Could closing an application destroy useful evidence?¶
Yes. Closing an application can remove or alter evidence that exists only in its current live state.
Why this matters¶
The dangerous assumption is that closing an application simply tidies the screen. It may save files, discard drafts, end sessions, clear temporary data or change timestamps.
What to record and do¶
An open chat may contain unsent text. A browser may hold an authenticated session. A remote desktop may be the only live route to another system.
A command window may show activity that is not fully recorded elsewhere.
Before closing anything, record the application name, window title, account, visible content, prompts and surrounding screen.
Do not close applications simply to reveal what is underneath.
If the application appears frozen or unresponsive, do not force it to close without specialist advice.
Closing may also trigger synchronisation, logout or security alerts.
Where immediate operational necessity requires closure, record why, what was closed and what changed.
Capture any save, logout or warning prompt before responding.
Document whether data was saved, discarded or became inaccessible.
Closing a browser can remove temporary tabs, authenticated sessions and content held only in cache. Closing a security tool may stop monitoring or destroy a useful view of current activity. Record whether the application is local, cloud-based or remotely hosted before any decision.
Do not assume that reopening the application will restore the same content, credentials or connection state.
Record who authorised the closure and whether any replacement record or specialist capture was obtained first.
Operational takeaway¶
Assume closing an application may destroy live, temporary or session evidence, and preserve the visible state before any closure decision.