purview-ediscovery

purview-ediscovery is a skill for Claude Code, Codex from vinayaklatthe/microsoft-security-skills. It costs 119 tokens per session (1,266 once invoked), scanned A, original, MIT.

Guidance for Microsoft Purview eDiscovery, which finds, preserves, collects, reviews, analyses, and exports Microsoft 365 content for legal cases, regulatory requests, and internal investigations. It can cover email, files, Teams content, and Copilot interactions.

In plain words
What is it for?
Use it to open cases, place people or data on legal hold, search and collect content, review evidence, analyse it, and export the result.
Why use it?
It helps organisations preserve relevant information and produce it in a defensible way when there is a legal or investigative duty. It separates formal cases from simple audit-log searches.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it to open cases, place people or data on legal hold, search and collect content, review evidence, analyse it, and export the result.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/vinayaklatthe/microsoft-security-skills/purview-ediscovery
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add vinayaklatthe/microsoft-security-skills --skill purview-ediscovery
Clone the repo
git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for purview-ediscovery

README.md
[![agentmods](https://agentmods.dev/badge/skills/vinayaklatthe/microsoft-security-skills/purview-ediscovery/github.svg)](https://agentmods.dev/skills/vinayaklatthe/microsoft-security-skills/purview-ediscovery)
Your own site
<a href="https://agentmods.dev/skills/vinayaklatthe/microsoft-security-skills/purview-ediscovery"><img src="https://agentmods.dev/badge/skills/vinayaklatthe/microsoft-security-skills/purview-ediscovery/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for purview-ediscovery

Your own site · 80×15
<a href="https://agentmods.dev/skills/vinayaklatthe/microsoft-security-skills/purview-ediscovery"><img src="https://agentmods.dev/badge/skills/vinayaklatthe/microsoft-security-skills/purview-ediscovery.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 119 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,266 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00119 $0.01266
Opus 5 $0.00060 $0.00633
Sonnet 5 $0.00024 $0.00253
Haiku 4.5 $0.00012 $0.00127

Measured 9d ago against content hash 10e1311ea67c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

purview-ediscovery scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/purview-ediscovery/SKILL.md · 91 lines

How it starts

The opening of the file, as written. The whole thing — 91 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Microsoft Purview eDiscovery

Microsoft Purview eDiscovery identifies, preserves, collects, reviews, analyses, and exports content across Microsoft 365 (Exchange, SharePoint, OneDrive, Teams, Copilot interactions) for legal cases, regulatory requests, and internal investigations - following the EDRM workflow with defensibility at every step.

When to use

Responding to litigation, regulatory, or HR/investigation requests requiring defensible content preservation and production from Microsoft 365.

Do not use this skill for routine audit-log searches without a legal/investigation matter (use purview-audit) or for retention policy design (use purview-data-lifecycle).

Pick the right matter type

Matter Approach
Litigation with named custodians Full case: custodians on hold, collection, review set, export
Regulatory request, broad scope Non-custodial data sources + searches + review set
HR investigation, single user Lightweight case with targeted hold + collection (no review set if simple)
Quick fact-finding, no preservation duty purview-audit instead

Rule of thumb: if there is any preservation duty, open a case and apply a hold before you search - searches without holds risk spoliation if a custodian deletes content during triage.

Approach

  1. Create a case - Organise the matter in an eDiscovery case; assign role-scoped reviewers (eDiscovery Manager vs Reviewer) and record matter metadata. Verify: the case appears in the eDiscovery solution and only assigned users can open it.
  2. Add custodians and non-custodial sources - Identify people and locations in scope; non-custodial sources cover sites/mailboxes not tied to a person. Verify: custodian status shows hold pending or applied.
  3. Apply legal holds - Place custodians/data sources on hold before any collection; confirm hold receipt where required. Verify: hold status is Active for all custodians and shows source coverage (mailbox, OneDrive, sites, Teams).
  4. Build searches - Run draft searches with keywords, conditions, date ranges, and locations; review statistics and refine before committing to a collection. Verify: search statistics show estimated item count and size; top locations look sensible.
  5. Commit to a collection and review set - Commit refined results to a review set; use analytics (near-duplicate, email threading, themes) and tagging to cull. Verify: review set indexing completes and analytics tiles populate.
  6. Review and tag - Reviewers tag responsive/privileged/etc.; redact where supported; track reviewer progress. Verify: tagging history is auditable per reviewer.
  7. Export and produce - Export reviewed content in a defensible format with a load file suitable for downstream review platforms. Verify: export package includes load file, native files, and a manifest with hashes.

Read the full file on GitHub · 91 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 91 lines · 119 tokens per session scan A 10e1311ea67c

Subscribe to this mod's changes

purview-ediscovery is a skill published in the GitHub repository vinayaklatthe/microsoft-security-skills (173 stars, last pushed 2mo ago), licensed MIT. It adds 119 tokens to every session and 1,266 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

treatment-plans

Format and structurally validate local treatment-plan documentation after clinical decisions have already been supplied and verified by authorized licensed professionals. Use for source traceability, clinician-authored intervention records, goals and checkpoints, shared-decision records, reconciliation handoffs, and…

K-Dense-AI/scientific-agent-skills · 62 tokens

handbook-updates

Diff a proposed handbook change against the current version, flag ripple effects and state supplement impacts. Use when user says "update the handbook", "add this to the handbook", "handbook change", or has a policy ready for insertion.

anthropics/claude-for-legal · 52 tokens

skill-deck

Generate slide deck presentations from briefs — use when you need slides, pitch decks, or visual summaries.

nyldn/claude-octopus · 23 tokens

software-copyright-materials

A workflow for creating Chinese application materials for software copyright registration from a real software project.

Fokkyp/SoftwareCopyright-Skill · 97 tokens

managedcode-markitdown

Use ManagedCode.MarkItDown when a .NET application needs deterministic document-to-Markdown conversion for ingestion, indexing, summarization, or content-processing workflows. USE FOR: ManagedCode.MarkItDown integration; document ingestion flows; Office or rich-text conversion to Markdown; indexing and summarization…

managedcode/dotnet-skills · 113 tokens

glean-cli

Provides knowledge on using the glean CLI tool to access company knowledge and documents through Glean. Use when the user asks you to use Glean to search, read or otherwise access knowledge from their company's Confluence, Slack, Google Drive Files (Slides, Documents, Sheets) etc.

sammcj/agentic-coding · 63 tokens