The preservation protocol, what to keep, what to retire.
Red Hat audit document preservation protocol is the records discipline that sits underneath the audit defense and protects the customer from spoliation risk on one side and from over disclosure on the other. Once the audit notice is received, the customer should issue a legal hold that suspends normal retention deletion on a defined class of records; once the settlement closes, the legal hold is lifted and normal retention resumes, with selected records held longer for the next contract cycle. This note treats the preservation protocol, the legal hold framework, and the retention discipline through and after the audit.
Why preservation matters in audit defense.
Red Hat audit document preservation protocol is the records discipline that determines whether the defense has the evidence it needs and whether the customer faces spoliation risk in the event of a dispute. The Red Hat audit clause typically does not impose a discovery style hold on the customer, but the customer's general obligations under its master agreement, its insurance policy, and applicable law frequently do create preservation obligations once the audit is on foot. Failing to preserve evidence the customer reasonably anticipates being relevant can produce adverse inference issues that materially worsen the defense's posture.1
The parent service note on Red Hat audit defense treats the general posture; the present note treats the preservation discipline that runs beneath the defense. The companion notes on the internal audit readiness program and audit clause anatomy treat the readiness and contract side that the preservation protocol draws on.
The legal hold, scope and trigger.
The legal hold is the formal instruction that suspends normal retention deletion on a defined class of records. The hold is triggered by the audit notice (or, where readiness is mature, by a credible indication that an audit is imminent). The hold scope typically covers: the Red Hat contract records, the procurement records, the deployment evidence (hypervisor exports, subscription-manager output, Smart Management inventory, cloud billing), the communications between the customer and Red Hat or its agents about the audit, and the internal communications about the audit response. The hold scope does not typically extend to unrelated business records.2
The hold is issued in writing by legal counsel, communicated to the named custodians, and acknowledged by each custodian; the audit team's later evidence requests are then handled within the hold framework. The companion note on the day by day audit defense timeline treats the issuance side of the hold within the first three days of the notice arriving.
What to keep, what to retire.
The preservation protocol distinguishes between three classes of records: legal hold records (suspended from normal deletion for the duration of the audit and a defined tail period after), extended retention records (held longer than normal retention because they support the next contract cycle), and normal retention records (deleted on the normal schedule). Records in the legal hold class are not deleted, modified, or made unavailable by any custodian during the hold; the legal hold is itself a record that documents the suspension.
| Class | Examples | Retention |
|---|---|---|
| Legal hold | Audit records, evidence, communications | Through audit plus tail |
| Extended retention | Contract package, settlement letter | Through next renewal cycle |
| Normal retention | Unrelated operational records | Per standard schedule |
| Privileged | Legal counsel communications | Per privilege protocol |
The companion notes on vCenter host inventory and subscription-manager output treat the specific evidence types most commonly placed under hold. The sibling notes on audit defense by deal size and preparing the board for audit disclosure treat the scale and governance dimensions that drive the protocol's rigour.
Privilege and protected communications.
The preservation protocol treats privileged communications separately from other audit records. Communications with legal counsel about the audit are typically protected by attorney client privilege and the work product doctrine; communications with the practice (the buyer side advisor) are typically protected as work product when made for the purpose of preparing for the defense, although the protections vary by jurisdiction and engagement structure. The customer's legal counsel makes the privilege determinations; the operational preservation discipline is to keep privileged communications in a separately labelled location so they can be identified and held back from any evidence production.3
The cross link into RHEL on IBM Power licensing is relevant when the audit reaches into IBM contracted Power infrastructure and additional privilege analysis is required across the broader IBM relationship. The companion note on when to bring in legal counsel treats the engagement of counsel that the privilege analysis depends on.
Lifting the hold, and the tail.
The legal hold is lifted when the audit is materially resolved (the settlement letter is signed and any remediation has been executed). The tail period after the hold is lifted typically runs for one to three years and is set by the customer's records policy and external counsel's recommendation. During the tail period the audit records are still preserved but normal retention deletion resumes on the unrelated business records that may have been swept up in the hold. The contract package and settlement letter typically move into extended retention and are held through at least the next renewal cycle.
The sibling note on post audit posture treats the broader post settlement period that the tail sits in. The cross link into Red Hat Advanced Cluster Security pricing is relevant when the settlement included ACS or other OpenShift add ons; the related contract package may carry its own extended retention requirements.
How the practice helps run the protocol.
The practice helps customers design and run the preservation protocol through coordination with the customer's legal counsel, records management, and platform engineering teams. The first analyst call after the notice arrives identifies the trigger event, the scope of the legal hold, the named custodians, the existing records management infrastructure, and any prior holds that intersect with the audit. The protocol is documented; the hold notices are templated; the lift criteria are pre defined. The parent practice note on RHEL licensing treats the product side that the records orbit.
Across audit defenses in the practice's trailing twelve months that ran the structured preservation protocol, settlements consistently closed without spoliation issues, and the post settlement records discipline produced the contract package that the next renewal cycle drew on. If the audit notice is in hand, the first useful hour is a call with the desk. The sibling notes on audit after acquisition inherited exposure, cloud marketplace audit special cases, and dev test environment audit exposure treat the operational levers the protocol draws on.
Notes & references
- 1. Spoliation risk. Failing to preserve evidence the customer reasonably anticipates being relevant can produce adverse inference issues that materially worsen the defense's posture.
- 2. Hold scope. The legal hold typically covers contract records, procurement records, deployment evidence, and audit related communications; it does not typically extend to unrelated business records.
- 3. Privilege protocol. Communications with legal counsel and work product are protected; the operational discipline is to keep them in a separately labelled location to identify them in any production.
- 4. Three preservation classes. Legal hold, extended retention, and normal retention; the protocol distinguishes between them explicitly.
- 5. Lifting and tail. The hold is lifted when the audit is materially resolved; the tail period runs one to three years; the contract package and settlement letter move into extended retention.
Preparing a response? The practice keeps a one-page Red Hat audit response checklist — what to acknowledge, what to preserve, and what not to volunteer in the first fourteen days after the letter arrives.