Behavioral evidence has replaced role as the reliable signal for identifying custodians. This isn't a prediction, it's the reality in 2026. If your identification practices still rely on the org chart and end with a keyword search, you're setting up a case that will cost more, preserve less, and defend poorly.
The eDiscovery process still involves identifying custodians, issuing holds, preserving data, collecting evidence, and reviewing for production. However, the environment for each step has changed. Work now occurs in Microsoft 365, Slack, Teams, SharePoint, and OneDrive. Evidence isn't just a document anymore, it's the document, version chain, link, channel, reaction, access pattern, and the identity behind each interaction. Programs that adapted early spend less on review and face fewer sanctions. Those that didn't are dealing with motions.
What Changed
Three structural shifts have redefined what "reasonable steps" means under Rule 37(e):
Behavioral evidence replaced role-based identification. The org chart shows who should have been involved. System logs reveal who actually was. The gap between these answers is where most identification mistakes occur and where opposing counsel will look. A junior analyst with edit access to a negotiation deck and a modification timestamp on a financial model is a custodian, even if their title doesn't suggest it. Identification based on observed access, edits, shares, and message activity leads to more accurate custodian lists. The precision of identification drives the economics of the program.
Collect-to-Preserve became the default for cloud collaboration. Preserve-in-place made sense when legal holds could control the source system. Microsoft 365 retention policies, Slack workspace settings, third-party app retention, and overlapping user-level permissions have changed that. A preservation hold is now a directive layered on platforms whose default behaviors continue around it. Collect-to-Preserve pulls relevant evidence into a defensible repository when the obligation attaches, rather than relying on the source system indefinitely. The collection itself becomes the preservation artifact. Chain of custody starts at collection, not at a hold notice that may not survive undocumented retention settings.
Chain of custody expanded to include context, not just artifacts. In cloud collaboration records, the document isn't the only thing needing a custody trail. The as-sent version of a message, the link target when a recipient clicked it, the permissions in effect when the file was opened, and the identity over time of the user who acted all carry evidentiary weight. A custody record that captures the file but not the context leaves a gap opposing counsel will exploit. Defensible chain of custody in 2026 means capturing evidence and the context that frames it, with cryptographic integrity, time-stamped acquisition, and an evidence graph linking each artifact to the identities, permissions, and behaviors around it.
What This Means for Your Team
Identification is the core of defensibility. Every downstream cost, sanction risk, and credibility argument traces back to whether the right data and custodians were identified initially. A well-scoped matter rarely leads to sanctions. A poorly scoped matter often does.
The standard for "reasonable steps" is now measured against what practitioners do in Microsoft 365 and Slack, not what was reasonable in the on-prem era. Epic Games v. Google (March 2023) found that relying on default Hangouts auto-deletion, without steps to suspend it once preservation duties attached, met the standard for intent under Rule 37(e)(2). Maziar v. City of Atlanta (2024) granted Rule 37(e)(1) curative measures and fees without an intent finding. In re Carvana (D. Ariz., 2026) ordered a bounded forensic capability test rather than accepting infeasibility claims. Judges are becoming more sophisticated about how M365 and Slack work.
Proportionality hasn't disappeared, it's become more challenging. The producing party isn't required to turn over every artifact that touched a custodian's account. They're required to make reasonable, proportional efforts. The challenge is that proportionality is judged against the matter, and modern matters don't present clean boundaries. A negotiation across email, Teams chat, a SharePoint workspace, three Slack channels, and a shared OneDrive folder doesn't fit neatly into a custodian-and-keyword search. The proportional response is to scope tightly using behavioral evidence, collect what falls inside that scope to a deterministic end state, and document the reasoning behind every inclusion and exclusion.
Action Items by Priority
1. Rebuild identification around behavioral evidence. Stop starting with the org chart. Start with system logs. Query for observed access, edit history, message activity, and shared workspace participation. The people who touched the evidence are your custodians, regardless of title. Document the query logic and exclusion reasoning. That documentation becomes your proportionality argument.
2. Adopt Collect-to-Preserve as your default for cloud collaboration sources. Don't rely on in-place retention controls for Microsoft 365, Slack, or Teams unless you've tested the preservation mechanics and documented the results. Pull the relevant evidence into a defensible repository when the obligation attaches. Capture the artifact and the context: version history, permissions, link targets, and identity chains.
3. Extend chain of custody to include contextual metadata. Your custody record must prove not just that you collected the file, but that you collected it with the permissions, access patterns, and identity information that give it evidentiary weight. Use cryptographic hashing, time-stamped acquisition, and an evidence graph that links artifacts to the behaviors around them.
4. Document your proportionality reasoning as you make scoping decisions. Proportionality is no longer a defense raised at production. It's a discipline applied at identification. Write down why you included certain data sources and excluded others. Write down why you expanded the custodian list based on behavioral evidence and why you stopped where you did. That record is what you'll cite in your Rule 26(f) conference and what you'll defend in a motion.
5. Test your preservation mechanics before the next matter. Don't wait for a legal hold to discover that your Microsoft 365 Records Control Schedule doesn't do what you think it does. Run a bounded test: issue a hold, wait 30 days, attempt collection, and verify that the data you expected to preserve is actually there. Document the results. If the mechanics don't work, switch to Collect-to-Preserve before you're explaining the gap under oath.



