What identifiers should be preserved before contacting a provider?¶
Before contacting a provider, preserve the identifiers that allow the correct account, object, session and time period to be located.
Avoid this assumption: A display name or email address will always be enough. Providers may operate several services, tenants, regions and account types with similar or changeable user-facing details.
Record the service name, full visible URL, username, email address, phone number, account handle and provider-generated account ID where available.
For organisational services, preserve the tenant, workspace, domain, organisation, subscription or customer reference.
For specific content, record file IDs, message IDs, conversation IDs, document URLs, transaction references, case numbers, channel names and folder paths.
For sessions or access events, preserve device IDs, session IDs, browser details, IP addresses, dates, times and time zones.
Record any partial or masked recovery details exactly as shown without guessing the hidden content.
Capture screenshots or photographs of the identifiers in their original context before copying them into a request.
Do not rely on a handwritten transcription alone where an exact provider-generated string is available.
Record whether the account is personal, business, managed, delegated, shared, suspended or deleted.
Where a public profile and internal account ID differ, preserve both and explain the relationship.
Check that the requested time range uses clear dates and a stated time zone.
Do not include unnecessary personal data unrelated to the preservation purpose.
Operational takeaway¶
Preserve exact provider, account, tenant, object, session and timestamp identifiers in context before contact, because vague or incomplete details may preserve the wrong records or none at all.