A cloud dispute usually begins with a concrete question. Who changed access to a file? Which account created a mailbox rule? Was an object downloaded, shared, renamed, or deleted? Did a session use a managed device? GDF turns that question into a collection and analysis plan for the services that could have recorded the answer. Work may involve Microsoft 365, Google Workspace, AWS, Azure, identity providers, collaboration systems, storage platforms, and the computers or phones synchronized with them. Availability is confirmed from the tenant in scope rather than assumed from a product name or subscription label.
Begin with the event that must be explained
The same word can describe different events. A file marked shared might reflect a direct invitation, inherited folder permission, public link, guest account, application grant, or later administrative change. A sign-in record may describe interactive access, background token use, a service principal, or an application acting for a user. The examination identifies the action, object, account, relevant period, expected recording service, and other records that could confirm or contradict it.
That question-led approach keeps collection proportionate. It also exposes missing prerequisites early, such as an unavailable administrator, expired logs, a disabled audit category, an unmanaged endpoint, or a vendor-controlled workspace. If the available records cannot answer the question, the limitation is stated before a broad export creates cost without clarity.
Preserve tenant state before administrators fix it
Containment and ordinary administration can rewrite the record. Resetting credentials, deleting a forwarding rule, revoking an application, changing retention, restoring a file, removing a guest, or rebuilding an endpoint may be necessary, but each action creates new events and can remove context. GDF coordinates with the client's authorized administrators so urgent control measures and preservation work are timed and documented. Credentials, recovery codes, and export packages are not sent through the public website form.
The preservation note records tenant identity, service, administrator role, collection time, time zone, relevant settings, export interface, filters, and known changes made during the response. GDF does not alter a tenant merely to make more historical data appear. New logging can help going forward, but it cannot recreate events that were never recorded or have already aged out.
Microsoft 365 and Google Workspace have separate records
Microsoft 365 activity can span Purview Audit, Exchange mailbox data, message trace, Entra audit and sign-in logs, SharePoint, OneDrive, Teams, Defender products, and local Office or sync artifacts. These are separate systems. Microsoft states that Purview audit retention varies by workload, license, policy, user, and event date. Entra audit and sign-in retention is also distinct from the Microsoft 365 unified audit record. The tenant's actual configuration and available date range control the work.
Google Workspace can require Gmail content, message-routing information, login events, Drive activity, file versions, sharing records, OAuth activity, administrator changes, Vault exports, and local Drive or browser artifacts. An administrator report may identify the primary account even when an alias appeared in the user-facing action. Exports are reviewed for field definitions, time basis, pagination, truncation, and whether deleted or historical content is included.
- Mailbox access, forwarding, delegate, and transport evidence
- File creation, revision, sharing, download, deletion, and restoration events
- Interactive, non-interactive, application, and administrative identity activity
- Guest access, OAuth consent, service accounts, and connected applications
- Endpoint and mobile artifacts that can corroborate tenant records
Infrastructure clouds and business applications need different questions
AWS and Azure records depend on what was enabled and where it was retained. CloudTrail event history is not the same as a configured trail or event data store, and management events do not establish that object-level data events were logged. Azure Activity Log, resource logs, identity data, storage access, network telemetry, deployment history, snapshots, and external monitoring can have different destinations and lifetimes. Region, account, subscription, resource, and log-routing choices remain part of the analysis.
Business SaaS platforms add another layer. Slack, Box, Dropbox, Salesforce, GitHub, ticketing systems, and industry applications expose different administrative reports, export formats, APIs, version histories, and deletion behavior. GDF confirms the supported method for the named platform and subscription. A user-facing download is not assumed to include administrative activity, deleted material, edits, reactions, attachments, or all message context.
An account event does not automatically identify a person
A cloud record can identify a tenant, account, application, token, device claim, IP address, user agent, and time. It may not identify the human who performed the act. Shared accounts, delegated access, automation, token theft, remote administration, proxies, stale device registration, and synchronized clients can produce activity under another user's name. Geographic databases can be imprecise, and a successful multifactor event does not by itself prove who approved it.
GDF tests attribution against independent material such as endpoint logs, browser records, mobile artifacts, email, security telemetry, device-management data, work schedules, and administrator actions. The report separates what the provider recorded from the inference drawn from it and identifies credible alternatives that the available evidence cannot resolve.
Exports need their own evidence record
Collection notes preserve the query or API call, account used, role, filters, dates, time zone, pagination, export options, provider job identifier, item count, errors, and checksum where the format supports one. Native JSON, CSV, MIME, message, archive, or provider package is retained before data is normalized for review. Screen captures can explain a setting, but they do not replace the underlying export when structured data is available.
Validation checks whether the export opens, expected result sets are present, counts reconcile, and timestamps and identifiers survive transformation. Rate limits, asynchronous jobs, partial failures, expired links, redacted fields, and vendor-side processing remain visible. A later examiner should be able to distinguish provider output from GDF's chronology, filtering, or interpretation.
- Original provider packages and documented acquisition details
- Normalized event tables with source fields retained
- Time-zone decisions and cross-service chronology
- Coverage, error, exception, and unavailable-period records
- Artifact citations connecting findings to collected material
New York matters often run on short technical deadlines
Assignments can support commercial disputes, employment matters, trade-secret claims, account compromise, business email events, insurance response, regulatory fact development, and expert testimony. New York counsel may need a preservation plan while motion practice, expedited discovery, or an application for temporary relief is moving. Security teams may need to contain access before provider records expire. The engagement identifies the decision deadline, preservation risk, authorized administrators, affected business process, and whether a neutral or opposing expert will review the work.
GDF provides technical collection, examination, chronology, reporting, and testimony. Counsel determines legal scope, privilege, discovery obligations, admissibility positions, notice, and regulatory interpretation. The technical report does not state that a legal requirement was satisfied and does not provide legal advice.
Deliverables built for the next decision
The work product can include a preservation memorandum, tenant and account inventory, collection log, export package, event chronology, identity-to-content correlation table, access or sharing analysis, exception register, technical report, declaration support, or expert demonstrative. The format depends on whether the next reader is counsel, a security lead, an administrator, an insurer, an opposing expert, or a factfinder.
Every conclusion states the services and period examined, evidence supporting it, assumptions, conflicting records, and material gaps. An absent event is not treated as proof that conduct did not occur unless logging coverage and expected behavior support that inference. Provider interfaces and schemas change, so tool names and field meanings are recorded as they existed during the work.
Prepare for the first technical call
Start with the disputed event, approximate dates, tenant domains, providers, affected users or resources, known administrator changes, current retention concerns, and the next deadline. Identify who can authorize access and whether counsel, an insurer, a response provider, or another expert is already involved. Do not paste logs, credentials, recovery codes, or sensitive content into the contact form. The opening call can establish priorities without transferring evidence.