What should be preserved from the account before interaction?¶
Before interacting with a live account, preserve the information that may identify the account, session and current state.
Why this matters¶
The dangerous assumption is that the account details will remain available later. Sessions expire, pages refresh, settings change and other users may alter the account remotely.
What to record and do¶
Record the service, full visible URL, username, email address, account handle, profile ID, tenant, workspace or organisation name.
Capture the page title, visible content, date, time, time zone and device or browser context.
Record any visible session information, linked devices, sign-in alerts, recovery details, administrator role, subscription status or security warning.
Preserve account-specific references such as case numbers, transaction IDs, conversation names, document IDs or provider-generated identifiers.
Do not navigate through menus merely to collect every possible detail. Start with what is already visible and likely to disappear.
Record whether the account appears live, cached, offline, partially loaded or open through a remote desktop.
Capture the whole screen first and then close detail.
If another person controls the account, record what they say separately from what the screen shows.
Where urgent safeguarding or containment action is required, preserve the visible state first where this can be done without unacceptable delay.
Preserve any visible recovery email, phone number, linked-device name or administrator contact without opening hidden details. Record whether the page is fully loaded or showing stale, cached or partly synchronised information, because that affects later interpretation.
Record who had physical control of the device and whether another person was present when the account was observed.
Operational takeaway¶
Preserve exact account, session, device and page context before navigation so later enquiries can identify what was visible and which account state was active.