4 ms·
Indeed. I suspect companies being started now will opt out of logging more and more. My companies employees work from home the majority of the time. We use H
by MetaCosm 12y ago
Indeed. I suspect companies being started now will opt out of logging more and more. My companies employees work from home the majority of the time. We use Hipchat, Trello, Github, Google Drive, and Email for most of our communications. We limit what we log technically (auto deleted after X days email, no logging on most hipchat channels) and by corporate policy.
We made an active decision to not store / log Hipchat and Email for a few reasons. We have a specific logged Hipchat channels -- but the rest just keep 75 lines for context and that is it. We also never have logged (nor ever will) the 1 on 1 conversations. Employees in a physical location can go outside and rant about a boss, family issue or other random noise -- and this isn't unhealthy, it is normal. We want to encourage open communication and straightforwardness -- and having communications "forgotten" is an important part of that. It also had additional benefits.
1. It limits the nightmare of discovery if we ever get sued, ever word every employee ever said won't be painstakingly scrutinized. Because we want the legal protection, we clearly spell out this privacy in our corporate documents so it is crystal clear to our employees.
2. It allows stuff to be discussed in context and in time and not being picked apart or misunderstood at a later point by other employees. Which encourages honesty and "getting it done".
3. It creates a "separation" of ephemeral communication that have a lower signal to noise ratio (our Hipchat today had many pictures of new desk layouts)... the important data leaves email or Hipchat and makes its way to Trello, Github or Google Drive.
- ElDiablo666 12y agoIntelligent corporate policy. Oh how I wish such a marriage of pragmatism and respect for privacy were the norm.
- teacup50 12y agoGiven how much you rely on SaaS, how do you even know the data is actually gone? Come discovery, I'd expect you'd find its a lot more permanent and exposed than you expect. Worrying about privacy while using SaaS seems to be missing the forest for a single small tree.
- MetaCosm 12y agoNot really, and there is a ton of case law on the topic. The way (civil) discovery works makes the SaaS concern far less of an issue. Civil cases are NOT criminal or national security -- this is not the CIA, it is not a secret court, it is not being tapped... it doesn't even rise to the level of a search warrant. It is up to the party being requested on to produce the documents. So, if we get a discovery request, we have to deliver the documents to fulfill it. For example, we have an automatic email cleanup after 90 days -- both technically, and in policy. This means if we are served with discovery, we can show the policy, show we have taken steps to follow our policy and produce the last 90 days of email. Same goes for Hipchat logs. Now, they could make some crazy play to extend discovery to Google or Atlassian. There are a couple problems with this, the first of which is such an insanely broad request would be flat out denied as fishing. If it wasn't, they would fight it kicking and screaming because they don't want to be involved in every civil case of every one of their of clients. They then would have to actually have the data, which in the no logging situation, hopefully they never had. Discovery is often used as a tool of attrition, to wear down the guy with the smaller wallet -- run lean (by policy and design) and if you ever get a request for discovery -- you can fulfill it quickly and completely.
- teacup50 12y ago> Now, they could make some crazy play to extend discovery to Google or Atlassian ... Discovery is often used as a tool of attrition, to wear down the guy with the smaller wallet Not that crazy. If the data exists, the fact that it's on a cloud vendor's backup tape is your problem. http://searchcio.techtarget.com/report/Avoid-lawsuit-nightmares-New-rules-of-engagement-for-e-discovery http://searchcio.techtarget.com/report/Avoid-lawsuit-nightma...
- MetaCosm 12y agoOn a technical level, I can understand your concerns. I am a developer, and it took me some time to get my head around how it works. But, the bottom line is -- it IS that crazy. Discovery isn't what you would think from popular culture ... if you served my company with discovery request, "we" (all the lawyers and companies) would have a meeting about it -- you would want to extend your grasp, we would look to shrink it. Most of the time, you would end up with something like "All emails about 'blue paint' between April 2011 and March 2012". Then it is up to ME and my company to find all those emails and provide them to you. Even knowing my email provider would likely be outside the scope. Discovery isn't to FIND a civil issue, it is to find evidence of one already filed issue, so fishing is explicitly not allowed. Corporate policies are a huge part of the discovery process, what makes it hellish is when you have NO policy around something (like email) because then you have to provide data or prove you don't have it. Our proof is our policy and technical measures. Our lack of recording data (logging) IS our record management strategy (and a wholly valid one) that massively reduces our costs if we ever get sued. The "cloud vendor's backup tape" is largely a straw man brought up by engineers rather than lawyers, I think I may have been guilty of bringing it up prior to learning about the discovery process.