Five record views
First define which history you mean
These views may contain different records. A visitor may see browser-linked history, agents a Teams thread, and compliance staff a protected copy. Attachments, reactions, system events, private notes, bot actions and edited or deleted versions may differ by path.
Name one authoritative record for each purpose. Support needs immediate context, privacy teams need defensible access and deletion, audit needs integrity, and migration needs a readable archive. One vague requirement for chat history cannot prove all four.
| Layer | Purpose | Required test |
|---|---|---|
| Visitor history | earlier messages in the website widget | identity, shared device, reset, consent and deletion |
| Agent history | context in a Teams thread or vendor inbox | roles, new members, private notes, search and attachments |
| Transcript/export | portable single or bulk dataset | fields, format, pagination, timestamps, completeness and checksum |
| Compliance copy | retention, hold, eDiscovery or investigation | licence, role, location, policy conflict and final deletion |
| Migration archive | legacy records after switching | read-only owner, searchability, legal basis, deadline and exit |
Product evidence
Documented capabilities and boundaries
| Model | Documented | Do not infer |
|---|---|---|
| WebChat in Teams | website enquiry and agent reply in Teams channel thread; local widget state | no evidenced complete product bulk export, retention/deletion scope or legacy import |
| Microsoft Teams | Graph Export APIs for channel messages; retention policies for chat/channel messages | no automatic complete WebChat export and no equality between visible UI and compliance copy |
| Chatwoot | permissioned Messages API per conversation; conversations live in inboxes | no ready bulk/legal export proven by these pages; inbox deletion is irreversible |
| Tidio | own Inbox for open and solved conversations; selected analytics exports | no complete transcript, retention or migration scope proven in reviewed pages |
| LiveChat | single transcript, future email forwarding, single/bulk API and chat-ended webhook | sample webhook is not an archive; visitor history differs from agent archive |
Governance
Retention and deletion need one data plan
Microsoft describes retention from message creation and different lifecycles for visible Teams content and secured compliance copies. Competing policies or holds may force longer preservation. A deletion notice in the client is therefore not evidence of final removal.
During a switch, a controlled parallel archive can be safer than an unproven import. Import only when IDs, timestamps, authors, threads, attachments, private content and deletion state map defensibly; otherwise keep legacy data read-only and begin new conversations in the replacement.
- Inventory the widget, vendor backend, Teams, Exchange compliance copy, SharePoint/OneDrive attachments, export destination, email and local downloads.
- Assign purpose, legal basis, owner, access, region, retention period, hold, deletion trigger and evidence to every store.
- Separate deletion from user view, a hidden compliance copy and final removal; document delays and policy conflicts.
- Give export apps minimum permissions, rotation, logs, pagination/retry control and an accountable operating owner.
- Transcript emails and CSV downloads are new copies: include recipients, mailbox rules, download folders, backups and later deletion.
- Freeze legacy scope before migration, sample it, store it read-only and attach an index, retention date and accountable disclosure contact.
Exit acceptance
Eight tests before purchase and migration
- 01
Write the record map
List visitor, agent, export, compliance and archive views with purpose and owner.
- 02
Create a control chat
Use text, emoji, link, file, private note, bot action, handoff, reaction and a test personal field.
- 03
Compare every view
Check widget, Teams/inbox, search, single transcript, bulk/API and compliance path against the control log.
- 04
Repeat the export
Test pagination, order, timezone, IDs, attachments, rate limits, retries and duplicates over two runs.
- 05
Exercise permissions
Agent, channel member, joiner, export app, compliance role and leaver receive only necessary access.
- 06
Trigger deletion
Trace one conversation through visitor device, agent view, backend, export copy and attachment; record hold exceptions separately.
- 07
Simulate exit
Disable widget, revoke access, export final delta, open archive and obtain vendor deletion confirmation.
- 08
Preserve acceptance
Version field matrix, samples, licences, roles, periods, deviations, restore/search test and accountable approval.