What’s your process when a user loses access to an email or file without deletion?
I’ve been seeing more cases where users lose access to something important even though nothing was deleted — things like expired links, permission drift, sync conflicts, or mailbox auditing gaps.
In some incidents, the logs only tell part of the story, and it’s hard to determine whether an item was accessed, moved, or just became unreachable.
For those of you handling email security or IR, how do you approach situations where:
- auditing wasn’t enabled early enough
- message trace shows movement but not access
- permissions or shared‑link states changed silently
- the user insists “it was there yesterday” but there’s no deletion event
Do you treat these as data‑loss incidents, access‑loss incidents, or something else entirely?