Preserve (Legal Hold)
Preserve is an operator-only override that exempts a file, folder, or drive from retention locking — typically used to satisfy a legal hold or a client request to keep specific data active past its normal retention window.
What it exempts
Marking an item preserved excludes it from being moved into the retention vault, for as long as the hold is in place. It has no effect on archiving’s own eligibility check — this is a real, deliberate distinction worth stating precisely: a preserved file is not exempt from the archiving sweep itself, only from the retention vault’s real, storage-provider lock. In today’s implementation, since archiving is what moves a file into the vault in the first place, marking an item preserved before archiving considers it is the mechanism that keeps it out of the vault entirely.
This distinction matters more than it used to: once a file is genuinely in the vault, it is locked by AWS or Azure themselves — not even BYOVault can remove that lock early. Preserve is the only way to keep a specific item out of that irreversible state altogether, which is exactly why it exists as a deliberate, operator-only override rather than an automatic rule.
How it’s applied
Preserve is set by an operator from the dashboard, at three levels of granularity: a single file, an entire folder, or an entire drive/mailbox. It is not exposed to end users through the self-service portal — applying a hold is always an operator action, and every use is written to the audit log along with which operator applied it.
Typical use
Use Preserve when a client or legal request requires specific data to remain outside the normal retention lifecycle — for example, a mailbox or drive subject to litigation hold, or a file a client has flagged for indefinite retention outside your standard policy. It’s intentionally an operator-side control, kept separate from the automatic, tenant-wide retention schedule.