.
- Automated PII detection: tools that tag names, phone numbers and identifiers help triage large volumes.
- Secret scanning: open-source scanners such as TruffleHog, which says it scans chats and wikis as well as Git, flag API keys and passwords. Its option to confirm whether a secret is live sends real login attempts, so agree with your security lead before using it.
Edge cases that need a decision#
Edge cases are work channels that contain a few sensitive messages, and each needs a recorded decision rather than a default. The usual choices are keeping the channel and redacting messages, dropping a thread, or dropping the channel.
Write each decision into the exclusion log with the reviewer's name and date, and apply it consistently. If one engineering channel keeps a redacted illness mention, every channel with the same situation should be handled the same way, which is far easier when decisions are written as rules rather than one-off calls.
| Situation | Usual decision |
|---|---|
| Company announcement channel with layoff or departure notices | Keep work announcements; drop personnel notices |
| Engineering channel where someone mentions an illness | Keep the channel; redact the message |
| On-call channel listing personal phone numbers | Keep the channel; redact numbers and names |
| Managers channel discussing staffing and performance | Drop the channel |
| Hiring coordination channel | Drop it, along with interview feedback |
| Customer escalation channel naming a customer's employees | Keep after redaction, subject to contract review |
Illustrative: a closed field service software company applies the list#
Illustrative: a fictional field service software company that had more than 50 full-time staff at its peak has closed. Its Slack workspace, Google Workspace mail, Confluence and BambooHR are preserved, and wind-down counsel is asked whether any of it could be licensed.
Counsel applies the exclusion list first. BambooHR, the people-ops Confluence space, every DM and group DM, all private channels without a documented work purpose, the leadership channel and the recruiting channels are set aside. A keyword scan and an automated PII pass flag messages in the remaining engineering and support channels, and a reviewer confirms each flag.
The reviewer finds an incident channel where an engineer explained an absence with a medical detail, and a support channel listing a technician's personal phone number. Both are redacted. What remains is engineering and support work, with an exclusion log naming each category, location and decision.
How SourceX handles workplace communications#
SourceX applies exclusions before scoping in the Preparation step of the SourceX five-step transaction and records each excluded category in the privacy record of the SourceX Evidence Packet. Direct messages are out of scope by default, and the supplier approves the final scope. Former employees' expectations weigh as heavily as legal minimums, which is why employee notices and handbooks are reviewed in the Rights step.
Exclusions also shape how the work is explained to former staff. A plain-language employee notice that lists what was left out, such as direct messages, HR records and private channels, answers the first question most people ask when they hear that a closed employer's records are being reviewed.
Frequently asked questions
Should excluded HR material be deleted?
Not automatically. Payroll, employment and some HR records carry retention obligations, and some may be under a litigation hold. Move excluded material into a restricted archive with named custodians, keep it as long as required, then delete it on schedule and record the deletion.
Are emails between HR and an employee excluded even if they are about work?
Yes, by default. Messages between HR and an individual employee usually concern that person's employment, even when the subject line mentions a project or schedule. The work content is rarely worth the privacy risk, and a simple rule is easier to verify.
Do contractors' messages need the same treatment?
Yes. Contractors' personal details, rates and performance discussions deserve the same care as employees', and their contracts may add confidentiality terms of their own. Apply the same exclusion categories to contractor channels and to email with staffing agencies.
What if former employees lived outside the US?
Records about people in other countries may bring other laws into play, such as the GDPR for people in the EU, with stricter rules on purpose and legal basis. Identify where former employees worked before scoping, and have counsel assess whether their records can be included at all.
Can former employees ask what was licensed?
Depending on where they live, privacy laws may give them rights to ask what information about them was used or disclosed. A clear exclusion log and a plain-language notice make those questions easier to answer, and a template employee notice can help explain the approach.
Sources
- Presidio's documentation warns that because it uses automated detection mechanisms, there is no guarantee it will find all sensitive information, and additional systems and protections should be employed. Source
- TruffleHog is an open-source secret scanner that scans sources including Git, chats, wikis, logs, object stores and filesystems, and for secrets it can classify it can log in to confirm whether the secret is live. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.