What identifiers should be preserved immediately?¶
Preserve the exact identifiers needed to distinguish the device, account, service or session and connect it to later provider, organisational or technical records.
Prefer stable identifiers to display labels¶
A profile name, contact label or device nickname can be changed, duplicated or assigned by another user. Where already visible, record the underlying username, email address, telephone number, account handle, profile URL, serial number, IMEI, SIM identifier, hostname, asset tag, tenant ID, wallet address or provider reference.
Session, alert, transaction and case identifiers can bridge a transient screen to records held elsewhere. An IP address is useful only with its observation point, precise time and timezone; by itself it may identify shared infrastructure rather than a device or person.
Preserve format and context together¶
Copy punctuation, capitalisation and leading zeros exactly. A missing character can identify another account or prevent a provider from finding the event. If part of a value is obscured, record the visible portion and the limitation instead of completing it from memory.
For every identifier, note where it appeared, on which device or service, under which account and at what time. Preserve both a friendly label and the underlying value when they coexist.
Do not dig through settings simply to assemble every possible identifier. Prioritise values already visible, likely to disappear or necessary to identify the correct preservation target. Other identifiers may be recovered later from documentation, provider records or controlled examination.
Key takeaway
Retain exact account, device, provider and event identifiers with their source and time; a changeable display name is rarely enough.