5.4. Insider Risk, eDiscovery, and Audit Capabilities
💡 First Principle: Even with strong classification, protection, and retention controls in place, an organization still needs to investigate when something might have gone wrong — whether the concern is a risky insider, a legal case requiring specific content, or simply "what did this user actually do" — and these three capabilities each investigate a different angle of that same underlying question.
Why care: these tools are often confused because they all involve searching and reviewing content or activity, but they answer fundamentally different investigative questions, which the next three subsections make explicit.
⚠️ Common Misconception: Assuming eDiscovery and Audit are interchangeable because both involve "searching" for something. eDiscovery finds content; Audit finds activity — a subtle but exam-relevant distinction covered below.