Published with current Microsoft Purview and OAIC source material and explicit tenant-configuration boundaries.
Why this matters
Microsoft describes unified auditing across services and retention labels that can mark emails and documents as records, subject to licensing and configuration. OAIC’s APP 11 guidance emphasises reasonable technical and organisational steps to protect personal information and to consider when it should no longer be retained. Those are separate concerns. Audit data can help investigate actions, while a case system explains why a message mattered to client work. A sound design preserves both without pulling unrelated mailbox content into a broad evidence store or granting users access beyond their role.
Key points to carry into the work
- Capture relevance, not mailbox volume: define which messages, attachments and shared documents belong to a case.
- Preserve source identifiers, sender and recipient data, received time, attachment hashes or versions and the classification action where available.
- Keep Microsoft 365 retention, audit and access configuration under authorised tenant administration rather than hard-coding assumptions in marketing software.
- Route ambiguous matches, missing attachments, duplicate threads and permission failures to a person instead of silently accepting them.
- 01Authorise the source
- 02Capture the item
- 03Preserve metadata
- 04Confirm the case
- 05Apply controls
- 06Reconcile exceptions
A controlled path from inbox to evidence case
Where Insia fits
Insia describes Microsoft 365 as a workflow target for controlled email and document intake, not as a live universal integration or partnership. Compliance Case Manager is intended to organise relevant evidence against case requirements, while Broker CRM keeps the client conversation and task ownership visible. Any connector would be scoped, authorised, tested and monitored per brokerage. The current public Compliance status remains private validation with a Draft Readiness Preview.
Keep the boundary clear. Insia does not change Microsoft 365 tenant settings, define a brokerage’s legal retention period, guarantee audit availability, copy every mailbox, certify records or replace Microsoft Purview, privacy review or legal hold processes. Microsoft capabilities and defaults can vary with configuration and licensing. A brokerage must approve the data scope, administrator permissions, retention design, exception handling and human review before use.
Checklist
- Authorised mailbox and library scope documented
- Capture event and actor recorded
- Source identifiers and versions preserved
- Case match confirmed by a person
- Access and retention configuration verified
- Exceptions and manual reconciliation visible
Sources and scope
Sources support the external context in this guide. Current product capability and availability are explained on the linked Insia product page.
- Microsoft Learn: auditing solutions in Microsoft PurviewMicrosoft · Accessed 10 August 2026
- Microsoft Learn: declare records with retention labelsMicrosoft · Accessed 10 August 2026
- OAIC: APP 11 security of personal informationOffice of the Australian Information Commissioner · Accessed 10 August 2026
Common questions
Is forwarding an email to a case mailbox enough?
It can be an intake method, but the workflow still needs source and attachment context, case matching, access controls, review and exception handling. Forwarding may change headers or separate an attachment from its wider conversation.
Does Microsoft 365 auditing create the broker evidence file?
No. Audit logs record supported user and administrator activities. A broker evidence file also needs case purpose, client context, requirements, source relationships, human decisions and the business outcome.
Can Insia read every Outlook mailbox by default?
No. No such public claim is made. Any Microsoft 365 connection must be separately authorised and scoped for the brokerage, with least-privilege access and a tested fallback.
Put the context to work
Turn this evidence task into a visible case.
Discuss how the evidence, requirements and human decisions in this guide could become a reviewable Compliance Case Manager workflow. This starts a product conversation and does not guarantee pilot access.
Discuss Compliance Case Manager