Private equity and portfolios
Post-acquisition data inventory checklist
By SourceX Editorial · Updated
Short answer
A post-acquisition data inventory records every system, record family, history range, administrator and restriction an acquired company holds. Run it in three passes: on day one secure access and stop deletion, by day 30 map systems to record families, and by day 90 confirm inherited rights. History deleted in the first weeks cannot be rebuilt later.
Key takeaways
- Day one is about preventing loss: admin access, renewal dates and deletion settings come before any mapping.
- Map record families, not just applications; one help desk can hold support, sales and warranty history.
- Inherited rights come from customer contracts, vendor terms, notices and the purchase agreement itself.
- Transition services agreements can leave years of history in the seller's systems with a deadline to extract it.
- A metadata-only inventory is enough to decide integration, retention and licensing options.
What is a post-acquisition data inventory?#
A post-acquisition data inventory is a structured list of every system the acquired company uses, the record families each system holds, how far back the history goes, who administers it and what restrictions apply. It is built from metadata, so it needs no exports or copies of records.
Portfolio operations teams use the inventory for three decisions that otherwise get made by accident: which systems to keep or retire, what must be preserved for legal and tax reasons, and which histories might be licensable later. Integration plans that skip it often retire an old help desk or CRM before anyone asks what was in it.
Day one: secure access and stop accidental loss#
Day one data work is about preventing loss, not understanding the archive. A change of ownership is when admin passwords leave with departing staff, company cards on vendor accounts get cancelled and auto-renewals quietly lapse.
Give one person ownership of the day-one list and the authority to pause any cancellation, account deletion or plan downgrade until it is complete. Finance teams cutting duplicate tools in the first weeks are a common cause of lost history, and the loss usually goes unnoticed until someone needs the records.
Retention settings deserve a look on day one because defaults differ and deletions are often final. Slack, for example, keeps all messages and files for the life of the workspace by default, but admins can set custom deletion periods, and message and file deletion is permanent. Record what each tool is set to before anyone changes it.
- Collect admin credentials for every SaaS tool and move them into the group's password manager.
- List each subscription's renewal and cancellation dates and the card or account that pays for it.
- Check retention and auto-deletion settings in the help desk, email, chat and call recording tools.
- Suspend, rather than delete, accounts of departing employees and keep their mailboxes.
- Freeze planned system shutdowns or migrations until the inventory is complete.
- Confirm whether legal holds were in place before closing and that they still apply.
Day 30: map systems to record families#
By day 30, the inventory should map each system to the record families it holds. Applications are a poor unit on their own: one Zendesk instance may hold support tickets, warranty claims and sales inquiries, and one shared drive may hold proposals, project files and HR documents.
| System category | Examples | What to record |
|---|---|---|
| Help desk and support | Zendesk, Intercom, Freshdesk | Ticket history range, linked tools, internal notes, attachments |
| CRM and sales | Salesforce, HubSpot | Accounts, opportunities, activity notes, logged email |
| Engineering | Jira, GitHub, GitLab, Linear | Issues, code reviews, releases, links to support tickets |
| Field operations | ServiceTitan, Housecall Pro, Jobber | Estimates, jobs, dispatch notes, invoices, callbacks |
| ERP and distribution | NetSuite, Epicor, Acumatica | Orders, exceptions, returns, vendor records |
| Documents and knowledge | Confluence, Notion, SharePoint | Playbooks, project files, owners of each space |
| Email and chat | Microsoft 365, Google Workspace, Slack | Retention policy, export options, archived users |
Day 90: confirm inherited rights and restrictions#
By day 90, the inventory should state what the company is allowed to do with each record family. Owning the company does not mean owning every record it holds without conditions; the target's customer contracts, vendor terms and notices came with it and still apply.
The transition services point is easy to miss in carve-outs. When the acquired business was part of a larger seller, years of its history may sit in the seller's ERP or CRM, and the right to extract those records may end with the transition period.
- Customer agreements: data use, confidentiality, aggregation and deletion clauses, including negotiated versions.
- Vendor terms: export rights and any limits on using exported data, especially on older plans.
- Privacy notices and employee notices or handbooks in force when the records were created.
- Prior data licenses, data sharing agreements or research collaborations the target signed.
- Purchase agreement representations on data, privacy and IP, and the survival period for claims.
- Transition services agreements that leave historic records in the seller's systems.
Inventory worksheet columns#
An inventory worksheet works best with one row for each pairing of system and record family. The columns below support integration, retention and licensing decisions without collecting any record content, and they stay useful through to exit if someone keeps them current.
| Column | Example entry |
|---|---|
| System and edition | Zendesk, enterprise plan, company-owned instance |
| Record family | Customer support tickets with internal notes |
| History range | Earliest exportable year to present, with a gap during a past migration |
| Linked systems | Tickets link to Jira issues and Salesforce accounts |
| Administrator | Named employee plus a backup at the group |
| Export route | Native export, API or vendor-assisted |
| Restrictions | Two negotiated customer contracts limit reuse |
| Retention duty | Kept for tax and contract reasons; no deletion before review |
| Planned change | Moving to the group CRM after integration |
Gaps that show up in acquired companies#
The most common gap in acquired companies is history held outside company-controlled systems. A founder's personal Google account, a contractor's GitHub organization or a project manager's Dropbox can hold records the business depends on, and none of them transfer with the shares.
Other gaps include help desks whose built-in export leaves out the conversations themselves, call recordings stored by a telephony vendor under a separate account, and shared drives with no clear owner. Help Scout, for example, says its in-app export covers reporting data and not the content of conversation threads, which are available through its API instead. Each gap belongs in the inventory as a row with an owner and a plan, even when the plan is to leave the records where they are.
Illustrative: a software holdco's first quarter with a new product#
Illustrative: a fictional vertical software holding company acquires an inspection scheduling product used by fire protection contractors. On day one, the portfolio operations lead learns that the support team's help desk subscription is billed to the founder's personal card and would lapse when the founder leaves.
The team moves billing to the group and confirms that conversation history back to the product's launch can still be pulled through the help desk's API. By day 30, the inventory shows that support conversations reference issues in a GitLab group owned by a former contractor, and the group takes over ownership of it. By day 90, counsel confirms the product's click-through terms allow aggregated use, but several large customers negotiated stricter confidentiality.
The holdco keeps the help desk through integration, flags the support and engineering history as a possible licensing candidate with those customers excluded, and records the decision in the inventory.
How SourceX uses a post-acquisition inventory#
SourceX uses an inventory like this as the starting point of the Supply step in the SourceX five-step transaction. The fit check asks for the same metadata, systems, record families, history and known restrictions, and nothing is shared during the initial assessment.
If a record family moves forward, the restrictions found by day 90 feed the Rights step, and the outcome is recorded in a SourceX Evidence Packet with provenance, licensing rights, permitted use, the privacy record and release authorization.
Frequently asked questions
Who should own the post-acquisition data inventory?
A head of portfolio operations or an integration lead usually owns it, with the acquired company's IT or operations lead filling in system details and counsel reviewing restrictions. One named owner matters more than the title, because the inventory has to be updated as systems are retired or migrated.
Should the inventory include records the seller kept?
Yes. List records held by the seller under a transition services agreement or retained under the purchase agreement, with the date access ends. Those rows often drive the most urgent decisions, because extraction rights can expire before integration is finished.
Do we need to export data to build the inventory?
No. The inventory is built from metadata: system names, plans, date ranges, administrators and restrictions. Exports come later, for specific purposes such as migration, retention or an approved licensing project, and each export should be logged when it happens.
How does the inventory help at exit?
A maintained inventory answers many data diligence questions directly: which systems exist, what history is kept, what restrictions apply and what has been licensed or shared. It also shows a buyer that records were preserved deliberately rather than by chance.
What if a system was shut down before closing?
Ask whether the vendor still holds the data and for how long, whether any backups or exports exist, and whether a former employee kept a copy. Record what was lost in the inventory so later decisions do not assume history that no longer exists.
Sources
- Slack's retention help article states that by default Slack retains all messages and files for the lifetime of the workspace, that admins can instead set custom deletion periods, and that message and file deletion is permanent. Source
- Help Scout's in-app export covers reporting data from the All Channels, Email, Company and Happiness reports as CSV or XLSX. It does not include the content of conversation threads. Source
- Help Scout says all other account data can be obtained through its APIs, such as the Inbox API for customer, user and conversation data. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.