Litigation hold is the process of preserving potentially relevant records when an investigation, dispute, or legal proceeding is anticipated or underway. It suspends normal deletion or retention rules for specific data so organisations can retain evidence in a controlled, auditable manner.
Expanded Definition
Litigation hold is a legal-preservation control that freezes records, messages, logs, and other evidence once a dispute, investigation, or regulatory action is reasonably anticipated. In NHI-heavy environments, that scope often includes service account activity, API key usage, automation logs, ticketing trails, and cloud audit records that may prove how an NIST Cybersecurity Framework 2.0 control was applied or bypassed.
Unlike ordinary retention, litigation hold is event-driven and exception-based: it suspends deletion, rotation, and overwrite workflows only for the custodian set that could contain relevant evidence. Definitions vary across vendors and legal teams, but the operational requirement is consistent. The hold must be traceable, narrowly scoped, and reversible when the legal trigger ends. In identity operations, that means preserving not just the record content but the associated provenance, including who accessed a secret, when a token was used, and whether an agent executed privileged actions.
The most common misapplication is treating litigation hold as a blanket data freeze, which occurs when teams fail to isolate the relevant identities, systems, and time window.
Examples and Use Cases
Implementing litigation hold rigorously often introduces storage, workflow, and access-control constraints, requiring organisations to weigh evidence integrity against the operational cost of suspending normal lifecycle automation.
- A security incident triggers preservation of CI/CD logs, secret access records, and change tickets so investigators can reconstruct whether an API key was extracted or misused.
- Legal counsel directs a hold on mailbox archives and collaboration transcripts while a contractor dispute is pending, ensuring messages tied to an Ultimate Guide to NHIs-style service account review remain available.
- A cloud compromise requires retaining IAM audit logs and vault events to confirm whether a rotated credential remained active during the exposure window.
- A regulated organisation preserves agent execution traces and approval records to show whether autonomous actions were authorised, challenged, or blocked.
- A vendor dispute involves shared API traffic, so the hold covers gateway logs and token issuance records aligned to NIST Cybersecurity Framework 2.0 evidence expectations.
Why It Matters in NHI Security
Litigation hold matters in NHI security because non-human identities generate the very evidence that proves control, misuse, and impact. If secret rotation, access revocation, or audit logging continues to run unchecked during a hold, organisations can destroy proof before they understand what happened. That creates legal exposure and weakens post-incident analysis at the same time. NHIMG research shows that 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage, which makes evidence preservation a practical security concern, not just a legal formality. The risk is amplified when records span code, vaults, CI/CD tools, and agent platforms, as described in the Ultimate Guide to NHIs. Proper holds also support governance decisions about whether compromised identities must be disabled, reissued, or monitored during the dispute window. Organisations typically encounter the operational necessity of litigation hold only after a breach, subpoena, or internal investigation, at which point retention control becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 provides the primary governance reference for this term.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 | Requires risk decisions to consider legal and regulatory obligations around evidence retention. |
Preserve relevant identity records under hold while documenting legal triggers and review dates.
Related resources from NHI Mgmt Group
- How should security teams govern SaaS integrations that hold delegated access?
- What breaks when agents hold long-lived credentials for tool access?
- How should VASPs build AML/CFT controls that hold up under AUSTRAC scrutiny?
- What should organisations do differently when password managers also hold secrets and shared vaults?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org